Grindr security flaws risk exposing users' location data

Two security issues could expose personal data for up to 3 million users of the gay dating app Grindr, according to an NBC OUT report. In the first, a website letting users log in with their Grindr credentials got wide-ranging access to data that isn't publicly available. This includes that user's unread messages, email addresses, deleted photos and real-time location -- even if they've opted out of publicly sharing the latter. But the second simply intercepts unencoded location data going from the app to servers, allowing anyone observing that user's internet traffic to pinpoint their position.

Trever Faden originally discovered the first flaw after creating the website C*ckblocked (asterisk intentional) to scrape data from anyone who logged in with their Grindr username and password. The second would let anyone monitoring web traffic observe the location-pings the Grindr app sends to its servers -- and while that's a creepy thing to do anywhere (like, say, over public Wi-Fi), it's also something that anti-gay governments or groups could use to peek at anyone who might use the service.

We've reached out to Grindr for comment and will add when we hear back. The company assured NBC OUT that the C*ckblock flaw had been fixed (the site was shut down anyway), but the second exploit reportedly remains.

Newsletter

Introducing 'Fronx' - Maruti Suzuki's sporty C-SUV at Ambal Auto's Nexa showroom in Nava India!

The car is designed with a modern aerodynamic style that is both aesthetically pleasing and sporty. The Fronx C-SUV is p...

Hello iPhone: Following EU, Indian Government to make USB-C charging port mandatory across all smartphones

Earlier this year, Greg Joswiak, Senior Vice President, worldwide marketing at Apple said during The Wall Street Journal...

Covid Vaccine 100% Effective On 12-15-Year-Olds: BioNTech-Pfizer

Covid Vaccine 100% Effective On 12-15-Year-Olds: BioNTech-Pfizer

Telegram introduces group voice chat in a unique way to mimic conference calls

Telegram introduces group voice chat in a unique way to mimic conference calls

Coimbatoreans witnessed The Great Conjunction with a telescopic view

The solar system's two biggest planets - Jupiter and Saturn were in a straight plane yesterdayas part of "The Great Conj...

Astronomy Festival on 21 Dec: Discussion on rare event of alignment of Jupiter and Saturn

Astronomy Festival on the 21st: Discussion on the rare event of alignment of Jupiter and Saturn