Behind Grindr's Doomed Hookup in China
reuters.com
reuters.com
And grindr isn't obscure or known only among gays, I've heard it joked about on late night television and light-hearted NPR shows. It's part of the zietgiest whether you're in the target demo or not.
I guess the domain space is inherently regional since it's about meeting locals but I'm still continually amazed at how unknown some of the largest players are outside their market.
It's like the regional scooter/rideshare/delivery competitors. I listen to UK podcasts and they act like everyone on the planet has heard of and constantly uses a company named "Deliveroo", which I, even in the startup world had only maybe tangentially heard of, but not in any significant way. It serves in 14 countries and has 13,000 employees and 20,000 deliverers.
[0] https://www.bloomberg.com/news/audio/2019-04-15/the-app-that...
I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people outside of China willingly send their most private info (including nudes & PII) to WeChat, Grindr, Tiktok, or any other Chinese apps.
In America, unauthorized dissemination of nude photos is both criminalized and widely reviled. What I don’t know is if it’s that difference or end to end encryption platforms that makes the difference.
I am not sure the contrast between the US and China is quite as stark as you imagine.
Whether or not a company has proper access control in place is mostly a function of whether they've had a scandal in the past that required them to lock things down. If it were widely known that Tencent employees are spying on WeChat users, they'd probably pretty quickly lose that access to stop the inevitable outrage.
[1] https://www.vice.com/en_us/article/xwnva7/snapchat-employees...
[2] https://www.nbcnews.com/tech/tech-news/uber-whistleblower-sa...
How much of this can be validated and proven to not be a masquerade (fake pictures / profiles are ridiculously common, as are bot accounts on the platform) is anyone's guess, but for blackmail purposes, that doesn't really matter.
Given how the app is marketed, and how pervasive it is throughout gay culture in the US (pretty much everyone in that community at least knows about it, whether they use it or not) just being shown to have an account on the service carries a pretty strong implication that the user is seeking a hookup of some kind. Now imagine if the target is married, or they're a closeted politician... it's pretty easy to see how dangerous the dataset can be from there.
Yes I know that not everybody sends face pics, but the majority do, and this is good enough to harvest for data.
Considering the large amount of points in OP's Marriott account, I highly doubt that was the highest-value target available. Considering it's already known that parts of their network were compromised, Occam's razor points to this being a vuln on the hotel's end.
https://www.reuters.com/article/us-marriott-intnl-cyber/marr...
It's easy to think of ways to combine all of these hack data streams into one database that can be cross referenced. You go to China on a visa, your entry to the country trips a flag in a system, and an intelligence agent shows up at your hotel to recruit you.