news.volyx.in

I hacked a dating app (and how not to treat a security researcher) (alexschapiro.com)

570 points by bearsyankees · 445 days ago · 311 comments on HN

Article summary

A security researcher discovered vulnerabilities in the Cerca dating app, including broken OTPs and open endpoints, which allowed access to personal information, passport data, and intimate messages. The researcher reported the issues to the Cerca team, who acknowledged the problems and promised to address them, but then failed to follow up or inform users. The vulnerabilities have since been patched, but the incident raises concerns about the app's security and the company's handling of the situation. The researcher published their findings to highlight the importance of security and responsible disclosure.

Main themes

  • Security vulnerabilities
  • Responsible disclosure
  • Data breach notification
  • Company accountability
  • User privacy
  • Regulations and laws
  • Prosecution of security researchers

What commenters say

  • Companies have a responsibility to inform users about data breaches and vulnerabilities, even if they have been patched.
  • Security researchers should be cautious when testing company systems, as it may be illegal and can lead to prosecution.
  • The lack of response from the company after acknowledging the vulnerabilities is unacceptable and may be an attempt to cover up the issue.
  • Regulations and laws are needed to hold companies accountable for protecting user data and informing them about breaches.
  • The company's failure to prioritize security and inform users is a result of a lack of competency and disregard for user privacy.
  • The incident highlights the importance of responsible disclosure and the need for companies to have a clear playbook for handling security reports.
  • Prosecution of security researchers should be declined if their conduct consists of good-faith security research.
  • Companies may not prioritize security due to a lack of consequences, such as fines and litigation, for data breaches and vulnerabilities.