That 'bug' is so stupid and elementary that I'm disinclined to think it's a bug. If they had any security people, it'd never have existed. So ... they just don't give a shit . Surprise?
"Security people" spend most of their time dealing with dubious compliance requirements that rarely improve security (in most cases they annoy users and force them to use even less secure workarounds) than actual security like reviewing code to catch things like this and implement policies to make sure unreviewed code doesn't make it to production.
Hacking Grindr Accounts with Copy and Paste
81–90 of 202 posts
Re: Hacking Grindr Accounts with Copy and Paste
#82OK, I know it’s easy to say “well of course it’s not safe, don’t send nudes and don’t go on sketchy hookups”. But, to paraphrase Drag Race: men are rotted gila monsters. (I’m a gay male, I can say that. Also I speak from experience. I've seen things you people wouldn't believe.) So, as a thought exercise, how do you make an app like this more secure? Harm reduction is the name of the game. What are the best practices…
I do what I can in terms of promoting certain ideas, creating informational resources, etc. But I am just one person and yadda.
As long as it is okay to jail or kill people merely for being gay, no amount of security will ever really make it safe.
In the meantime, perhaps someone should blog about "dating security best practices for the LGBTQ crowd" or something like that. (It won't be me. I'm just tossing the idea out there.)
Re: Hacking Grindr Accounts with Copy and Paste
#83I guess the good news is that it requires knowledge of the user's email address to execute. You can't just run it on random people (emails aren't disclosed) and even if you know someone on the app in real life, chances are good that they use a personal address that you won't have. Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.
Imagine someone running their contact list through this. You could find everyone you know on Grindr right away, and snoop on their conversations and read their personal info... Not only that, but emails are very easy to find these days with tools like apollo.io.
Re: Hacking Grindr Accounts with Copy and Paste
#84One thing I did notice, though: The timestamps on the Twitter DMs, which were used as evidence to assert that they're unresponsive in DMs, cover a time period of 90 minutes. The language the twitter client is set to is also not english (maybe French? the original discovery was made by someone who lives in France. I don't know), which introduces the possibility that it wasn't even daytime in the US when those were sent.
I'm all for publicly announcing these things (in a responsible way) and forcing a quicker response from the company, and its also likely that Troy tried to reach out on his own, but I just think that screenshot is a bad example of a company not responding to DMs. If it had been 48 hours to a week, then I'd be in the concerned camp.
Re: Hacking Grindr Accounts with Copy and Paste
#85If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.
I don't mean to downplay the issue, but why would LGBT-hostile nation-states target Grindr's infrastructure when it's much easier to detect users at the network level based on TLS SNI (since encrypted SNI is still not a thing thanks to corporate influence)?
Re: Hacking Grindr Accounts with Copy and Paste
#86Wow, password reset tokens returned directly in-browser; that's hard to believe. I wonder how long this had been going on?
Re: Hacking Grindr Accounts with Copy and Paste
#87This issue is incredibly strange and severe. One thing I did notice, though: The timestamps on the Twitter DMs, which were used as evidence to assert that they're unresponsive in DMs, cover a time period of 90 minutes. The language the twitter client is set to is also not english (maybe French? the original discovery was made by someone who lives in France. I don't know), which introduces the possibility that it wasn…
Re: Hacking Grindr Accounts with Copy and Paste
#88Re: Hacking Grindr Accounts with Copy and Paste
#89One reason why generating random email address for each registered account is a good practice if you care about security, and can sometimes save you.
Re: Hacking Grindr Accounts with Copy and Paste
#90Earlier quoted context omitted.
$50 says they're not. This is something every organization has to say for PR reasons, but saying "we believe" is very fishy wording. It could well be this bug has been around for months before it was discovered, and used by many black/grey-hat hackers.
Governments. It was likely used by governments. Bi men who live straight lives with a wife and family are ridiculously common. The ability to blackmail those people is extremely valuable to certain state organizations.