Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Snapchat Responds to Security Breach Allegations, Promises App Update

No apology for the leaks, though.

Snapchat

After weeks of controversy surrounding user security concerns, ephemeral-messaging service Snapchat responded to allegations of hacking on Thursday, promising an update to its mobile application that may assuage the ire of upset users.

In December, an Australian security firm detailed a vulnerability in Snapchat’s application programming interface that effectively allowed savvy outsiders to connect Snapchat account names to telephone numbers. Shortly after the disclosure, an anonymous group did exactly that; around 5 million user names and phone numbers were searchable through the tool the hacker group built.

After days of radio silence, Snapchat responded:

“We will be releasing an updated version of the Snapchat application that will allow Snapchatters to opt out of appearing in Find Friends after they have verified their phone number,” the company said in a blog post. “We’re also improving rate limiting and other restrictions to address future attempts to abuse our service.”

In its current implementation, Snapchat’s app allows new users to find their friends also on the service by matching user names to cellphone address books. It has become a commonplace practice over the past few years — a simple way to jumpstart growth and engagement on a new app service by making more connections between friends.

Snapchat was dismissive of the security firm’s original findings, effectively waving off concerns in a blog post. Four days later, the loophole was exploited.

Some things to note here: The anonymous group that built the exploit tool has positioned itself as a group of “white hat” hackers, pointing out vulnerabilities so that companies will end up fixing them. In its statement on Thursday, Snapchat didn’t see it that way, painting the group as “attackers.” Make of that what you will.

More importantly, Snapchat will allow people to opt out of being found via the Find Friends address book tool in a forthcoming app update. That could have implications for Snapchat’s ability to continue growing as quickly — especially under its current spotlight of media attention and Silicon Valley hype. At one point, Snapchat also allowed newcomers the ability to find their Facebook friends who use the app, though that functionality has been removed.

In addition, the company announced a new venue for outsiders to report security vulnerabilities in the future, via an email alias at security@snapchat.com.

Snapchat made clear in its statement that “no other information, including Snaps, was leaked or accessed.”

This article originally appeared on Recode.net.

More in Technology

Technology
The case for AI realismThe case for AI realism
Technology

AI isn’t going to be the end of the world — no matter what this documentary sometimes argues.

By Shayna Korol
Politics
OpenAI’s oddly socialist, wildly hypocritical new economic agendaOpenAI’s oddly socialist, wildly hypocritical new economic agenda
Politics

The AI company released a set of highly progressive policy ideas. There’s just one small problem.

By Eric Levitz
Future Perfect
Human bodies aren’t ready to travel to Mars. Space medicine can help.Human bodies aren’t ready to travel to Mars. Space medicine can help.
Future Perfect

Protecting astronauts in space — and maybe even Mars — will help transform health on Earth.

By Shayna Korol
Podcasts
The importance of space toilets, explainedThe importance of space toilets, explained
Podcast
Podcasts

Houston, we have a plumbing problem.

By Peter Balonon-Rosen and Sean Rameswaram
Technology
What happened when they installed ChatGPT on a nuclear supercomputerWhat happened when they installed ChatGPT on a nuclear supercomputer
Technology

How they’re using AI at the lab that created the atom bomb.

By Joshua Keating
Future Perfect
Humanity’s return to the moon is a deeply religious missionHumanity’s return to the moon is a deeply religious mission
Future Perfect

Space barons like Jeff Bezos and Elon Musk don’t seem religious. But their quest to colonize outer space is.

By Sigal Samuel