Home » Immorality, North America, Social » Group sex app with "worst security ever seen" exposes users in White House & 10 Downing St


Group sex app with "worst security ever seen" exposes users in White House & 10 Downing St

 
 
 
 
submit to reddit

5d4d6cbffc7e93c81f8b45d7

A massive vulnerability has been exposed in the group dating app 3fun, with researchers gaining access to a trove of information on its users. In a further twist, users were uncovered in the corridors of power in the US and UK.

The app is described as a “Curious Couples & Singles Dating” platform. One would think that security would rank fairly high on the agenda for such a service; however that was clearly not the case as the Pen Test Partners security researchers, who discovered the vulnerability, described what they felt was “probably the worst security for any dating app we’ve ever seen.”

Personal information, sexual preferences, private photos, chat data and users’ real time locations were all exposed due to 3fun’s shoddy security practices.

The leak was due to 3fun storing its users’ location data in the app itself, as opposed to keeping it securely on its servers. This allowed the researchers to uncover the data on the client side, even for users who had restricted their location data.

The vulnerability meant that Pen Test Partners could discover the locations of 3fun’s users around the globe. Amazingly users were found in the White House, the US Supreme Court, and at 10 Downing Street in London. However the security experts did concede that it’s “technically possible” that these users faked their locations.

Pen Test Partners made 3fun aware of the bugs on July 1; however, it took weeks to address the issues. TechCrunch was able to independently verify the app’s vulnerability.

Source

Please wait...


RELATED ARTICLES

Did you like this information? Then please consider making a donation or subscribing to our Newsletter.

Conversation Guidelines

Starting a conversation on our website is very easy, all you need to do is to write your name, email and the comment itself. No account is required to leave a comment. Your email won't be used for any purpose whatsoever, if you want, you can even write a fictitious email. Please keep it civil, try to refrain from slurs and insults. We offer Free Speech rights to our comment section but please take note that the comment section is moderated so certain comments may be held for moderation in case they triggered our automatic filters. If your comment is on hold for moderation and you can't see it anywhere there is no need to repost it. Don't worry, it doesn't mean it won't get approved. Please patiently wait and check back later.



Copyright © 2009 The European Union Times – Breaking News, Latest News. All rights reserved.