Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Snapchat Account Leak Raises Questions About It and Other Mobile Apps

In addition, it turns out Snapchat was warned about the current vulnerability.

Ten lines of code appears to have been all that stood between Snapchat, a mobile photo-sharing app, and what has morphed into an embarrassing security incident that seems to have compromised the phone numbers and user names of more than 4 million users.

A feature that allowed Snapchat users to search for their friends in their phone’s address book has been turned into something that a stalker might like to use. An Australian security firm, Gibson Security, chose Christmas Day to disclose a vulnerability in Snapchat’s API that would allow someone to create a tool to match Snapchat account names to phone numbers.

Then on New Year’s Eve, someone did exactly what the GibSec researchers warned about. Well, almost: They created a website called SnapchatDB (the site has since been suspended) that essentially leaked the account names and phone numbers of nearly 5 million Snapchat users.

Since then, the people who did it have said their primary motivation was to raise the pressure on Snapchat to fix the vulnerability. GibSec, which describes itself on its website as “poor students,” said on Twitter that it had nothing to do with the creation of the SnapchatDB. But it has created another tool, one that’s still working, which you can find here. In both cases, the final two digits of the phone numbers have been blocked out.

And in a twist that, if true, would be typical of these cases, GibSec said it tried to notify Snapchat about the vulnerability back in August. When media attention shed light on the vulnerability, Snapchat, in a company blog post, dismissed it as “theoretical.” But it did say it has added new security countermeasures, though it hasn’t said anything about what they are.

A Snapchat representative did not immediately respond to a request for comment.

The basic vulnerability had to with something called rate limiting, which would put a cap on the number of searches a person or program might make for a number using the Snapchat API. Without those rate limits — the theoretical limit for these searchers, as Naked Security blogger Paul Ducklin noted on Dec. 27 — appeared to be about 7 million a day.

What’s less clear is what this does to Snapchat users’ confidence in the product. Billed as an app that lets you send photos that disappear after 10 seconds, it has an air of naughty permissibility about that has appealed to teens and twentysomethings, and tends to raise alarm bells in the minds of parents. Questions about whether or not those photos really do disappear have persisted for some time. (Answer: They really don’t.)

And even with the new countermeasures in place, the anonymous hackers behind SnapchatDB told the Verge that the problem isn’t really fixed.

“Snapchat could have easily avoided that disclosure by replying to Gibsonsec’s private communications, yet they didn’t. Even long after that disclosure, Snapchat was reluctant to take the necessary steps to secure user data. Once we started scraping on a large scale, they decided to implement minor obstacles, which were still far from enough. Even now the exploit persists. It is still possible to scrape this data on a large scale.”

The exploitation of the vulnerability also raises some larger issues about how other apps access address books on phones. There have been cases where this sort of feature has raised privacy and security concerns. If you’re building apps that tap the address book, today would be a good day to study what has been going on with Snapchat these last few days and then go back and check your own code.

This article originally appeared on Recode.net.

More in Technology

Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram
Technology
What happened when they installed ChatGPT on a nuclear supercomputerWhat happened when they installed ChatGPT on a nuclear supercomputer
Technology

How they’re using AI at the lab that created the atom bomb.

By Joshua Keating
Future Perfect
Humanity’s return to the moon is a deeply religious missionHumanity’s return to the moon is a deeply religious mission
Future Perfect

Space barons like Jeff Bezos and Elon Musk don’t seem religious. But their quest to colonize outer space is.

By Sigal Samuel