Tinder's lack of encryption allows spying
nakedsecurity.sophos.com
nakedsecurity.sophos.com
Firesheep was a 2010 invention. Once that happened, anyone could chill in a coffeeshop and watch the http traffic whizz by.
... as much as we want to excoriate Tinder, it's been reasonable for most of their users to have 'i dgaf' as their threat model.
That's incorrect. Firesheep performed session hijacking using unencrypted session cookies.
I quoted the incorrect part of the comment. Then, I posted a correction to the comment that is incorrect. Firesheep doesn't display the HTTP traffic whizzing by but steals cookies for a session - allowing the malicious party to view information from the server, not the information between the sever and client.
This presumes users are aware of whether an app's traffic is encrypted or not. It's interesting how much thought goes into the UX of browser address bar security indicators, while everyone happily uses apps with no visual indicators of network connection security of any kind.
Users don't chose between apps based on a laundry list of features like security consciousness of the developers. They know tinder is where you get dates and they download and use that.
I'm a mobile app developer, and if I were downloading Tinder I am actually naïve enough that I would have presumed its network traffic would be. It just seems so matter of course to me that network requests written into any app being developed would just use HTTPS.
http://www.dailymail.co.uk/video/sciencetech/video-1614014/V...
Also, clever find that there's a side channel on left vs right swipe. What caused these payload differences?
Because the app isn't strictly enforcing the validation of the cert of the photos domain it's trying to reach to pull photos, your MITM server is free to serve to the app as if it was the server on the Internet.
Also, attacks don't have to exist in a vacuum. As part of a larger suite of attacks, it appears to be a useful tool that can help build up a profile of somebody.
The answer when it comes to hacking is almost never "why". Rather, it's usually "why not".
That said, you've described the 'why not'. All of the attacks you've identified are targeted and require significant investment. This opening doesn't allow for economically profitable mass-collection and exploitation (like say, grabbing credit cards or hacking into email accounts).
Then Tinder is owned by the same company that owns all of the other dating websites, so there is a whole tier of people there that have your data.
Then there are the adverts - I assume Tinder has them or could have them - so again you have another 27 trackers on the advertising side of things.
Of course there is nothing cloak and dagger about this, the T+C's explain it all and a click on an agree button has been made along the way.
Luckily we have too much data to deal with and whatever weird clumsy stuff said in messaging won't haunt you for life, e.g. adverts for some alternative lifestyle won't haunt you in the day job.
I have heard that 'dick pics' are a problem with dating, guys don't seem to get the message. However, if they had a box in the agreement that said 'all dick pics and naked chest shots in front of cars will be shared with your bank, Facebook, advertisers and third party marketing randoms' then that might change things a bit.