Live data from Hacker News

Hacking Grindr Accounts with Copy and Paste

troyhunt.com

141–150 of 202 posts

Re: Hacking Grindr Accounts with Copy and Paste

#141
post #53

If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.

Hacking Grindr sounds like a lot of work. Why wouldn't gru@kremvax.ru just sign up, post a photo of her son and his classmates twerking at the pilot academy, enable tourist mode, and take a virtual trip to Los Alamos?

Re: Hacking Grindr Accounts with Copy and Paste

#142

As far as I can tell Grindr has had crappy security and a willful negligent response to security concerns for its entire existence. Don't forget that location tracking in real time of people with Grindr. Don't use Grindr.

I'm not a user of Grindr, but isn't the real time location tracking a feature that users actually like?

Yes. "Who else in my structural engineering tute is gay?" was one of the killer apps for GPS on mobile phones.

Re: Hacking Grindr Accounts with Copy and Paste

#143
post #139

Must be some framework that has this behaviour as default. Else it would be really really bad.

What would be the use case for a framework that returns password reset token to random user requesting password reset of another account. Token must only be available to account owner.

A framework like this should not be used.

Re: Hacking Grindr Accounts with Copy and Paste

#144
post #125

Earlier quoted context omitted.

Foreign governments blackmailing US government staff is only one side of the equation. There is, of course, the whole "but what would the wife/churchfellows think?" issue, still, but there are still many countries that do not take the same enlightened view that the US does. It's entirely possible that even the ability to verify that a particular email address has a Grindr account may be enough to threaten a person wi…

verifying that an email has an account is unfortunately always unavoidable. all you need to do is attempt to register with that email.

Fortunately it's easily avoidable: You defer checking address status until you send the mail out.

So when an email-address is entered to create an account, you always respond with "pending email verification". Then you send an email saying "Someone is registering an account with us using this address." And then, when the account already exists, you continue with "lol it already exists. If this was you, you can click to reset your password". If there is no account under that address, you send the "please click to verify" mail. At no point does this process expose the status of the address.

Re: Hacking Grindr Accounts with Copy and Paste

#145
post #125

Earlier quoted context omitted.

Foreign governments blackmailing US government staff is only one side of the equation. There is, of course, the whole "but what would the wife/churchfellows think?" issue, still, but there are still many countries that do not take the same enlightened view that the US does. It's entirely possible that even the ability to verify that a particular email address has a Grindr account may be enough to threaten a person wi…

verifying that an email has an account is unfortunately always unavoidable. all you need to do is attempt to register with that email.

We could do better by letting the web UI say nothing about that and only in the email that we send we tell someone that they already have an account.

Re: Hacking Grindr Accounts with Copy and Paste

#146

Earlier quoted context omitted.

This is why I love sign up with Apple. Even though developers don’t like it, it’s good for users privacy and security.

In theory, yes. But since it itself has had significant security flaws, since it's so difficult to log in without apple devices, and since you cant trust Apple to be neutral (they recently deleted all Sign-In-With-Apple Accounts from Epic, even though that has very little to do with their dispute and will hurt customers more than Epic), I'd rather reuse my email a couple of times than sell even more of my soul to thi…

They didn't actually remove Epic's access. Epic just claimed that they would with no corroboration. https://www.imore.com/apple-reverses-course-will-still-allow...

Re: Hacking Grindr Accounts with Copy and Paste

#147
post #117

Earlier quoted context omitted.

I've never been gay or bi, and I've never used Grindr, but I have held government security clearances for almost 40 years. It's a lot different today than it was back then. Early on, I knew several people who had "experimented" in college, and they were denied clearances. (Actually the government never officially denied them because that would require an explanation of the criteria used for the denial. Instead, it wa…

So were they denying clearances to openly gay people back in the old days? Because there wouldn’t be potential for blackmail in that case. Sorry I can’t tell what you’re saying changed about the policies.

Thirty years ago George Bush Senior was president, Reagan has recently left office, and the United States government was handling HIV poorly and intentionally so.

Sodomy laws were still on the books - can you keep a clearance while openly breaking the law every time you and your partner sleep together?

Re: Hacking Grindr Accounts with Copy and Paste

#148

Wow, password reset tokens returned directly in-browser; that's hard to believe. I wonder how long this had been going on?

Mental thought process of programmer: Sooo... what's the one thing we need this token to be. Secret. OK, let's just return it to the one person in the whole world we don't want to have it. Mmmm is it lunchtime...?

More like this:

Issue #2141 - implement password reset: After answering secret question user should see password reset link.

Issue #2534 - send email with password reset link.

Issue #2743 - remove password reset link from web page

Issue #3892 - replace secret question with email address input

Re: Hacking Grindr Accounts with Copy and Paste

#149
I have very little trust in the capabilities and interest of the Grindr team to do anything but making money with overpriced subscriptions. It's riddled with bugs, years old, yet they keep adding new, unnecessary features like video chat to justify their insanely priced "unlimited" subscription.

This year there have been a few months where your own profile data would not load, making you think you'd lost your profile data and having to create it all again. Yet all you needed to do was to restart the app ~10 times to get it to load.

Sometimes messages just... get lost in the ether.

The "online now" notification is flaky.

Grindr Online (web browser) is a whole new mess. I haven't used it in a long while, but the first months it felt as "professional" as an interns side project. Also you need to keep Grindr open on the phone while using it, kind of beating the purpose.

The setting to use the metric system still resets to imperial regularly.

The app is full of fakers, yet they still have no identity validation feature.

Post reply on HN