How I was able to track the location of any Tinder user
blog.includesecurity.com
blog.includesecurity.com
Is Tinder still sending date of birth instead of a calculated age, like in the API example? It seems that no one there has given any thought at all to this topic other than to splash some water at the earlier fire. (IncludeSecurity, could you let us know whether Tinder is still sending the birth date data?)
I can understand that many people don't think through the consequences of sharing personal information, but it's hard to believe how many developers dealing with other people's information give it so little thought as well.
Not taking trilateration into account may have been a careless mistake. Sending literal GPS coordinates, however, means the developer probably didn't care.
In isolation, this vulnerability could be chalked up to carelessness. Coming on the heels of another even more egregious vuln, however, it (IMO) speaks to a IDGAF approach to privacy and security.
At least I hope that's not how this issue was fixed; article doesn't say.
I didn't propose rounding the distance as a solution--I mentioned it as an example of the kind of thought that should have started taking place in the mind of someone who was looking to fix the real location issue rather than making a quick change to stop complaints.
> but it's not always easy to see every possible security issue
The quality level of the original fix, in which they sent extremely precise distances, indicates that they put approximately 0 thought into analyzing the issue. It may not be easy to see /every/ possible security issue. But seeing many of them at all requires looking, and it appears they weren't doing much of that. They were getting some serious bad press in July, and their solution was a band-aid rather than an examination of their practices.
The solution may not be obvious, but the problem, especially once brought to one's attention, should have been. It's built into the nature of what they're doing, which makes it especially disturbing that they didn't care enough to put some more thought into it. Their response to the person who reported the problem reflects that as well.
Anyway, the point is processing this one sensetive information on server side really take little time. Maybe only several nanoseconds? The network latency is the botttleneck, not the proceesing of several bits of data.
Now the worst thing that will happen is someone triangulates a point say, 1/4 mile away from you.
Once you've found their Twitter/Instagram/whatever, then you have a name. Now you have their Facebook profile.
Especially with the facebook graph search you can do something like: "women who live near me named _____ who like _____ and graduated from ____." And then you have their facebook profile...
I am still sort of shocked that facebook just allows anyone to do this.
Facebook gives zero privacy to anyone using it. If I walk into a coffee shop and see someone interesting working there, I can just run a graph search and page through the results until I have their entire life history online.
Also again reduced precision on the reported distance won't fix the issue, you can sweep the map for changes in the last digit (by changing the attackers reported position)
They must reduce the precision of the users input not the reported distances precision.
ps. the problem in here is the accuracy not the precision
That's an interesting idea: randomly perturbing a user's reported location.
I've been developing a social network app that, in v1 (development was outsourced to someone else), sent the distance to a particular profile (I'm not sure how accurately). In v2, I wasn't sure what to do so I've left it out, but it's currently at number 3 on my TODO list.
In our case, it's pretty important to be able to do location sorting client side. We have the geo extensions for SQLite and are intending on using that.
So, question: if I randomly perturbed user's locations reported to the server by anywhere from 1-5 miles, would that be sufficient to ensure privacy, while also enabling the app feature, which only needs precision at the level of a few miles?
UPDATE: I thought about this some more, and what I'd do is the following:
1. Take the location of the device and make it imprecise, but accurate. For example, it could be anywhere within a five square mile radius, but it really would be within that radius.
2. On a per-user basis, pseudo-randomly but deterministically perturb the imprecise location for that user, to generate the stored location.
The second requirement is to prevent averaging multiple location updates for the same person over time, to pinpoint a location. Each user would have a different random, but deterministic offset for each five square mile area on the globe.
The perturbed location for that device in that area would be the same for everyone, so you wouldn't be able to merge the output of multiple users "view" of that device's location to increase accuracy, either.
I'd appreciate any and all feedback. Thanks.
So if you run a web or mobile app, scrub these on receipt by re-rasterizing (load .jpg/png -> copy image data -> save to a new file) using something like ImageMagick.
As long as the undocumented API is publicly accessible, and Tinder intends on reporting a users distance to each other (4.5 miles), it will always be possible to triangulate the position.
The only thing I can think of is to obfuscate the user ID in a way that you cant use the ID to guarantee a lookup of the same user.
Either way, it's trivial to take a lat and long and randomise a +/- on each value, or alternatively if you want a ciruclar error randomise a magnitude and angle and resolve the shift to lat and long.
Of course, you could probably do a lot of requests from different locations and intersect the results to find a more accurate position of the target with this fix too, though with some randomness to each request on the server side it will probably make it not worthwhile.
There is a way they can fix it properly though. What they need to do is report the actual position of the user, not the position relative to a position you give it. This may seem less secure but if it gave that latitude and longitude to within 3 miles, for example, it would be impossible to locate a user more precise than that.
"February 19th 2014 - As the issue does not seem to be reproducible and we have no updates from the vendor....blog post published."
So, this has been fixed now? The rest of the post wasn't very clear about that.
Having been in a similar situation, I don't think I would have waited as long as you did.
The easiest fix is just to send less precise location radius. The user does not care whether another user is 6 miles or 6.0000000001 miles away from him anyway.
I don't see how the attacker can read the JSON payload if SSL is used. Am I missing something?
Repeat for two more points and you have the same vulnerability.
EDIT: Ah, just fired up tinder, and saw the "x kilometres away from you" forgot about that haha :D