Vulnerability in Bumble dating app reveals any user's exact location
robertheaton.com
robertheaton.com
Not very HN-y, but I recommend his serie on being a parent : https://robertheaton.com/married-with-kids/
return a || s || l ||
was a subtle jab at the early chat apps of the 90s (aol chat rooms)"X is a few miles away", "X is less than a,mile away", "X is several yards away" (which is, say, within 30-50 yards) — and more precision is not needed. If users want contact, they need to explicitly coordinate.
This approach, of course, should not be centered on the exact user location, but use some rough and slightly irregular grid, so that the best one could do is to determine the cell of that grid (again, like 50 yards wide), without any idea where in that cell the target user is.
This, and query throttling so that scanning more often than once in 5 minutes isn't possible.
It’s not that easy to obfuscate the coordinate in a way that the position is still relatively accurate (for the purpose of distance), and not “hackable” with some basic statistics.
My solution was just to Math.floor both of their lat/lng to be in increments of .25 miles. You could still use the triangulation trick to find that point, but .25 miles seemed like more than enough to obfuscate things.
Had I made the display in increments of miles only, that would have probably been even better.
https://robertheaton.com/2018/07/09/how-tinder-keeps-your-lo...
I suppose the downside is that this could put someone else at risk if the tweaked position happens to be on top of their house.
If you knew this was happening, you’d create N accounts, match with the same person, and average queries over account pairs.
Also, if the error is constrained to be the same, then the attack is reduced to estimating the radius of a circle where you are given points on the perimeter, which you should be able to do in very few queries (3?). I haven’t worked out the triangulation math but you’d basically solve for x^2+y^2=r^2.
2. If you can collect the offset location over a longer time, you can correlate it with likely travel paths (e.g. along major roads) to figure out what the offset is.
How exactly would you figure that out? Of course once you have a full working solution it's easy, but how do you distinguish this when you're just tinkering with it?
Within same zip code or two zip codes that border each other? "0 feet to (farthest distance between any two points within zip code(s))"
Zip codes farther apart? "(closest distance between any two points within zip code) to (farthest distance between any two points within zip code)"
No need to limit queries, no need to fuzz anything. No way to triangulate unless one person happens to live at the corner of three or more zip codes, in which case you could just pin them to one zip code as long as they are within a certain range of that zip code.
In areas where zip codes are unusually large (Alaska?) or unusually small (NYC?), you can substitute in some other chunk metric.
It just doesn't work.
For zip codes for example: There are single street zip codes (aka postal codes) all over Canada. And I'm not talking a large boulevard that goes across town. Literally one street that I can see one end from the other on easily.
Your try to make it less easy to find someone also makes it less good for the intended use case. Suddenly the app can only tell you if someone is in the same town or not because we combined the heck out of zips.
But the you realize that at the edges of whatever combination you chose you can find if someone is on one side or another of those areas. And these areas have borders on many sides so many cells to triangulate with and play the "are you here or on the other side".
So basically both requirements fight each other and guess which one won and what the results are.
It's been a long time since I've done online dating, and back then long-form OKCupid profiles were the norm, but instead of a distance radius, I always wished could draw a shape of interest roughly correlated with my local subway map and places that were convenient to walk to.
Screw that, in UK zip codes can be less than single building.
My zip code corresponds to flats 90-180 in my building.
[0] https://www.androidpolice.com/2021/01/05/telegrams-people-ne...
You left out a very important key word, "potentially." The article did not say a single person out of millions using Bumble was actually attacked via this method.
You can find the current/last known address of nearly any registered voter with a simple Google search. I'm not exactly sure why or how, but you can.
There are also services, that aren't exactly expensive, in which you can buy the phone number or address of nearly everybody in the U.S.
If you think being able to triangulate and pinpoint the location of somebody via a dating app constitutes grave danger... Well, there are much graver dangers that can't be fixed by any $ bounty all around us.
I'm not trying to say that what happened with Bumble isn't bad, and it makes the company look somewhat foolish, but in 2021, finding the location of somebody in most developed countries, aside from your ultra secure OPSEC average HN user, is quite a simple task.
To further illustrate the point, I believe trips to Tahoe are a non-trivial source of hookups, but being able to follow a potential match back to their chalet is not something anyone would voluntarily opt-into
If level of danger caused by a company was proportional to punishment, then every gun or tobacco (secondhand smoke) or fossil fuel company would have to have everyone in the org resign effective immediately.