'Secret' app didn't actually keep you anonymous

Written By limadu on Jumat, 22 Agustus 2014 | 22.16

secret app The Secret app is supposed to keep you anonymous. But until last week, it was possible to trace posts directly to you.

NEW YORK (CNNMoney)

Hackers at Rhino Security Labs figured out a way to dupe Secret's system.

To join Secret's community, the app imports your contacts. It then labels which posts are from your friends.

To prevent you from tracking a particular person, Secret requires that seven of your contacts post to the network before it labels their posts.

But here's the hack: Fill your phone's contact list with fake people and only one real contact -- your target. If you control posts coming from these dummy Secret accounts, it's easy to spot when your real "friend" is posting.

"Poison the data on the outside, bring it in as trusted data, and voilĂ ! You make the system work for you," said Bryan Seely, a Rhino researcher in Seattle.

Why does it matter? Consider these recent posts.

Related story: Hospitals can't protect patient data

From someone in Tel Aviv, Israel: "I am an Arab. I live near Jerusalem. I am against war, and I believe in democracy. Hamas is bad for all Muslims! Stop Hamas! If someone found out I said that, I would be executed!"

A person in Utah: "Having an invisible illness is killing me. Literally. And I'm only 24."

And someone in Poland: "I told everyone that cat made those scars."

CNNMoney's cybersecurity Flipboard magazine: How safe are you?

The security researchers notified the San Francisco startup and say that Secret issued a fix this week. Now, if you import a bunch of fake friends and only one real one, the real one won't be tagged as a "friend," Seely said. It's security through obscurity.

Secret CEO David Byttow didn't immediately respond to requests for comment.

But consider this a reminder about a mantra in the hacker community: Nothing you do in the digital realm is truly anonymous. Eventually, it will be traced back to you.

First Published: August 22, 2014: 10:59 AM ET


Anda sedang membaca artikel tentang

'Secret' app didn't actually keep you anonymous

Dengan url

http://kasiatbuatsehat.blogspot.com/2014/08/secret-app-didnt-actually-keep-you.html

Anda boleh menyebar luaskannya atau mengcopy paste-nya

'Secret' app didn't actually keep you anonymous

namun jangan lupa untuk meletakkan link

'Secret' app didn't actually keep you anonymous

sebagai sumbernya

0 komentar:

Posting Komentar

techieblogger.com Techie Blogger Techie Blogger