187

In a new academic paper, researchers from the Belgian university KU Leuven detailed their findings when they analyzed 15 popular dating apps. Of those, Badoo, Bumble, Grindr, happn, Hinge and Hily all had the same vulnerability that could have helped a malicious user to identify the near-exact location of another user, according to the researchers.

While neither of those apps share exact locations when displaying the distance between users on their profiles, they did use exact locations for the “filters” feature of the apps. Generally speaking, by using filters, users can tailor their search for a partner based on criteria like age, height, what type of relationship they are looking for and, crucially, distance.

To pinpoint the exact location of a target user, the researchers used a novel technique they call “oracle trilateration.”

The good news is that all the apps that had these issues, and that the researchers reached out to, have now changed how distance filters work and are not vulnerable to the oracle trilateration technique.

Neither Badoo, which is owned by Bumble, nor Hinge responded to a request for comment.

top 7 comments
sorted by: hot top controversial new old
[-] doctortran@lemm.ee 12 points 1 month ago* (last edited 1 month ago)

Seems weird to include Grindr with all the others, given Grindr is an actual radar. The whole point is that you're supposed to be able to see who's near. At about a thousand feet, the distance starts getting murky and obfuscated, but still, you're supposed to be able to know when somebody is close, down to a couple hundred feet.

In that case, at least, the user base knows what they're getting into when they use the app.

[-] Zerfallen@lemmy.world 7 points 1 month ago* (last edited 1 month ago)

Grindr reports down to single digit metres... That level of accuracy is certainly not needed and potentially dangerous. I've had stalker issues with Grindr before.... Imo the radar aspect can be preserved while simply capping the accuracy or reporting at "<500m", because seriously that's close enough to know someone is literally less than 5 minute walk from you.

Sniffies is a similar app, but includes an option to randomise your location within a certain radius that you can set. So you can still determine people are "nearby" or get an idea of their general distance and location, without being able to literally hunt them down.

[-] werefreeatlast@lemmy.world 1 points 1 month ago

I don't understand why people use Sniffles anymore. They used to allow you to post comments while not paying. Now you gotta pay up for everything. It's not stupid for them but it means that if you want to find someone to 💕 love 😘, 💞, you gotta give someone else money. That makes no sense to me whatsoever. I propose that the entire community create icons with numbers...like number 234... Put it on the sniffies AP as your icon, and then come over to a local Lemmy instance and talk away. It's ridiculous to have to pay for love. WTF!

[-] ivanafterall@lemmy.world 3 points 1 month ago* (last edited 1 month ago)

Dang, I didn't know that. That's cool. I can see how that might be problematic on Tinder, etc... but it'd be pretty neat.

[-] another@discuss.online 4 points 1 month ago

When the apps also show the distance down to feet, you can triangulate their exact potion by moving your phone’s gps location.

Always choose the “don’t show” option. It’s not perfect, but it makes triangulation more difficult.

Also, pro tip, always ask new people to show their face while doing something that people don’t normally do, like holding up three fingers or a scrap of paper with text YOU chose.

Obviously AI makes things more difficult, but this weeds out most of the “average” catfishers.

[-] technocrit@lemmy.dbzer0.com 2 points 1 month ago

Amazing clickbait here. Nobody "allowed stalkers to pinpoint" people. It was technically possible but apparently never happened. And now it's fixed.

[-] Mubelotix@jlai.lu 1 points 1 month ago* (last edited 1 month ago)

I found the same issue in Slowly when it had only 3 million users. They refused to fix it, feel free to exploit (you can enumerate their entire userbase with a simple counter)

this post was submitted on 31 Jul 2024
187 points (97.9% liked)

Technology

58123 readers
4039 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS