5 ms·
I guess the good news is that it requires knowledge of the user's email address to execute. You can't just run it on random people (emails aren't disclosed) an
by djaque 6y ago
I guess the good news is that it requires knowledge of the user's email address to execute. You can't just run it on random people (emails aren't disclosed) and even if you know someone on the app in real life, chances are good that they use a personal address that you won't have.
Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.
- jdminhbg 6y ago> even if you knkw someone on the app, chances are good that they use a personal address that you won't have I doubt that; I bet most users use whatever Gmail/etc personal address they use for other non-work accounts.
- perardi 6y agoExtremely anecdotally: it’s [person_name]@gmail.com I know of very few friends who go through the process of creating a burner email account to sign up for Grindr. Now, maybe that’s different in other countries, but at least in the States, I would bet good money you can guess their Gmail address.
- sebmellen 6y agoImagine someone running their contact list through this. You could find everyone you know on Grindr right away, and snoop on their conversations and read their personal info... Not only that, but emails are very easy to find these days with tools like apollo.io.
- nickff 6y agoIt would be very easy to target a large group of individuals at a given organization.
- djaque 6y agoGood point, even just being able to use it as a tool to play "gay or not" has some pretty aweful implications for people who aren't openly gay.
- staplor 6y agoYes, but even if the referenced security risk is patched you would still be able to find out if some has an account or not since a password reset page will tell you if it has successfully sent an email to an account.
- Nextgrid 6y agoA good password reset page would not disclose such a fact (it would return a successful response with a message "if this email exists, we'll email you" regardless of whether it actually exists) however attempting to create an account would disclose that fact by rejecting an account creation attempt with an existing email, unless they use emails purely as communication channels and accounts are uniquely identified by username/account number instead.
- joshuaissac 6y ago>however attempting to create an account would disclose that fact by rejecting an account creation attempt with an existing email, unless they use emails purely as communication channels They can tell the user to await an e-mail from them with the confirmation link. Then if the e-mail address is already in use, send an e-mail saying, "somebody, probably you, tried to register as <new-username> on <site> but we have you down as <old-username> already". Otherwise, send a normal confirmation link.
- 6y ago