Exposed Server Leaks Real-Time Locations of Over 238,000 Family Tracking App Users

A popular family tracking app called Family Locator exposes highly sensitive real-time locations and plaintext passwords for hundreds of thousands of users due to an unprotected database. The developer remains unresponsive despite efforts to report the massive security breach.

A popular family tracking app called Family Locator exposes the real-time locations of more than 238,000 users because the developer leaves a backend MongoDB database completely unprotected and without a password. The app allows parents and spouses to track each other and set up geofenced alerts for places like school or work, but a security researcher discovers that anyone with knowledge of the server accesses this highly sensitive information.

The exposed database contains each user's name, email address, profile photo, and plaintext passwords, meaning no data is encrypted. It also stores the exact real-time coordinates of users and their linked family members, pinpointing their locations to within a few feet, along with labeled geofence zones like "home" or "work."

TechCrunch verifies the leak by creating a dummy account and watching its precise coordinates appear in the database within seconds, and a randomly contacted user confirms the accuracy of the exposed location data. Despite a week of persistent efforts by TechCrunch to alert the Australia-based developer, React Apps, the company provides no response and hides its contact information behind a private WHOIS record.

Read More at the original source →