Stalking your Facebook friends on Tinder
defaultnamehere.tumblr.com
defaultnamehere.tumblr.com
He doesn't succumb to the temptation to be abusive (to either the people who made the thing he's testing, the people reading, or anyone who might be impacted by it), which is something a lot of security researchers seem to find impossible to avoid; there's a lot of calling people various forms of stupid in many incident reports. Even when given ample opportunity by the Tinder folks to call them names, he didn't do so (and, didn't blow it out of proportion, either...it's problematic, but if you're using Facebook and Tinder, you probably are already aware you're giving up a lot of privacy; this is a big deal, but not vastly bigger than using facebook all by itself).
He explains clearly what he did, and what tools he used to do it, which is another thing that often gets left out. Many security folks follow the magician's code ("never show'em how it's done"), and are dismissive that mere mortals could ever understand what they do.
And, he tells a good story in the process. All around, top notch technical writing about a usually boring subject.
At least he's not inserting meme-pictures every other paragraph, which seems to be thing now even in otherwise well-written material.
Any social network with deteriorating privacy is bad. One where the content can potentially be sensitive is even worse. If you started on a service and it kept becoming more private by default, that's fine - potentially annoying, but fine. If you start on a service and it kept becoming more public by default, then we have a problem.
The fact that Tinder don't realize Tinder profiles may contain sensitive information for a significant portion of their user base is hugely disturbing. As stated in the article, there are so many circumstances beyond cheating that this is still an issue.
Assume for a fictional argument that I was born into a religious family, "no sex before marriage" type of thing, but enjoyed one night stands. One might use Tinder to do so quietly. Tinder didn't allow your friends to see that information before - I assumed I was safe from judgement by my family and their friends. Then Tinder rips that privacy you thought you had away!
Saying that users should have known better is not an excuse. As developers we must operate under the assumption that best practices are likely going to be missed or misunderstood. Tinder violated that in an extreme way in an attempted land grab for a large social market beyond hook-ups and dating.
Disclosure: I'm friends with the author and commented on drafts.
Why would you think your profile is "secret" in any way to begin with? It is literally an app that shows you others using it NEARBY yourself. And a highly popular one at that.
The profiles are also public and there is no indication to them being private as far as I've ever read about the app.
A disapproving family member could still go to a bar or open an account to try to find you there. Which you should be aware of because they are both still publicly accessible spaces.
I guess it is like that in Australia though.
If this isn't criminal, it should be. People belong in jail for this sort of thing.
It's for this reason that, by default, I assume essentially everything I do online is public. My username is my name, almost everything on Facebook is defaulted to public, etc.
If you live under the assumption that you're never private, you'll never make the mistake of thinking you are.
curl -v -X POST 'https://api.gotinder.com/auth' -H 'Content-Type: application/json' --data '{"facebook_token": "facebook_token_string", "facebook_id": "facebook_id_string"}'
With that I modified the python code to no longer POST to get the X-Auth-Token and just pasted it in there: self.headers["X-Auth-Token"] = 'auth_token_string'
print("Authenticated to Tinder ")
self.authed = True
print self.authed
After that, everything worked fine!> """Yeah it's really important to write extremely enterprise well-documented hacky API code. Hacker News will love it I swear."""
[0]: https://github.com/defaultnamehere/tinder-detective/blob/13b...
Feature can be disabled at any time.
Has anyone in America tried out https://github.com/defaultnamehere/tinder-detective to see if the API still works in the US without having to opt in?
There's nothing new to discover with this 'hack', seeing your friends' tinder profiles is what tinder social does.
Do I have to create an App featuring access to my friend list for that?
On an unrelated note, I liked the way that the post was written. It made reading the details more interesting (but then again, I'm one of those young whippersnappers, so maybe I'm just more prone to liking that sort of thing).
Not quite... the API returns the Tinder user ID of all your Facebook friends that use Tinder. You can see who uses it, when they last used it, what picture they use there, etc.
You can also "swipe right" or "swipe left" using the API on anyone you have the Tinder user ID of, even if Tinder never matched them with you.
So it's scary in a "creep on your friends" way not in a "creep on strangers" way.
So you're saying I can brute-force iterate through the entire Tinder userbase and swipe right on everyone automatically?
Finally! The feature we've all been waiting for!
(More than a little sarcasm here.)
Most of the information was already available to someone you matched with (that's the whole point of matching), barring the 'last logged in' value. The real concern is that you can get the user id of any of your facebook friends, exposing information that was previously hidden unless you did match. Matching relies on two-party consent, this violates that for a subset of users.
What it does do is allow you to quickly find your Facebook friends quickly among the thousands of Tinder users in your area. You can find them anyway with enough swiping.
And I grabbed the user_id from the groups json "user_id" var
I also made the request from the browser on my phone.. same thing.
Do I need to add some tinder oauth credential to the curl request?
f = open(SECRETS.json) self.fb_auth = json.load(f)
So does it matter what I name the auth parameters or just that I set the values correctly?
i.e:
{ "auth_token" : "TOKENVAL", "fb_id" : "IDVAL" }
virtualenv venv --python=python3.5
source venv/bin/activate
pip install -r requirements.txtvirtualenv venv --python=python3.5 Running virtualenv with interpreter /usr/local/bin/python3.5 Using base prefix '/Library/Frameworks/Python.framework/Versions/3.5' New python executable in venv/bin/python3.5 Also creating executable in venv/bin/python Failed to import the site module Traceback (most recent call last): File "/Users/ericlw/Development/tinder-detective/venv/bin/../lib/python3.5/site.py", line 67, in <module> import os File "/Users/ericlw/Development/tinder-detective/venv/bin/../lib/python3.5/os.py", line 708, in <module> from _collections_abc import MutableMapping ImportError: No module named '_collections_abc' ERROR: The executable venv/bin/python3.5 is not functioning ERROR: It thinks sys.prefix is '/Users/ericlw/Development/tinder-detective' (should be '/Users/ericlw/Development/tinder-detective/venv') ERROR: virtualenv is not compatible with this system or executable
ugh none of this python 3 stuff works right
brew install python3.5C'mon Tinder.
Like, you weren't kidding. They honestly made it a float. What.
Gender can be either Male, Female, or Custom, and Facebook gives you the option to choose which gender pronouns you prefer. Thus, to see it represented as a boolean is unusual. I'm curious as to what the value of that field is when a user has chosen Facebook's custom gender display options.
That question needs unpacked further:
(1) Are there more than two gender identities? Yes.
(2) Are there more than two socially ascribed genders? Yes, given that (1) has achieved a significant degree of acceptance, as has aligning ascribed gender with identity.
(3) Are there more than two grammatical genders? Depends on the language.
(4) Are there more than two arrangements of sex-related biological traits? Yes
(5) Are there more than two of any of the items in #1, #2, or #4 on which people might preferences that would be relevant in a dating app? Probably.
It's OPT-IN - you can tell because you would have said 'opt me in to Tinder Social'. Also, if you can remember, swipe to your profile screen. If you have opted in it has it in huge writing.