Mashable 07月26日 03:36
Controversial womens safety app Tea target of massive hack
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

女性安全约会App“Tea”近来成为网络攻击的最新受害者,导致数千用户上传的图像数据面临风险。此次攻击影响了过去两年间上传到该App的72,000张图片,其中包括13,000张用于验证身份的自拍照和驾照照片,以及59,000张用户发布的个人照片。该App旨在帮助女性记录与男性不愉快的经历并预警潜在危险,但其数据存储和用户验证系统因隐私问题引发争议。攻击者在4Chan上分享了被盗用的身份照片,引发了对用户隐私的担忧。Tea公司表示,数据存储是为了防止网络欺凌,且当前用户信息未受影响,但此次事件无疑给用户带来了极大的困扰。

🛡️ **用户数据大规模泄露**:女性安全约会App“Tea”遭受网络攻击,导致72,000张用户上传的图片(包括自拍照、驾照等身份验证信息和个人照片)被泄露,其中13,000张为用户提交的身份证明文件,59,000张为用户在App上发布的照片,暴露了大量用户隐私。

❓ **数据存储与隐私争议**:Tea App因存储用户用于身份验证的照片和记录负面约会经历的功能,一直面临隐私方面的争议。批评者认为其用户验证系统和公开记录男性不当行为的机制,可能侵犯个人隐私,并可能导致“人肉搜索”等网络欺凌行为。

🚨 **攻击者利用漏洞公开数据**:此次攻击的漏洞被发现于4Chan平台,攻击者开始公开分享被盗用的女性身份照片和驾照信息,并称数据存储在“公共存储桶”中,使得用户个人信息暴露无遗,引起了广泛关注和担忧。

⚖️ **App背景与社会影响**:Tea App作为一个专为女性设计的平台,旨在记录负面约会经历并预警风险,并将部分利润捐赠给国家家庭暴力热线。然而,其以公开论坛形式记录男性行为的模式,引发了关于网络八卦、骚扰以及潜在“人肉搜索”的讨论,并催生了用户针对女性的“复制粘贴”式App。

🚫 **官方回应与用户担忧**:Tea公司回应称,数据存储是为了遵守网络欺凌预防要求,且当前用户信息未受影响。然而,此次事件仍引发了用户对数据安全的广泛担忧,尤其是在App近期因用户分享的负面经历而登上Apple App Store榜首之后。

Past users of viral women's dating safety app Tea are the latest victims of a massive cyberattack, which has rendered thousands of user images held in a legacy database vulnerable.

First reported by Reddit users, the hack was verified by 404Media and later confirmed by Tea itself, and affects 72,000 images posted to the app over the last two years. Of the hacked data, 13,000 images were selfies or photo identification cards like drivers licenses submitted by users to verify their accounts. Another 59,000 images stored in the database were of individuals posted to the app.

Tea, founded by Sean Cook, was designed as a women-only app for users to document their negative experiences with men and warn other women of potential danger. According to Tea's website, 10 percent of its profits are donated the National Domestic Violence Hotline.

The vulnerability was discovered by users on 4Chan, who began sharing photo IDs of women on the platform. In a thread detailing the hack, one user wrote: "Yes, if you sent Tea App your face and drivers license, they doxxed you publicly! No authentication, no nothing. It's a public bucket. DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!” Other users stated they were collecting personal information from the images, 404Media reported. In a statement to the publication, Tea said the data was stored to comply with cyber-bullying prevention requirements and that no current user information had been breached.

Earlier this week and due to several viral tweets from its users, Tea became the number one app on the Apple App Store. The trending app has since become the subject of online controversy, particularly from individuals who disagree with the app's focus on documenting unwanted and inappropriate behavior of men in a public forum, without verification. Many critics (including men who have been implicated on the app) see the app's reporting mechanisms, such as users posting images of "red flag" men, and its user verification system, which uses photos to "confirm" a user's gender, as violations of privacy.

Culturally, others worry it's forum-like nature is too similar to online snark pages, which often incentive users to engage in obsessive cycles of gossip and online harassment, and could potentially lead to doxxing. It has been compared to the popular "Are we dating the same guy?" Facebook page.

In an X post from July 22, one user wrote, "How long til there is a data leak? I'm giving it 1 month." Other emboldened online users responded to the popularity of the women-only app with overtly misogynistic "copycat" apps, including ones intended to track women's "body counts." "Introducing BoxScore, a man-only app where users anonymously share info and warnings about women to spot red flags and get feedback," wrote user @tolly_xyz in a post on X.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Tea App 网络安全 数据泄露 用户隐私 女性安全
相关文章