Subscribe

0

  • Sign in with Email

By clicking the button, I accept the Terms of Use of the service and its Privacy Policy, as well as consent to the processing of personal data.

Don’t have an account? Signup

  • Bookmarks
  • My Profile
  • Log Out
  • News
    • Tech Buzz
    • Appointments
  • StraightTalk
    • Interview
    • Our Podcast
  • CXO of the week
    • CxO Insights
    • Founders
    • Strategy
  • Startup Circle
    • Funding
    • Spotlight
    • Entrepreneur of the month
  • Emerging Tech
    • Mobility
    • IOT
    • Generative AI
  • More
    • Virtual Events
    • Future Workspace
    • Social
    • C-Change 2017
    • Resources
    • Digital Transformation
    • Vlogs
      • Technews of the week
      • PCB Playbook Series
      • Interviews
      • Webinars
    • Nextgenit
    • SMB
    • Governance
    • Enterprise
ad_close_btn
  • News
  • straight-talk
  • CxO Of The Week
  • Startup Circle
  • Mobility
  • IoT
  • Generative AI

Powered by :

You have successfully subscribed the newsletter.
Social Tech Buzz

Tinder's security flaw gives access to user's account using only the phone number

author-image
CIOL Writers
22 Feb 2018 07:24 IST

Follow Us

New Update
Tinder Passport For Free

A major vulnerability has been revealed in Tinder app by security researchers at AppSecure. The issue left Tinder accounts potentially exposed to infiltrators by only requiring a phone number to log in. This was due to issues with the Facebook API and the Tinder app’s login process, both of which have already been fixed.

Advertisment

The vulnerability was first reported by ethical hacker Anand Prakash in a Medium blog post. The account takeover vulnerability was due to Facebook’s Account Kit, which has since been fixed. Account Kit is used by Tinder to allow for mobile phone number logins.

The blog states, "When a user clicks on login with a phone number on Tinder, they are redirected to Accountkit.com for login. If the authentication is successful then Account Kit passes the access token to Tinder for login. The vulnerability essentially exposed the access tokens of users, which means that hackers who obtained a valid access token could easily take over a user’s account."

After being alerted to the security vulnerability, Tinder has since patched it which means that users should be safe moving forward.

Advertisment

Prakash, who reported the vulnerabilities to both Tinder and Facebook was awarded $5,000 by Facebook and $1,250 by Tinder.

security tinder
Subscribe to our Newsletter! Be the first to get exclusive offers and the latest news
logo

Related Articles
Read the Next Article
Latest Stories
Subscribe to our Newsletter! Be the first to get exclusive offers and the latest news

Latest Stories
Latest Stories
    Powered by


    Subscribe to our Newsletter!




    Powered by
    Select Language
    English

    Share this article

    If you liked this article share it with your friends.
    they will thank you later

    Facebook
    Twitter
    Whatsapp

    Copied!