Yik Yak Hack
silverskylabs.github.io
silverskylabs.github.io
By the sounds of the Wikipedia article the developers were novices, however, which might be why they didn't think of doing this.
It's not the most secure, but it's actually a pretty elegant solution. The userIDs are never used anywhere else, just as a cookie session ID essentially. They should have had them expire though. Your public key solution is definitely more secure and would accomplish hthat.
2. Hack someone in your home (one of your kids for example)
3. Hack someone in a coffee shop
Generally, when someone thinks they're anonymous and they aren't, bad things are going to happen.
You can view all the posts they've made and make a reasonable guess as to which person it was, I suppose, but that seems like a pretty flimsy argument.
I'm long out of undergrad so I've never used this app, but I've read that YikYak is at least somewhat known for controversial content regarding schools, school employees/faculty, and fellow students.
Seems like there would've been just as much, if not more, incentive for a university administrator to want to get people's post histories in order to divine who posted a particular piece of content.
University campuses, where students are constantly using the free WiFi in cafes, are on private WiFi networks shared with friends, etc. Even if the University's own WiFi was magically invulnerable, there will be many associated venues ready for use of this exploit.
2. Give it a default name (e.g. 'linksys').
3. Capture packets.
4. Profit.
Twitter wasn't much of a honeypot, either, until activists and corporations started using it. Did Twitter know the exact moment that happened? No. They should have been secure long before that.
Based on some of the vague locations that Yik Yak gives with each post I'd say a little less than half are actually sent from on campus.
It's my understanding that unless the wireless access point is sufficiently smart, any device on the same network can claim to be the router and your phone won't know the difference. Even if an attacking device can't passively decrypt your radio transmissions, it won't matter because the router will actively decrypt and re-encrypt your packets before forwarding them on to the attacking device.
[0] http://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Mo...
Turnabout is fair play.
A user ID is fine to use as a public key, but it must be paired with something private. Generally some sort of unique, crypographically-secure auth token is fine when combined with forced HTTPS connections.
This is especially true of Flurry, which is tailored for connections directly from devices.
[1] http://android-developers.blogspot.de/2011/09/androids-http-... [2] https://developer.android.com/training/articles/security-ssl...
And, while reading the article, we all probably were: "No, please, I hope they didn't do what I'm afraid is following now ..."
I'm not sure if I'd ever want SilverSky (the firm behind this) to have my money.
The original source appeared on their blog on Friday, December 3rd after Yik Yak had released an update to the App Store.
I doubt the users find the app pointless, but there isn't much reason to steal someone's account. You can't even link it to their real name to blackmail them.
Even the article has to fall back to saying you have to just keep monitoring packets with that IP and hope the user uses some non-HTTPS web site that reveals their name. Although, honestly, most ISPs don't give you a static IP any more so the same user could be a different IP address multiple times a day.
How do you get Edward Snowden's yik yak userID? This post doesn't show anything that lets you do this from a posted yak.
Further, you can obtain a new userID just by reinstalling the app, so the information can be totally destroyed by the user as well.
It's very hard to leverage this attack into anything more interesting than getting a userID banned.
http://www.theguardian.com/world/2014/oct/16/-sp-revealed-wh...
That's not the point of Yik Yak. You're just broadcasting to the community, and rarely is something super incriminating posted, at least in my college's community.