Users from 4chan claim to have discovered an exposed database hosted on Google’s mobile app development platform, Firebase, belonging to the newly popular women’s dating safety app Tea. Users say they are rifling through peoples’ personal data and selfies uploaded to the app, and then posting that data online, according to screenshots, 4chan posts, and code reviewed by 404 Media.

top 50 comments

sorted by: hot top controversial new old
[–] 214 points 1 year ago (32 children)

This is what happens when you decide to vibecode a service with zero attention to safety or web development. This is why you don't immediately jump onto a new service without it being vetted properly. Now one of the worst communities on the Internet is in possession of over a hundred thousand women's driving licenses and faces. This is going to be an absolute disaster.

  • source
  • hideshow 32 child comments
  • [–] 163 points 1 year ago (4 children)

    This is ALSO why no service should ever require or get my driver's license information. Fuck that. Also, yet another Constance to those who can't afford a car or want to improve the environment by living car free.

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (2 replies)
  • [–] 27 points 1 year ago

    To be fair, I’m not sure why firebase even has a public access option. That’s a recipe for issues.

    Though if it’s anything like Google Cloud Store, they hopefully make it very clear that your bucket is public.

  • source
  • parent
  • load more comments (5 replies)
    [–] 155 points 1 year ago (32 children)

    People sign up to app intended to share personal information about others without their permission, end up having their own personal information shared without permission - the irony is impressive.

  • source
  • hideshow 32 child comments
  • [–] 109 points 1 year ago (26 children)

    At first I was going to call bullshit because I thought you were exaggerating and being ridiculous.

    Nope. That's the app. "Anonymous" sharing of pictures and info of other people. Presumably without their permission. That's fucked up.

  • source
  • parent
  • hideshow 26 child comments
  • [–] 50 points 1 year ago (25 children)

    Yeah. I mean, I get it. The concept of the app makes sense. And I would be that, on average, it is/would be used for good.

    On the other hand, as a guy, the idea that people are out there sharing reviews of me as a person on the open internet, and I have no way of knowing this, is deeply unsettling. Like, I haven't done anything wrong - just the whole concept feels very gross.

  • source
  • parent
  • hideshow 25 child comments
  • load more comments (24 replies)
  • [–] 22 points 1 year ago (4 children)

    I think it depends on people's intent and purpose for using this service. I'm overall not a fan of someone taking and sharing pictures of me without my consent, or making claims that can't be defended...

    The group of women legitimately using it for safety is fine, in a general sense.

    The group of women using it as gossip and entertainment is not.

  • source
  • parent
  • hideshow 4 child comments
  • load more comments (1 reply)
  • [–] 114 points 1 year ago (11 children)

    I would not under any circumstances give my drivers license to a for profit app. I don’t even like to give my email.

  • source
  • hideshow 11 child comments
  • [–] 40 points 1 year ago (10 children)

    apparently there's some law in the UK that mandates it now 🙄

  • source
  • parent
  • hideshow 10 child comments
  • [–] 33 points 1 year ago (5 children)

    Well UK, have the day you voted for I guess

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (3 replies)
  • load more comments (4 replies)
  • [–] 103 points 1 year ago* (last edited 1 year ago) (16 children)

    Wow that was fast.

    I did not even know this app existed untill about 8 hours ago.

    Already comprimised.

    EDIT: Also, lol, this arguably is not even largely a hack.

    These idiots just had everything stored in a fucking publically accesible firebase bucket... amazing.

    They didn't delete anything they claimed to.

    Either way you look at it, anywhere on the spectrum from:

    A ] A bunch of women reasonably concerned for their safety

    B ] A bunch of gossip mongers

    ... well, they've now all been doxxed, ironic from each angle.

    What a fucking disaster.

  • source
  • hideshow 16 child comments
  • load more comments (16 replies)
    [–] 99 points 1 year ago (15 children)

    I can't open the article, but I think I read that this was hosted on an unprotected bucket. Assuming that's correct I wouldn't say this was a breach. A better headline would be "Women dating safety app 'Tea' exposed women's PII".

    To be 100% clear, I'm not excusing the hackers. I don't believe it's morally correct to publicize something because it is exposed. For folks curious about that you can look into how to ethically disclose vulnerabilities. I still view this as doxxing. I still believe what the hackers did should be a criminal offense, it's just that I also believe the app holds a ton of the blame as well. How can you proclaim to be about keeping women safe while putting them at risk? That should be punished as well.

    Like if the storage facility you trusted to hold your stuff never had locks on the doors, shouldn't they take a lot of the blame as well as the thief who found out a door was unlocked?

  • source
  • hideshow 15 child comments
  • [–] 43 points 1 year ago (10 children)

    The bigger problem is trying to get the mainstream that would read an article like that to understand the technical difference between hacking and accessing unsecured data.

  • source
  • parent
  • hideshow 10 child comments
  • [–] 26 points 1 year ago (6 children)

    One of the definitions of hacking is illegally gaining access to a computer system. It doesn't need to involve any sort of exploit. Stealing from an unlocked home is still stealing. Gaining access to a system by phishing is still hacking. Leaking data that is technically publicly accessible that isn't meant to be publicly accessible is still hacking.

    Not that I suspect anything good from 4chan but the proper thing to do would be to disclose to Tea that their data is public and allow them to fix the problem. The ethics of vulnerability disclosure still apply when the vulnerability is "hey you literally didn't secure this at all."

  • source
  • parent
  • hideshow 6 child comments
  • load more comments (6 replies)
  • load more comments (3 replies)
  • load more comments (4 replies)

    Not sure if this is ironic that the users are now less safe after using the safety app. But I still feel bad for the users. Dating is hard enough without the fear of being harmed.

  • source
  • [–] 83 points 1 year ago* (64 children)

    The replies in this thread are disturbing, giving me a sense that Lemmy has a misogyny problem; maybe I was naïve, but I expected outrage about 4chan doxxing women trying to protect one another, instead I see lots of revenge enjoyment as if being doxxed on 4chan is justice for ... warning one another about dangerous men they encounter when dating?

    The inability to empathize and take seriously the threats posed to women or to understand their motivation to protect one another is alarming.

    There is no good faith extended, but also no evidence presented that instead of safety the app was just for gossip, it's just taken as assumed that women are wrong for using Tea and they all deserve to be doxxed.

  • source
  • hideshow 64 child comments
  • [–] 51 points 1 year ago (10 children)

    I'm all for groups of safe spaces for women. Especially when it's designed to keep them safe while dating. I have my doubts that Tea was that. Even if it was advertised as such, "tea" is slang for the word gossip. I've heard stories from several sources that it was used to dox people as well. Not saying what happened to the users is right. I think some users here are just feeling smug that this might cause the app to fail or shut down.

  • source
  • parent
  • hideshow 10 child comments
  • load more comments (10 replies)
  • [–] 45 points 1 year ago (5 children)

    It isn't the women who are wrong; it's the app developer and 4chan. But setting aside the data breach, creating a Yelp for dating is a ticking time bomb. They were going to get sued out the ass, data breach or no data breach. I don't know how many times this needs to happen, but I guess web developers have the memory of goldfish. There have been several attempts at something similar that got shut down for the obvious reasons. Making a website that rates human beings is always going to be a legal minefield.

  • source
  • parent
  • hideshow 5 child comments
  • load more comments (5 replies)
  • [–] 32 points 1 year ago (1 child)

    The Tea app is agnostic. While its purpose and main use case was made for the safety of women in the dating scene, it was inevitably used to spread exaggerated or misleading information about otherwise innocent men. Imagine being a privacy-conscious individual, and breaking up with a toxic woman. She could go on to spread lies about you and even upload pictures of you to the reverse image search/ai. So even if you were doing everything right from a privacy standpoint, you’d still end up in someone’s private database, subjected to ai training, shared with the government, or who knows what. While I do see the purpose of apps like these, they can effectively take away someone’s privacy/dignity without them even knowing about it. Now imagine being a 4channer, someone probably even more privacy-conscious than lemmings, and possibly experiencing mental disorders like paranoid schizophrenia or autism; of course they’re drawn to hacking an app that would destroy their privacy. They are not sane individuals, so this event really was inevitable.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 30 points 1 year ago

    I think you are misunderstanding why people are upset.

    It's horrible that these women were doxxed.

    It's also horrible that a subset of women were doxxing men, which is what brought this negative attention to the site.

    Misogyny is real in our society, misandry is real.

    Saying things happen for sexist reasons when it was for a logical reason does a disservice to movements that seek equality.

    The internet also cheered on the 4chan PII leak that happened recently, not becauase it's a male dominant space, but because they do shitty things like dox people.

  • source
  • parent
  • load more comments (32 replies)
    [–] 82 points 1 year ago (7 children)

    Maybe I'm just getting old, but the idea of "verifying" my real identity to a faceless website or mobile app is abhorrent.

    I guess it doesn't help that governments in some countries (UK, Australia that I know of) are encouraging this bullshit with Trojan horse laws claiming to protect children from adult websites / social media.

    Can't help but think there is also an element of pot meet kettle here, when users of an app designed to dox and slander people without their knowledge are now the ones getting doxxed themselves.

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    [–] 52 points 1 year ago

    Protecting our users' privacy and data is our highest priority. We are taking every necessary step to ensure the security of our platform

    Since sensitive data was put on a public bucket, maybe they meant it was their lowest priority?

  • source
  • [–] [S] 50 points 1 year ago (9 children)

    My friend came over and told me a story about this crazy date she was on. The guy love bombs her, sets her up with a massage, then in the morning, goes out and eats McDonalds alone and ghosts her. Then repeats every few weeks with love bombs.

    I shared that with my discord group and someone said they know that guy too.

    Im assuming that's what Tea is for.

  • source
  • hideshow 9 child comments
  • load more comments (9 replies)
    [–] 46 points 1 year ago (7 children)

    No sympathy from me whatsoever. The app was designed to allow these women to anonymously post personal information about other people. Fuck 'em. Turnabout is fair play. As my kindergarten teacher used to say, "you get what you get and you don't pitch a fit".

  • source
  • hideshow 7 child comments
  • load more comments (7 replies)
    [–] 45 points 1 year ago (4 children)

    This is why there should be a nationwide rule that PII data should be deleted after the users identity has been verified

  • source
  • hideshow 4 child comments
  • load more comments (4 replies)
    [+] 43 points 1 year ago* (last edited 1 year ago)
    [–] 38 points 1 year ago (2 children)

    Reading these incredible comments has revealed a large piece of what was named as the reason for lemm.ee shutting down.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 36 points 1 year ago (2 children)

    Never upload PII to social media

    Your privacy is not legally protected.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 32 points 1 year ago (1 child)

    What are the chances of this being the main reason for the app's existence?

  • source
  • hideshow 1 child comment
  • [–] 27 points 1 year ago (3 children)

    I thought 4chan shut down permanently like 2 months ago?

  • source
  • hideshow 3 child comments
  • load more comments (2 replies)
    [–] 26 points 1 year ago

    Hungry data privacy lawyers when they learned about Tea this week:

  • source
  • [–] 25 points 1 year ago (6 children)

    I had been under the impression that 4chan had also basically died due to their own site getting hacked

  • source
  • hideshow 6 child comments
  • load more comments (4 replies)
    load more comments
    view more: next ›