If your company is being actively targeted by nation states (and rest assured, Grindr is), you should have a serious security team where this sort of stuff shouldn't have seen the light of day. I'm not exaggerating when I say this bug may have gotten people locked up, or been the lever for corporate/government espionage.
Hacking Grindr Accounts with Copy and Paste
141–150 of 202 posts
Re: Hacking Grindr Accounts with Copy and Paste
#142As far as I can tell Grindr has had crappy security and a willful negligent response to security concerns for its entire existence. Don't forget that location tracking in real time of people with Grindr. Don't use Grindr.
I'm not a user of Grindr, but isn't the real time location tracking a feature that users actually like?
Re: Hacking Grindr Accounts with Copy and Paste
#143Must be some framework that has this behaviour as default. Else it would be really really bad.
A framework like this should not be used.
Re: Hacking Grindr Accounts with Copy and Paste
#144Earlier quoted context omitted.
Foreign governments blackmailing US government staff is only one side of the equation. There is, of course, the whole "but what would the wife/churchfellows think?" issue, still, but there are still many countries that do not take the same enlightened view that the US does. It's entirely possible that even the ability to verify that a particular email address has a Grindr account may be enough to threaten a person wi…
verifying that an email has an account is unfortunately always unavoidable. all you need to do is attempt to register with that email.
So when an email-address is entered to create an account, you always respond with "pending email verification". Then you send an email saying "Someone is registering an account with us using this address." And then, when the account already exists, you continue with "lol it already exists. If this was you, you can click to reset your password". If there is no account under that address, you send the "please click to verify" mail. At no point does this process expose the status of the address.
Re: Hacking Grindr Accounts with Copy and Paste
#145Earlier quoted context omitted.
Foreign governments blackmailing US government staff is only one side of the equation. There is, of course, the whole "but what would the wife/churchfellows think?" issue, still, but there are still many countries that do not take the same enlightened view that the US does. It's entirely possible that even the ability to verify that a particular email address has a Grindr account may be enough to threaten a person wi…
verifying that an email has an account is unfortunately always unavoidable. all you need to do is attempt to register with that email.
Re: Hacking Grindr Accounts with Copy and Paste
#146Earlier quoted context omitted.
This is why I love sign up with Apple. Even though developers don’t like it, it’s good for users privacy and security.
In theory, yes. But since it itself has had significant security flaws, since it's so difficult to log in without apple devices, and since you cant trust Apple to be neutral (they recently deleted all Sign-In-With-Apple Accounts from Epic, even though that has very little to do with their dispute and will hurt customers more than Epic), I'd rather reuse my email a couple of times than sell even more of my soul to thi…
Re: Hacking Grindr Accounts with Copy and Paste
#147Earlier quoted context omitted.
I've never been gay or bi, and I've never used Grindr, but I have held government security clearances for almost 40 years. It's a lot different today than it was back then. Early on, I knew several people who had "experimented" in college, and they were denied clearances. (Actually the government never officially denied them because that would require an explanation of the criteria used for the denial. Instead, it wa…
So were they denying clearances to openly gay people back in the old days? Because there wouldn’t be potential for blackmail in that case. Sorry I can’t tell what you’re saying changed about the policies.
Sodomy laws were still on the books - can you keep a clearance while openly breaking the law every time you and your partner sleep together?
Re: Hacking Grindr Accounts with Copy and Paste
#148Wow, password reset tokens returned directly in-browser; that's hard to believe. I wonder how long this had been going on?
Mental thought process of programmer: Sooo... what's the one thing we need this token to be. Secret. OK, let's just return it to the one person in the whole world we don't want to have it. Mmmm is it lunchtime...?
Issue #2141 - implement password reset: After answering secret question user should see password reset link.
Issue #2534 - send email with password reset link.
Issue #2743 - remove password reset link from web page
Issue #3892 - replace secret question with email address input
Re: Hacking Grindr Accounts with Copy and Paste
#149This year there have been a few months where your own profile data would not load, making you think you'd lost your profile data and having to create it all again. Yet all you needed to do was to restart the app ~10 times to get it to load.
Sometimes messages just... get lost in the ether.
The "online now" notification is flaky.
Grindr Online (web browser) is a whole new mess. I haven't used it in a long while, but the first months it felt as "professional" as an interns side project. Also you need to keep Grindr open on the phone while using it, kind of beating the purpose.
The setting to use the metric system still resets to imperial regularly.
The app is full of fakers, yet they still have no identity validation feature.