Your secrets are still safe with Secret
A coder named @barce got pulses raising Wednesday afternoon after he tweeted out the following message:
The vulnerability, @barce claimed, could be exploited using a “man in the middle” attack to retrieve a user’s personal information. The attack happens when an “intruder uses a program that appears to be the server to the client and appears to be the client to the server,” Margaret Rouse of SearchSecurity states. “The attack may be used simply to gain access to the message, or enable the attacker to modify the message before retransmitting it.”
This message caught the attention of entrepreneur and former Mashable Editor Ben Parr.
Did someone figure out whose secrets are whose on Secret? pic.twitter.com/qYNKzxtxAv— Ben Parr (@benparr) February 12, 2014
Minutes after @barce and Parr’s tweets were sent, David Byttow, cofounder of Secret, calmed everyone down.
“Nobody should be concerned,” Byttow told the Daily Dot. “This particular person simply set up a ‘man in the middle’ proxy on their home network and sniffed our internal API. Occasionally, the app makes a call to the server that returns user-specific information for that session. This person asked for the user information, which returned their own email address.” Emphasis ours: Byttow made a point to clarify that this hack will only yield the hacker’s identifying information, no one else’s.
In other words, the identities and information of other Secret users are still a secret.
Byttow also announced that his team is working on a security bug bounty program to encourage coders like @barce to sniff out vulnerabilities in the app.
This Secret scare comes little over a month after 4.6 million Snapchat usernames and phone numbers (including my own) were dumped online.
Japan accepts U.S. giant-robot battle challenge
What a time to be alive.10k
The Philae comet lander may have discovered alien life
Don't get too excited just yet. The findings haven't been verified.4.4k
U.S. women win first World Cup since '99
The Americans ride Carli Lloyd's hat trick for World Cup title.2.0k
Volunteers are needed to answer an age-old question about Tootsie Pops
Math says it’s about 1,000 licks. We call BS.
Counter-Strike squad affNity signs with 3sUP
3sUP is best know for its Call of Duty outings.106