Researchers find serious flaws in OKCupid security

0
Chris M
Updated October 13, 2022
Published August 3, 2020
We may earn a commission via links on our site.
Why?

OkCupid has become the latest dating app to fall prey to the sloppy-security police, with several bugs discovered that could have led to a leak in users’ personal information.

A team from cybersecurity specialist Checkpoint Research discovered problems with both the website and app, which, if exploited could have given criminals access to unredacted profiles and even private messages, with full sending privileges.

Any hacker who wanted to could send a phishing email to a user containing a link which includes malicious code, giving the sender access to the account.

Explore topics mentioned in this article
stg icon alpha trio

The stalwart site has remained stubbornly free to use throughout its life, and with a ‘light touch’ in terms of moderation, meaning it has been a prime target for everything from Catfishing users to fake mirror sites.

OkCupid repaired the problems within 48 hours of being informed by Checkpoint Research. In a statement released by Checkpoint (which is a slightly unusual way of handling it), OkCupid said:

“Check Point Research informed OkCupid developers about the vulnerabilities exposed in this research and a solution was responsibly deployed to ensure its users can safely continue using the OkCupid app. Not a single user was impacted by the potential vulnerability on OkCupid, and we were able to fix it within 48 hours. We’re grateful to partners like Check Point who with OkCupid, put the safety and privacy of our users first.”

OkCupid has oft been questioned over the way it monetises data, with accusations that it sells users’ personal data to analytics firms. Now, as it emerges that the coding has flaws too, raising the question – how safe are dating apps?

“Our research into OkCupid, which is one of the longest-standing and most popular applications in their sector, has led us to raise some serious questions over the security of dating apps,” Checkpoint says.

“The fundamental questions being: how safe are my intimate details on the application? How easily can someone I don’t know access my most private photos, messages and details?”

The sad fact is that we all need to ask this question when really and truly, it should never come up. This isn’t the first piece of sloppy coding by a dating app and it certainly won’t be the last.

We’ve asked OKCupid for comment, but hadn’t heard back at the time of publication.

Read Next: How did online dating turn into such a hot mess?

Article by
Chris M has worked in technology journalism for over a decade, and brings his nerdy expertise to looking at what goes on under the hood of sex tech.With over a decade of expertise in his field, Chris brings a nerdy perspective to his exploration of the fascinating world behind the scenes. His articles have graced the pages of renowned publications such as Engadget, TechRadar, AskMen, and The Register.
Get in touch
On the same topic…
  • bluesky adult content guide

    Bluesky adult content: Every feature that keeps your feed exactly how you want it

    Ben/
    November 13, 2024
  • Ethical dilemmas of ai in sextech

    Ethical dilemmas of AI in sextech: Balancing technological advances and consent

    Stu N/
    October 1, 2024
  • DATING APP UPDATES

    Dating appdates (August 2024): ChatGPT vs ‘fake’ heights, SIMS get catfished, GPS safety concerns, and more

    Jamie F/
    August 18, 2024
By the same author…
  • Watch Porn on Google TV / Android TV

    How to watch XXX videos on Google TV, Android TV, and Android Media Players (AMP)

    Chris M/
    April 11, 2022
  • Instructions for how to sideload apps and watch porn on Amazon Fire TV devices.

    Amazon porn: How to find, install and watch XXX videos on Fire TV (Stick, Box, Cube and TV)

    Chris M/
    January 13, 2023
  • Emjoy

    Erotic audio app Emjoy lands $3m in funding as sextech goldrush continues

    Chris M/
    August 17, 2021

Leave a Reply

Your email address will not be published. Required fields are marked *