Privacy-Focused Social App True Exposes User Data in Server Lapse

A social networking app that promises to protect user privacy accidentally leaves a database exposed, leaking private messages, locations, and account tokens.

A social networking app called True, which promises to protect user privacy, exposes a massive amount of sensitive user data due to an unsecured server. The app, launched by virtual carrier Hello Mobile in 2017, leaves a database dashboard accessible to anyone on the internet without a password. This security lapse allows anyone to read, browse, and search through the private information of its users.

The exposed database contains daily server logs dating back to February, revealing registered email addresses, phone numbers, and the contents of private posts and messages. It also shows the last known geolocations of users and the contact lists they upload to find friends on the platform. Security researcher Mossab Hussein discovers the exposed data and confirms that none of the leaked information is encrypted.

Beyond exposing static personal information, the unsecured dashboard also leaks account access tokens that allow anyone to hijack user accounts without needing a password. After TechCrunch reaches out to the company, True pulls the dashboard offline, but chief executive Bret Cox refuses to answer questions about notifying affected users or reporting the incident to regulators. The incident stands in stark contrast to the app's core marketing promise of safeguarding user privacy.

Read More at the original source →