TopRatedTech

Tech News, Gadget Reviews, and Product Analysis for Affiliate Marketing

TopRatedTech

Tech News, Gadget Reviews, and Product Analysis for Affiliate Marketing

Dating app Raw exposed users’ location data and personal information

A safety lapse at relationship app Uncooked publicly uncovered the non-public knowledge and personal location knowledge of its customers, TechCrunch has discovered.

The uncovered knowledge included customers’ show names, dates of delivery, relationship and sexual preferences related to the Uncooked app, in addition to customers’ areas. A number of the location knowledge included coordinates that had been particular sufficient to find Uncooked app customers with street-level accuracy.

Uncooked, which launched in 2023, is a dating app that claims to supply extra real interactions with others partly by asking customers to add every day selfie photographs. The corporate doesn’t disclose what number of customers it has, however its app itemizing on the Google Play Retailer notes greater than 500,000 Android downloads up to now.

Information of the safety lapse is available in the identical week that the startup introduced a {hardware} extension of its relationship app, the Uncooked Ring, an unreleased wearable device that it claims will permit app customers to trace their companion’s coronary heart charge and different sensor knowledge to obtain AI-generated insights, ostensibly to detect infidelity.

However the moral and ethical issues of tracking romantic partners and the risks of emotional surveillance, Uncooked claims on its web site and in its privateness coverage that its app, and its unreleased system, each use end-to-end encryption, a safety function that stops anybody apart from the consumer — together with the corporate — from accessing the info.

After we tried the app this week, which included an evaluation of the app’s community site visitors, TechCrunch discovered no proof that the app makes use of end-to-end encryption. As an alternative, we discovered that the app was publicly spilling knowledge about its customers to anybody with an online browser.

Uncooked fastened the info publicity on Wednesday, shortly after TechCrunch contacted the corporate with particulars of the bug.

“All beforehand uncovered endpoints have been secured, and we’ve applied further safeguards to forestall related points sooner or later,” Marina Anderson, the co-founder of Uncooked relationship app, instructed TechCrunch by electronic mail. 

When requested by TechCrunch, Anderson confirmed that the corporate had not carried out a third-party safety audit of its app, including that its “focus stays on constructing a high-quality product and fascinating meaningfully with our rising group.”

Anderson wouldn’t decide to proactively notifying affected customers that their info was uncovered, however mentioned the corporate would “submit an in depth report back to the related knowledge safety authorities underneath relevant rules.”

It’s not instantly identified how lengthy the app was publicly spilling its customers’ knowledge. Anderson mentioned that the corporate was nonetheless investigating the incident. 

Relating to its declare that the app makes use of end-to-end encryption, Anderson mentioned Uncooked “makes use of encryption in transit and enforces entry controls for delicate knowledge inside our infrastructure. Additional steps might be clear after totally analyzing the scenario.” 

Anderson wouldn’t say, when requested, whether or not the corporate plans to regulate its privateness coverage, and Anderson didn’t reply to a follow-up electronic mail from TechCrunch.

How we discovered the uncovered knowledge

TechCrunch found the bug on Wednesday throughout a quick check of the app. As a part of our check, we put in the Uncooked relationship app on a virtualized Android system, which permits us to make use of the app with out having to supply any real-world knowledge, similar to our bodily location.

We created a brand new consumer account with dummy knowledge, similar to a reputation and date of delivery, and configured our digital system’s location to look as if we had been at a museum in Mountain View, California. When the app requested our digital system’s location, we allowed the app entry to our exact location down to some meters.

We used a community site visitors evaluation software to observe and examine the info flowing out and in of the Uncooked app, which allowed us to grasp how the app works and what sorts of information the app was importing about its customers. 

TechCrunch found the info publicity inside a couple of minutes of utilizing the Uncooked app. After we first loaded the app, we discovered that it was pulling the consumer’s profile info immediately from the corporate’s servers, however that the server was not defending the returned knowledge with any authentication.

In apply, that meant anybody might entry another consumer’s non-public info by utilizing an online browser to go to the net handle of the uncovered server — api.uncooked.app/customers/ adopted by a novel 11-digit quantity corresponding to a different app consumer. Altering the digits to correspond with another consumer’s 11-digit identifier returned non-public info from that consumer’s profile, together with their location knowledge.

a screenshot showing an exposed user's profile set up by TechCrunch, which includes the user's precise location.
Picture Credit:TechCrunch
a screenshot showing the location of the TechCrunch user's profile on a map, hovering over Mountain View, California.
Picture Credit:TechCrunch

This sort of vulnerability is named an insecure direct object reference, or IDOR, a kind of bug that may permit somebody to entry or modify knowledge on another person’s server due to a scarcity of correct safety checks on the consumer accessing the info.

As we’ve explained before, IDOR bugs are akin to having a key to a non-public mailbox, for instance, however that key may also unlock each different mailbox on that very same avenue. As such, IDOR bugs could be exploited with ease and in some circumstances enumerated, permitting entry to document after document of consumer knowledge.

U.S. cybersecurity company CISA has lengthy warned of the dangers that IDOR bugs current, together with the power to entry sometimes delicate knowledge “at scale.” As a part of its Secure by Design initiative, CISA mentioned in a 2023 advisory that builders ought to guarantee their apps carry out correct authentication and authorization checks.

Since Uncooked fastened the bug, the uncovered server not returns consumer knowledge within the browser. 

Source link

Dating app Raw exposed users’ location data and personal information

Leave a Reply

Your email address will not be published. Required fields are marked *

Scroll to top