Stay in the Loop

We are thrilled to extend a warm welcome to you as a valuable member of our vibrant crypto community! Whether you're an experienced trader, a crypto enthusiast, or someone who's just getting started on their digital currency journey, we're excited to have you onboard.

Read & Get Inspired

We're delighted to have you here and embark on this exciting journey into the world of Wikibusiness. Whether you're a newcomer or a seasoned explorer in this realm, we're dedicated to making your experience extraordinary. Our website is your gateway to a treasure trove of knowledge, resources, and opportunities.

PrimeHomeDeco

At PrimeHomeDeco, we believe that your home should be a reflection of your style and personality. Our upcoming website is dedicated to bringing you a curated selection of exquisite home decor that will transform your living spaces into elegant sanctuaries. Whether you're looking to revamp your living room, add a touch of sophistication to your bedroom, or create a cozy and inviting ambiance in your dining area, we have just the right pieces for you.

A shameful security flaw could have let anyone access your Grindr account – The Verge

You would think a dating app that knows your sexuality and HIV status would take thorough precautions to keep that info protected, but Grindr has disappointed the world once again — this time, with a gobsmackingly egregious security vulnerability that could have let literally anyone who could guess your email address into your user account.

Luckily, French security researcher Wassime Bouimadaghene discovered the vulnerability, perhaps before it could be exploited, and it’s now been fixed.

Unluckily for Grindr, the company ignored his disclosures — until security researcher Troy Hunt (of Have I Been Pwned) and journalist Zack Whittaker (of TechCrunch) each confirmed the issue and wrote about it.

The details need to be seen to be believed (so please look at the image above) but the short version is this: if you put an email address into Grindr’s password reset form, it would send a message back to your web browser with the key you need to reset the password buried inside it.

You could then theoretically just copy and paste that key into a password reset URL (which Hunt did), and take over an account just like that.

Grindr COO Rick Marini told TechCrunch that “we believe we addressed the issue before it was exploited by any malicious parties,” and says Grindr will both partner with a “leading security firm” and introduce a bug bounty program. That should hopefully mean security researchers like Bouimadaghene will have an easier time getting in touch.

Again, this isn’t just an app that contains a few messages. Grindr users include gay, bi, trans and queer individuals, and the mere presence of the app on a person’s phone can indicate something about their sexuality they may not want revealed to the outside world. And yet this is the company that was caught sharing its users’ HIV status to other companies, and sharing other personal info to third-party advertisers.

That said, it might be a slightly different company now. This March, the company’s Chinese owners sold it to a group of US investors, who also became Grindr’s new management. Marini, the COO quoted by TechCrunch, was one of the investors in the group. Another, Jeff Bonforte, is the company’s new CEO.

Related articles

SpaceX is preparing to launch Starship V2 one final time

Reports have emerged suggesting that Elon Musk might be rethinking his promise to give away most of his fortune. This was reportedly due to his longtime friend Peter Thiel, who told the world’s...

Redb – HTML5 Fashion Website Template

LIVE PREVIEWBUY FOR $29 About Redb Redb is a modern fashion template. It is a fully responsive HTML5/CSS3 template based on Bootstrap 4. It works seamlessly on all smart devices, including smartphones, tablets, PCs, and desktops....

Tesla axed one of the Model Y’s best features in ‘Standard’ trims: here’s why

When Tesla unveiled its Standard versions of the Model 3 and Model Y this week, reactions were mixed. Many liked the addition of two new models, but they were also concerned about the...
[mwai_chat model="gpt-4"]
Exit mobile version