{"id":4582,"date":"2024-07-22T13:18:55","date_gmt":"2024-07-22T18:18:55","guid":{"rendered":"https:\/\/www.darkreading.com\/application-security\/swipe-right-for-data-leaks-dating-apps-expose-location-more"},"modified":"2024-07-22T13:18:55","modified_gmt":"2024-07-22T18:18:55","slug":"swipe-right-for-data-leaks-dating-apps-expose-location-more","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/22\/swipe-right-for-data-leaks-dating-apps-expose-location-more\/","title":{"rendered":"Swipe Right for Data Leaks: Dating Apps Expose Location, More"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt7d1a66c36d24fab3\/66885573184b2a7a04f4cafd\/_Tinder_MarceldeGrijs_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/arid-viper-camouflages-malware-in-knockoff-dating-app\" rel=\"noopener\">Using dating apps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> to find love can already be a daunting process. Now, security researchers in Belgium have found that dozens of these apps may threaten users&#8217; privacy too, by leaking their sensitive data and, worryingly, even their exact location.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Karel Dhondt and Victor Le Pochat, both researchers at Belgian university KU Leuven, analyzed 15 location-based dating apps to see what type of user data a malicious actor might extract from them.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">It turns out that all 15 of the apps leaked some type of sensitive user data &#8220;that could be abused by the attacker&#8221; beyond what people share publicly with the app through their public profile or in their personal settings. Le Pochat explains in an interview with Dark Reading that the researchers based their definition of &#8220;sensitive&#8221; data on the Europe Union&#8217;s <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/meta-hit-1-3b-record-breaking-fine-gdpr-violations\" rel=\"noopener\">General Data Protection Regulation (GDPR)<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, which puts data such as ethnic origin, political opinions, sexual orientation and\/or gender, and health information into this category.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Our main objective was that we specifically wanted to see what risks there are [in terms of] data sharing with other uses,&#8221; he says. &#8220;If I&#8217;m maliciously on the app, what can I learn about the users around me?&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The apps analyzed include some that are popular globally, such as <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/mobile-security\/tinder-and-instagram-make-the-blacklisted-apps-list-in-appthority-q4-enterprise-mobile-security-pulse-report\" rel=\"noopener\">Tinder<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, Bumble, Grindr, Badoo, OKCupid, MeetMe, and Hinge, as well as apps that are popular in certain regions, such as Asia&#8217;s TanTan and Europe&#8217;s Meetic.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Sensitive Data and Location Exposed\">Sensitive Data and Location Exposed<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Le Pochat stressed the ease with which someone could access user data from the apps. &#8220;To be clear, we did not hack the server in any way,&#8221; he explains. &#8220;If I am using the app, maybe with some additional technical proficiency \u2026 and looking at the traffic that&#8217;s coming in and going out, that already leaks this information.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Moreover, in the case of six of the apps (including three that are well known and widely used: Bumble, Gindr, and Hinge), a malicious actor could pinpoint the exact physical location of someone using the app &#8220;through interacting with the app and understanding how distances were being calculated,&#8221; Le Pochat says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researchers plan to <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/lepoch.at\/files\/dating-apps-usesec24.pdf\" rel=\"noopener\">unveil the findings of a paper<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> on their research, called &#8220;Swipe Left for Identity Theft: An Analysis of User Data Privacy Risks on Location-based Dating Apps,&#8221; in a session of the same name at the upcoming Black Hat USA 2024 conference in Las Vegas.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dhondt and Le Pochat have previously collaborated to conduct similar research <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/popular-fitness-apps-leak-location-data-even-when-users-set-privacy-zones\" rel=\"noopener\">identifying how fitness apps<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> such as Strava leak sensitive location information of users, even when they&#8217;ve used in-app features to specifically set up privacy zones to hide their activity within specified areas. That work was presented at Black Hat Asia in 2023.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The examination of dating apps stemmed from Dhondt&#8217;s PhD research, which focused on location privacy, specifically &#8220;if I can extract location data from other users on these service,&#8221; he tells Dark Reading. The two researchers then extended their research into seeing what other type of data they could access.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"GPS Method Pinpoints Location\">GPS Method Pinpoints Location<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">To exploit apps to pinpoint a user&#8217;s exact location, an actor can use a method called trilateration that is similar to how GPS satellites track location. Location-based dating apps rely on the general area of where someone currently is to deliver potential matches of other people nearby.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Using trilateration, the researchers found that they could take the known distance from their location to the victim and construct a series of circles with intersection points that lead to a precise location of the app user with varying accuracy.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Grindr, for instance, delivered what&#8217;s called &#8220;exact distance trilateration,&#8221; which is accurate to the meter even for users who have hidden distance information within their profiles. This can be dangerous for users of the app, which is used predominantly by members of the LGBTQ community, especially in countries where homosexual activity is illegal, such as Egypt, the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Dhondt and Le Pot also could pinpoint &#8220;rounded distance trilateration&#8221; in apps that used rounded distances rather than exact distances for their users locations, as well as &#8220;oracle trilateration,&#8221; which uses an oracle that indicates through a binary signal whether a victim is located within a defined \u201cproximity distance\u201d from a would-be threat actor. The apps Badoo, Bumble, Hinge, and Hily in particular were susceptible to the latter.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Determining the exact location of someone on a dating app without their knowledge clearly can pose a physical threat to them due to the intimate nature of interactions that occur in these scenarios, the researchers noted.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Given that it&#8217;s related to dating, which really gets to people&#8217;s emotions and feelings, any privacy leaks or dangers are really exacerbated,&#8221; Dhondt says. &#8220;If people are hurt, they may want to hurt back. That&#8217;s why it&#8217;s important that people&#8217;s privacy and safety is well-maintained by these apps.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Traffic Reveals Data\">Traffic Reveals Data<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In terms of how much personal data is being shared via the various dating apps, some of the apps request and share more personal data than others. Researchers took a look under the hood of the apps to examine API traffic that&#8217;s automatically sent to a person&#8217;s device and can easily be inspected by a malicious actor. They found that all 15 of the apps have some form of <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/api-security-the-big-picture\" rel=\"noopener\">leak in their API<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;In most cases, the server is just pushing more data than necessary to the application interface,&#8221; Le Pochat says. &#8220;Maybe in the app it only shows a person&#8217;s age, but the API is showing the person&#8217;s exact birthday.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some of this data could be deemed sensitive and could expose private info that a person deliberately omitted from their dating profile. For example, in Tinder, people can set their gender to be hidden. However, &#8220;even if you had set a custom non-binary gender, this also was sent in the background traffic and could be read by anyone even if it was not shown in the app,&#8221; Le Pochat says.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Vulnerabilities Fixed, Mostly\">Vulnerabilities Fixed, Mostly<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The researchers contacted all of the companies with vulnerable apps, and all of the location leaks in the apps that allowed for trilateration have since been fixed, they said. However, some of the apps are still leaking data because some of the companies, while acknowledging the leak, claimed it was &#8220;intended behavior&#8221; of the apps, the researchers note.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">What this amounts to is that while millions of people all over the world share very personal information with strangers via dating apps, maybe in some cases, they shouldn&#8217;t, because it may not be totally secure, Dhondt notes. He urged people to &#8220;be very conscious about what info you share.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;We see apps nudge people to share a lot of information to get more matches,&#8221; he says. &#8220;Maybe they should not. What [data the apps] don&#8217;t have, they can&#8217;t leak.&#8221;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/application-security\/swipe-right-for-data-leaks-dating-apps-expose-location-more\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Using dating apps to find love can already be a<\/p>\n","protected":false},"author":12,"featured_media":4583,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4582","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=2560%2C1362&ssl=1",2560,1362,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=300%2C160&ssl=1",300,160,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=640%2C340&ssl=1",640,340,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=640%2C341&ssl=1",640,341,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=1536%2C817&ssl=1",1536,817,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=2048%2C1089&ssl=1",2048,1089,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=1024%2C545&ssl=1",1024,545,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/swipe-right-for-data-leaks-dating-apps-expose-location-more-scaled.jpg?fit=2560%2C1362&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4582","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4582"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4582\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4583"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4582"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4582"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4582"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}