Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.
Still a pretty bad vulnerability and pretty awful that grindr was ignoring it.
Not only that, but emails are very easy to find these days with tools like apollo.io.
They can tell the user to await an e-mail from them with the confirmation link. Then if the e-mail address is already in use, send an e-mail saying, "somebody, probably you, tried to register as <new-username> on <site> but we have you down as <old-username> already". Otherwise, send a normal confirmation link.
This also makes it very easy to lose conversations/content.
I doubt that; I bet most users use whatever Gmail/etc personal address they use for other non-work accounts.
I know of very few friends who go through the process of creating a burner email account to sign up for Grindr. Now, maybe that’s different in other countries, but at least in the States, I would bet good money you can guess their Gmail address.