x

Like our Facebook Page

   
Early Times Newspaper Jammu, Leading Newspaper Jammu
 
Breaking News :   Speaker warns MLAs over giving publicity to House business notices | CM Omar expresses inability to announce new dates for Khelo India Winter Games 2025 | Speaker warns MLAs over giving publicity to House business notices | Those with slave mentality mock India’s religious beliefs: PM Modi | DIG CKR, CRPF chair joint security review meeting | SC to hear on Monday plea over for treating HIV patients | Come to Maha Kumbh, one of century’s rarest events: Yogi | NC Govt committed to empower Sikh community: Dr Farooq | NC Govt committed to empower Sikh community: Dr Farooq | 3 residential houses gutted in Sgr blaze | Rescue teams inch closer to trapped workers | Woman injured by gunfire in Rajouri | Sunhere Pal Buzargo Ke Sung’ held at Old Age Home | SCERT, DIET Kishtwar conduct 5-Day Training | ROF, NDS & VKMI Host Cultural Program “Sunhere Pal, Bazurgo Ke Sang” | AIKS organizes Mother Tongue day event at IGNCA Delhi | Miss World undeclared’ highlights inner beauty over racial bias | TNWS organizes police-public meeting with SHO Trikuta Nagar | 507th Kabir Nirvan Divas Commemorated | Synergetic green warriors foundation leads cleanliness drive | Third Phase of Nirankari Mission’s ‘Project Amrit’ concludes successfully | First e-FIR | Back Issues  
 
news details
Hackers can crack your Tinder account password with just a phone number
2/22/2018 11:33:11 AM
Agencies
It was reported last month that online dating app Tinder had a security flaw which allows strangers to see your photos and matches. Now, Appsecure has discovered a new flaw which is potentially more damaging.

The new vulnerability allows infiltrators to get access to your account with the help of your login phone number. But there is no need to worry because the good news is that after being alerted by Appsecure, Tinder has fixed the issue.

According to Appsecure, the hackers could have taken advantage of two vulnerabilities to attack accounts. One is Tinder's own API and the other is in Facebook's Account Kit system which Tinder uses to manage the logins
Basically, the vulnerability exposed the access tokens of the users. If a hacker is successful in obtaining the valid access token then he/she can easily take over a user account.

Anand Prakash from Appsecure explained how the attack works on Tinder, "The user clicks on Login with Phone Number on tinder.com and then they are redirected to Accountkit.com for login. If the authentication is successful then Account Kit passes the access token to Tinder for login."

"Interestingly, the Tinder API was not checking the client ID on the token provided by Account Kit.This enabled the attacker to use any other app's access token provided by Account Kit to take over the real Tinder accounts of other users," he added.

Appsecure has already received awards of $5,000 and $1,250 by Facebook and Twitter through the companies' bug bounty programs for reporting such security flaws.
  Share This News with Your Friends on Social Network  
  Comment on this Story  
 
 
 
Early Times Android App
STOCK UPDATE
  
BSE Sensex
NSE Nifty
 
CRICKET UPDATE
 
 
 
 
 
 
 
 
   
Home About Us Top Stories Local News National News Sports News Opinion Editorial ET Cetra Advertise with Us ET E-paper
 
 
J&K RELATED WEBSITES
J&K Govt. Official website
Jammu Kashmir Tourism
JKTDC
Mata Vaishnodevi Shrine Board
Shri Amarnath Ji Shrine Board
Shri Shiv Khori Shrine Board
UTILITY
Train Enquiry
IRCTC
Matavaishnodevi
BSNL
Jammu Kashmir Bank
State Bank of India
PUBLIC INTEREST
Passport Department
Income Tax Department
JK CAMPA
JK GAD
IT Education
Web Site Design Services
EDUCATION
Jammu University
Jammu University Results
JKBOSE
Kashmir University
IGNOU Jammu Center
SMVDU