Snapchat Source Code GitHub Leak Caused by Bad iOS Update
sensorstechforum.com
sensorstechforum.com
If the source was not already on GitHub, then a "GitHub Leak" of that source could not possibly be caused by a software error.
Regardless, many of us agree that the title suggests GitHub as a central role to the leak. If, as other commenters say, it was just used as a file host.. it doesn't belong in the title imo. It's just there to pull in more views. It may as well been Piratebay.
Edit: I'm guessing there's enough in the redacted part of the notice to prove SC's identity. But I think the question of DMCA abuse remains.
https://www.reddit.com/r/sickrage/comments/6oep02/false_dmca...
> The problem is that we tried to communicate with you but to no avail. The source code has been published on Github and I will publish it again until we get a response.
It's been forked 49 times so far.
But git is a distributed version control system, so git clone before the takedown would help.
If you fork a public repo and the original is deleted, your fork survives.
I'm not trying to nitpick or be a jerk; I just wanted to point this out because I think that forking in general on GitHub is less useless than you imply.
[1] https://help.github.com/articles/what-happens-to-forks-when-...
Java was compiled correctly with ProGuard (code obfuscator), but C# code was compiled in debug mode. C# in debug mode keeps variable/class/method names as they are in source code, leaves comments in the binary, binary file is bigger and slower. You can decompile it to compilable source code, literally.
I managed to get incorrectly protected secret key (they used GPG to encrypt JWT to server lol), later I managed RE of their API, make my own app with identical UI and working coupons. This allowed me to get free coupons every day for next almost 2 years. There were several updates in Google Play since then, but they haven't changed the logic or anything, the app is still in debug mode and anyone can use it. What is interesting, they have also app for iOS which is not in debug mode. Consistency is the key.
After I stopped using their services, I checked their ToS that you have to accept before registering and they prohibit app decompilation, but I never registered and never before read ToS, so it's OK for me ;) I wanted to report the problem but they have literally no contact information, I spent a few hours trying to find their contact details, Twitter is dead since 2014, no contact@ email, no contact form on website... nothing.
Lesson for you: check if your apps are correctly compiled and secrets protected, there are tools for it. In my previous company we had a Jenkins job to test it before release.
And remember: no matter how well you think you have protected the secret, if it is in the client-side application then someone will be able to find it if they want to enough. It must be unpackable by your local code so it must be unpackable by someone who can unpack and understand that code.
Honestly, it seems so stupid that their best defense is probably that no cracker even thought to check.
Every Play Store app has a contact email in the listing.
If anyone is really curious, it is called Source-SnapChat and it is all over Github.
Github is going to have to mass delete these mirrors, and prevent anyone from re-commiting it anywhere. Snapchat sending DMCAs is not going to be enough.