Plenty of Fish app was leaking users’ hidden names and postal codes

Dating app Plenty of Fish has pushed out a fix for its apps after a security researcher found they were leaking information that users had set to “private” on their profiles.

The app was always silently returning users’ first names and Zip postal codes to the app, according to The App Analyst, a mobile expert who writes about his analyses of popular apps on his eponymous blog.

The leaking data was not immediately visible to app users, and the data was scrambled to make it difficult to read. But using freely available tools designed to analyze network traffic, the researcher found it was possible to reveal the information about users as their profiles appeared on his phone.

In one case, the App Analyst found enough information to identify where a particular user lived, he told TechCrunch.

Plenty of Fish has more than 150 million registered users, according to its parent company IAC. In recent years, law enforcement have warned about the threats some people face on dating apps, like Plenty of Fish. Reports suggest sex attacks involving dating apps have risen in the past five years. And those in the LGBTQ+ community on these apps also face safety threats from both individuals and governments, prompting apps like Tinder to proactively warn their LGBTQ+ users when they visit regions and states with restrictive and oppressive laws against same-sex partners.

A fix is said to have rolled out for the information leakage bug earlier this month. A spokesperson for Plenty of Fish did not immediately comment.

Earlier this year, the App Analyst found a number of third-party tools were allowing app developers to record the device’s screen while users engaged with their apps, prompting a crackdown by Apple.

https://techcrunch.com/?p=1927106

Source: TechCrunch

By:

Vice President Pence bulks up Coronavirus Task Force with medical and economic experts
Vice President Pence bulks up Coronavirus Task Force with medical and economic experts ...
Feb/27/2020
Gift Guide: 10 gadgets for a smarter smart home
Gift Guide: 10 gadgets for a smarter smart home ...
Dec/19/2019
Spotify opens up its podcast catalog to third-party apps, but not for streaming
Spotify opens up its podcast catalog to third-party apps, but not for streaming ...
Mar/20/2020
TripActions secures $500M credit facility for its new corporate travel product
TripActions secures $500M credit facility for its new corporate travel product ...
Feb/25/2020
Instagram prototypes Snapchat-style disappearing text messages
Instagram prototypes Snapchat-style disappearing text messages ...
Mar/19/2020
Robinhood blames record trade volume & itself for outages
Robinhood blames record trade volume itself for outages ...
Mar/04/2020