Oneitiscel
Failed Jestermaxxx LDAR Extraordinaire
★★★★★
- Joined
- Nov 13, 2018
- Posts
- 6,972
- Online time
- 2d 11h
A rival Tea app for men is leaking its users' personal data and driver's licenses | TechCrunch
The newly launched app, now trending on Apple's App Store, contains at least one major security flaw that exposes the private information of its users, including their uploaded selfies and government-issued IDs.
TechCrunch has found at least one security flaw that allows anyone access to data belonging to TeaOnHer app users, including their usernames and associated email addresses, as well as driver’s licenses and selfies that users uploaded to TeaOnHer. Images of these driver’s licenses are publicly accessible web addresses, allowing anyone with the links to access them using their web browser.
In one case, TechCrunch saw a list of posts shared on TeaOnHer appended with each user’s email address, display name, and self-reported location.
TechCrunch is withholding some of the details of the bugs so as to not help malicious actors access anyone’s data. The app’s maker did not respond to emails from TechCrunch asking who we can report the flaws to. As such, TechCrunch is publishing this report with limited details of the issue, given the app’s current popularity and the risk faced with using the app.
The bug also exposes the number of users the TeaOnHer app has, which is about 53,000 users at the time of publication.
TechCrunch also identified a potential second security issue, in which an email address and plaintext password belonging to the app’s creator, Lampkin, was left exposed on the server.





