Live data from Hacker News

Tinder's lack of encryption allows spying

nakedsecurity.sophos.com

21–30 of 35 posts

Re: Tinder's lack of encryption allows spying

#21
The guy spying on your Tinder searches in Starbucks is kind of late to the party. Presumably you have paid for Tinder somehow and therefore Paypal or your other payment provider have sold that data point to advertisers already, perhaps Facebook have bought that too.

Then Tinder is owned by the same company that owns all of the other dating websites, so there is a whole tier of people there that have your data.

Then there are the adverts - I assume Tinder has them or could have them - so again you have another 27 trackers on the advertising side of things.

Of course there is nothing cloak and dagger about this, the T+C's explain it all and a click on an agree button has been made along the way.

Luckily we have too much data to deal with and whatever weird clumsy stuff said in messaging won't haunt you for life, e.g. adverts for some alternative lifestyle won't haunt you in the day job.

I have heard that 'dick pics' are a problem with dating, guys don't seem to get the message. However, if they had a box in the agreement that said 'all dick pics and naked chest shots in front of cars will be shared with your bank, Facebook, advertisers and third party marketing randoms' then that might change things a bit.

Re: Tinder's lack of encryption allows spying

#22

The most surprising thing about this to me is how long it took to have a new cycle about it. Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by. ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.

> ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.

This presumes users are aware of whether an app's traffic is encrypted or not. It's interesting how much thought goes into the UX of browser address bar security indicators, while everyone happily uses apps with no visual indicators of network connection security of any kind.

Re: Tinder's lack of encryption allows spying

#23

The most surprising thing about this to me is how long it took to have a new cycle about it. Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by. ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.

> ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model. This presumes users are aware of whether an app's traffic is encrypted or not. It's interesting how much thought goes into the UX of browser address bar security indicators, while everyone happily uses apps with no visual indicators of network connection security of any kind.

Or whether users know what encryption really means or not.

Users don't chose between apps based on a laundry list of features like security consciousness of the developers. They know tinder is where you get dates and they download and use that.

Re: Tinder's lack of encryption allows spying

#25

Earlier quoted context omitted.

> ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model. This presumes users are aware of whether an app's traffic is encrypted or not. It's interesting how much thought goes into the UX of browser address bar security indicators, while everyone happily uses apps with no visual indicators of network connection security of any kind.

Or whether users know what encryption really means or not. Users don't chose between apps based on a laundry list of features like security consciousness of the developers. They know tinder is where you get dates and they download and use that.

Most users, yes. But even those who do care, and know a little about it, don't necessarily have any obvious path to verify which apps do/don't encrypt their traffic.

I'm a mobile app developer, and if I were downloading Tinder I am actually naïve enough that I would have presumed its network traffic would be. It just seems so matter of course to me that network requests written into any app being developed would just use HTTPS.

Re: Tinder's lack of encryption allows spying

#26
post #13

The most surprising thing about this to me is how long it took to have a new cycle about it. Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by. ... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.

> Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by. That's incorrect. Firesheep performed session hijacking using unencrypted session cookies.

Which part of the comment is incorrect?

Re: Tinder's lack of encryption allows spying

#27
post #14
post #2

So where is the github link that let's us play with this?

Why would they make a github repo with this exploit for a seemingly not-fixed bug? If you're a security researcher it shouldn't be that hard for you to replicate it, and if you're not, there's no reason for you to have access to an app that lets you easily MITM someone's tinder results.

Because if shit like this gets magically patched and no one gets hurt, most people will continue to not care and groups like Tindr can continue to be lazy and do shit like this.

Re: Tinder's lack of encryption allows spying

#29

The next thing you should look at is who they send your personal data to and what data they send. There was rumors a year ago that they sent personal data to known advertiser IPs.

Does tinder have ads? How do they monetize their service?

Premium subscriptions and micro-transactions. As an active user, it really is a very cost-effective service.

Re: Tinder's lack of encryption allows spying

#30
post #17

Someone already released an app making use of this exploit. http://www.dailymail.co.uk/video/sciencetech/video-1614014/V...

Good. These kinds of things need to happen and be well-known in order for companies like Tinder to get their act together.
Post reply on HN