Showing posts with label Snapchat. Show all posts
Showing posts with label Snapchat. Show all posts

Sunday, January 12, 2014

, , , , ,

Apology agonistes? Don't blame Snapchat -- blame yourselves

Snapchat's middle-finger salute in the aftermath of a massive security breach is par for the course in an industry with the attention span of a hamster.



View the Original article

Saturday, January 4, 2014

, , , , , ,

Snapchat Says It’s Improving Its App, Service To Prevent Future User Data Leaks

Snapchat has released an official post about the recent leak of 4.6M usernames and phone numbers from its servers. The post blames what it says was ‘abuse’ of its API on the leak, but acknowledges that the way that it stores the information made it possible for a database of numbers to be used to sniff out usernames and match them up.

Changes will be made to both Snapchat’s apps and the service in order to prevent future leaks including being able to opt out of the Find Friends feature that uses phone numbers.

Snapchat says that it was notified of the possible security risk (publicly) in August and took some steps to correct it including limiting the speed at which its API could be queried. In what is one of the most cringe-worthy security moves in recent memory, Snapchat posted a response late last month to claims of risk that outlined just how a hacker might be able to match usernames to phone numbers.

In the post, they said “Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way.”

That is exactly what the group behind the leaked SnapchatDB.info database says that they did. The result was a trove of 4.6M Snapchat accounts matched up with usernames and phone numbers.

Despite partially redacted phone numbers and usernames, matched conveniently in an online repository, Snapchat says that “no other information, including Snaps, was leaked or accessed in these attacks.”

Notably, Snapchat’s public response to this hacking does not include an apology of any sort to its users who have had their user names or phone numbers publicly exposed. Perhaps its an effort to avoid an admission of guilt, but it still feels like a bad effort.

The person(s) responsible for releasing the names and numbers told Techcrunch that “raise the public awareness around the issue, and also put public pressure on Snapchat to get this exploit fixed. It is understandable that tech startups have limited resources but security and privacy should not be a secondary goal. Security matters as much as user experience does.”

The group says that they were following the research of Gibson Security, who gave a detailed account of how such an exploit could be accomplished to ZDNet in late December. The researches came forward after they say that they approached Snapchat and got no response from them on the matter. Snapchat’s statement today appears to confirm that its reverse engineered API was used to obtain the user info.

As our own Josh Constine mentioned about this issue late last month, Snapchat’s first mistake was to not take the efforts of ‘white hat’ hackers seriously. If Gibson Security did indeed approach Snapchat far in advance of going public, their revelations should have been taken seriously and acted on with vigor.

Snapchat’s first blog post on the issue in December acknowledged the potential vulnerability publicly and noted that some countermeasures had been put into place. But, in the same breath, it noted that there was still a method that could be used to accomplish this kind of leak. Yet it didn’t fix it.

Now, Snapchat says that it will add an opt-out to its apps which will allow people to choose not to appear in the Find Friends feature after they’ve used their phone number for verification purposes. It says it is also ‘improving’ the rate limiting it used to throttle API requests previously and adding ‘other restrictions’ to address future attempts to abuse the service.

Here’s the full post from Snapchat:

When we first built Snapchat, we had a difficult time finding other friends that were using the service. We wanted a way to find friends in our address book that were also using Snapchat – so we created Find Friends. Find Friends is an optional service that asks Snapchatters to enter their phone number so that their friends can find their username. This means that if you enter your phone number into Find Friends, someone who has your phone number in his or her address book can find your username.

A security group first published a report about potential Find Friends abuse in August 2013. Shortly thereafter, we implemented practices like rate limiting aimed at addressing these concerns. On Christmas Eve, that same group publicly documented our API, making it easier for individuals to abuse our service and violate our Terms of Use.

We acknowledged in a blog post last Friday that it was possible for an attacker to use the functionality of Find Friends to upload a large number of random phone numbers and match them with Snapchat usernames. On New Years Eve, an attacker released a database of partially redacted phone numbers and usernames. No other information, including Snaps, was leaked or accessed in these attacks.

We will be releasing an updated version of the Snapchat application that will allow Snapchatters to opt out of appearing in Find Friends after they have verified their phone number. We’re also improving rate limiting and other restrictions to address future attempts to abuse our service.

We want to make sure that security experts can get ahold of us when they discover new ways to abuse our service so that we can respond quickly to address those concerns. The best way to let us know about security vulnerabilities is by emailing us: security

View the Original article

Friday, January 3, 2014

, ,

Overexposed: Snapchat user info from 4.6M accounts

Heads up, Snapchat users: someone has allegedly comprised 4.6 million accounts, potentially exposing your usernames and phone numbers.

The Snapchat account information apparently had been posted to a site called SnapchatDB.info by an individual or group determined to prod the 2-year-old photo-sharing service, which has more than 8 million adult users in the US alone, into shoring up its security. Sometime after the hack was first revealed overnight, the SnapchatDB site went offline, perhaps because of all the attention it attracted: "This account has been suspended," reads the brief note at the Web site. "Either the domain has been overused, or the reseller ran out of resources."

Related posts5 things to expect in social in 2014Does Missouri topless mom case prove Snapchat is pointless?Instagram treks into well-worn territory with direct messagesSnapchat snags $50M in latest funding roundIn Snapchat suit, Reggie Brown's lawyers defend right 'to fight back'

The phone numbers that were revealed were not quite complete. SnapchatDB reportedly blocked out the last two digits in a small, but likely incomplete, gesture toward preserving users' privacy.

The incident, which affects users primarily in the US, comes just a few days after Snapchat acknowledged a potential vulnerability that would allow "a possible attack by which one could compile a database of Snapchat usernames and phone numbers." At that time, Snapchat even described how such an attack might be constructed -- a description suggestive of the framework that may have been used by SnapchatDB -- even as it said it has taken preventive measures:

Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way. Over the past year we've implemented various safeguards to make it more difficult to do. We recently added additional counter-measures and continue to make improvements to combat spam and abuse.

Whoever is behind SnapchatDB told the Verge that Snapchat had not, in fact, taken sufficient action to protect users' data: "Once we started scraping on a large scale, they decided to implement minor obstacles, which were still far from enough. Even now the exploit persists. It is still possible to scrape this data on a large scale."

Snapchat's blog post and SnapchatDB's actions stemmed from a Christmas Eve post by Gibson Security detailing Snapchat code that would allow access to Snapchat user information.

CNET has contacted Snapchat for comment and will update this story when we hear back.

Topics: Social networking Tags: Snapchat, hacking. privacy

View the Original article

Thursday, January 2, 2014

, , , , , , ,

Snapchat database leak claims to contain 4.6 million phone numbers and usernames

Last week security researchers published a way to skim Snapchat's full database, and it appears someone did it before the vulnerability -- which, according to those researchers had been known for months -- was addressed. A website called SnapchatDB! has appeared posting SQL/CSV files that it claims contain the username and associated phone number for a "vast majority" of the service's users, with the last two digits of the numbers obscured. Snapchat eventually admitted that such a hack was theoretically possible, but said additional countermeasures and safeguards it's implemented would make that harder to do. That amounts to 4.6 million pairs, although actually downloading the files to actually use them or verify the claim seems impossible, presumably due to an overload of traffic.

We don't know who is behind the website (its WHOIS record is hidden by WHOISGuard), but the homepage claims this release is happening to "raise awareness" of the fact that companies should be more careful with the private information of their users. As the site mentions, even the info included could be enough to figure out someone's phone number from their username (if it's also used publicly on Twitter, for example), especially problematic for those with unlisted numbers. They also have not ruled out releasing the uncensored database "under certain circumstances," so if you've ever used the service this may be something to keep an eye out for.

Update: Developers Robbie Trencheny and Will Smeindlein have worked up a searchable database to see if your info is among those captured. It's accessible here, and searches by username, apparently based on the SQL file uploaded. Our friends at TechCrunch apparently found at least one writer's info in the database, although a Reddit user who grabbed the file suggests only certain area codes are affected.




View the Original article

Wednesday, January 1, 2014

, , , , ,

Confirmed: Snapchat Hack Not A Hoax, 4.6M Usernames And Numbers Published

A site called SnapchatDB.info has saved usernames and phone numbers for 4.6 million accounts and made the information available for download. In a statement to us, SnapchatDB says that it got the information through a recently identified and patched Snapchat exploit and that it is making the data available in an effort to convince the messaging app to beef up its security. We’ve also reached out to Snapchat.

SnapchatDB said:

Our motivation behind the release was to raise the public awareness around the issue, and also put public pressure on Snapchat to get this exploit fixed. It is understandable that tech startups have limited resources but security and privacy should not be a secondary goal. Security matters as much as user experience does.

We used a modified version of gibsonsec’s exploit/method. Snapchat
could have easily avoided that disclosure by replying to Gibsonsec’s private communications, yet they didn’t. Even long after that disclosure, Snapchat was reluctant to taking the necessary steps to secure user data. Once we started scraping on a large scale, they decided to implement very minor obstacles, which were still far from enough. Even now the exploit persists. It is still possible to scrape this data on a large scale. Their latest changes are still not too hard to circumvent.

We wanted to minimize spam and abuse that may arise from this release. Our main goal is to raise public awareness on how reckless many internet companies are with user information. It is a secondary goal for them, and that should not be the case. You wouldn’t want to eat at a restaurant that spends millions on decoration, but barely anything on cleanliness.

Earlier we speculated that SnapchatDB might be a hoax meant to call attention to the app’s security issues but, as it turns out, it’s real–at least one member of our editorial team has been affected. A reader also told us he found his own number, that of several friends and Snapchat founder Evan Spiegel in the list. On Hacker News, several people have had trouble downloading the data files (I just got an error message for both of them, but that may be because of high traffic), but a Jailbreak subreddit user who saw the list said that only numbers in some parts of the U.S. have been published so far. If you have not been able to download the list, you can use this site created by developer Robbie Trencheny to see if your username was included.

SnapchatDB said it “censored the last two digits of the phone numbers” in order to “minimize spam and abuse,” but it might still release the unfiltered data, including millions of phone numbers.

The Next Web did a WHOIS lookup on SnapchatDB’s domain and found it was created just yesterday on December 31. The registrant’s name is protected, but its mailing address and contact number are both listed in Panama.



View the Original article

Tuesday, December 31, 2013

, , , ,

How Snapchat Became The Breakout Consumer Product Of 2013

Editor’s Note: Semil Shah works on product for Swell, is a TechCrunch columnist, and an investor. He blogs at Haywire, and you can follow him on Twitter at 

View the Original article

Sunday, December 29, 2013

, , , , , ,

Report: Snapchat exploits can steal your private info, expose you to spam

A group of security researchers has published a pair Snapchat security exploits, claiming the popular social startup has ignored requests to address them since August -- prior to any Facebook acquisition talk. The Gibson Security team is hoping that'll force the company to respond to the problems, which they say could pose serious privacy risks for both iOS and Android users. The first bug could help a hacker suss out private user details like phone numbers, while the second could be used to create masses of dummy accounts. Together, they could be used by spammers, or worse, stalkers, provided they roughly know the location of the target. Now that the code's out in public, anyone with technical know-how could exploit the bugs, which the team said could be fixed with "ten lines of code." If true, hopefully Snapchat will jump on them quick -- check the source for more.

Update: Snapchat has responded, acknowledging that "theoretically" the phone number data exploit is possible, but claims it has implemented safeguards over the past year and "recently added additional counter-measures and continue to make improvements to combat spam and abuse."

0 Comments Share

Via: Ars Technica, ZDNet

Source: Gibson Security

Tags: exploit, security, snapchat Next: Vidzone brings free music-video streaming to PS4 .fyre .fyre-comment-divider

View the Original article
, , , , , , , ,

Daily Roundup: Snapchat security exploit, judge okays NSA spying and more!

You might say the day is never really done in consumer technology news. Your workday, however, hopefully draws to a close at some point. This is the Daily Roundup on Engadget, a quick peek back at the top headlines for the past 24 hours -- all handpicked by the editors here at the site. Click on through the break, and enjoy.



View the Original article

, , , , , , , ,

Snapchat Downplays Phone Number Matching Hack, Says It’s Added New Counter-Measures

Following security researchers publishing a way to match Snapchat usernames to phone numbers, Snapchat has published a skimpy statement making the hack sound impractical and noting “We recently added additional counter-measures and continue to make improvements to combat spam and abuse.”

Earlier this week ZDNet published an in-depth write-up of how white-hat Gibson Security researchers had tried to notify Snapchat of a way hackers could connect usernames to phone numbers for use in stalking, but were ignored. The GibSec team then published the exploit publicly on Christmas Eve. Read ZDNet’s post for full details on how the hack works.

Snapchat hadn’t provided a public statement until now, and what it’s offered isn’t very satisfying. “Theoretically, if someone were able to upload a huge set of phone numbers, like every number in an area code, or every possible number in the U.S., they could create a database of the results and match usernames to phone numbers that way. Over the past year we’ve implemented various safeguards to make it more difficult to do.” It goes on to note it’s added more barriers to the use of this hack.



View the Original article

Monday, December 23, 2013

, , , , , , , , ,

Snapchat Adds Filters, A Replay Function And For Whatever Reason, Time, Temperature And Speed Overlays

Next StoryBTC China CEO Attempts To Calm The Bitcoin Market After RMB Deposit Shutdown

Snapchat busted out an update to its app today just before the holidays. The new version of the ephemeral messaging app includes several color filters, a new ‘special text’ font and a few other additions.

The main update is the ‘visual filters’ that will add juiced up color effects to your images. If you’re stumped at how to activate them it is likely because you are not a teen. It took me 10 minutes to figure out that you have to swipe from right to left to trigger the filters. You’ve got 3 filters including two color and one black & white to choose from.



View the Original article

, , , ,

Snapchat Sacrifices Ephemerality With New Replay Feature

My least favorite part of Snapchat is mistakenly opening a video Snap when I can’t hear it, like in a noisy public place or when my sound is off. Snapchat tried to address that today with an experimental new Replay feature that lets you rewatch one old Snap per day. But by fixing that problem it created a much bigger one. It killed off some of its ephemerality.

A lot of the excitement and urgency of Snapchat stems from the fact that you only get one shot to look at a Snap. That means you have to pay close attention and be fully engaged.

But with Replay, you can be lazy. Once a day you can re-view a Snap a second time if you don’t close the app or get another Snap first. “Oh, that looked funny. Wow, they looked sexy. I’ll watch it again.”

It’s not quite the “forever” of Facebook’s Timeline, but suddenly I’m a bit more self-conscious of what I send. Did I line up the shot right? Does my stupid hair look ok?

A big draw of Snapchat was that once someone had viewed your Snap, it only lived on in their imperfect memory. That made sending them carefree and lightweight — something I’d do without second guessing what could happen. That encouraged the silly and racy behavior Snapchat thrives on, and set it apart from other photo sharing services that create a permanent record you have to worry about.

Now whoever I send a Snap to can verify their first impression, show it to someone else, or get a second camera or phone out and secretly screenshot it. This makes sexting with Snapchat a lot more risky. Who wants to flash their jubblies if they have to worry they’ll get replayed in front of a crowd or a camera?



View the Original article