Tinder vulnerability let hackers take over accounts with just a phone number


A newly published attack let researchers take over Tinder accounts with just a user’s phone number, according to a new report by Appsecure. Tinder has changed its login system to protect against the attack and there’s no evidence it was exploited before the patch. Still, it’s a reminder of how fragile many login systems still are, and how powerful even basic vulnerabilities can be when chained together.

The attack worked by exploiting two separate vulnerabilities: one in Tinder and another in Facebook’s Account Kit system, which Tinder uses to manage logins. The Account Kit vulnerability exposed users’ access tokens (also called an “aks” token), making them accessible through a simple API request with an associated phone number.

That...

Continue reading…

via The Verge - Tech Posts "http://ift.tt/2CBK5PQ"

Comments

Popular posts from this blog

Evernote cuts staff as user growth stalls

The best air conditioner

We won't see a 'universal' vape oil cartridge anytime soon