Users from 4chan claim to have discovered an exposed database hosted on Google’s mobile app development platform, Firebase, belonging to the newly popular women’s dating safety app Tea. Users say they are rifling through peoples’ personal data and selfies uploaded to the app, and then posting that data online, according to screenshots, 4chan posts, and code reviewed by 404 Media.

  • sunglocto@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    13
    ·
    2 months ago

    This is what happens when you decide to vibecode a service with zero attention to safety or web development. This is why you don’t immediately jump onto a new service without it being vetted properly. Now one of the worst communities on the Internet is in possession of over a hundred thousand women’s driving licenses and faces. This is going to be an absolute disaster.

    • Darrell_Winfield@lemmy.world
      link
      fedilink
      English
      arrow-up
      8
      ·
      2 months ago

      This is ALSO why no service should ever require or get my driver’s license information. Fuck that. Also, yet another Constance to those who can’t afford a car or want to improve the environment by living car free.

      • shiroininja@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        My only exception to that are uber drivers. But then again we live in an age where somehow better help has become popular, even though they sell your data.

    • 4am@lemmy.zip
      link
      fedilink
      English
      arrow-up
      4
      ·
      2 months ago

      Now now, I like to shit on vibecoders too but let’s not pretend this is some new problem.

      Idiots leave databases on cloud servers exposed all the time rather than deal with their companies often arcane rules for generating certificates

      • ByteOnBikes@discuss.onlineOP
        link
        fedilink
        English
        arrow-up
        0
        arrow-down
        1
        ·
        edit-2
        2 months ago

        I honestly don’t understand what op is talking about.

        Leaks happen all the time, even in billion dollar companies.

        Their comment is the equivalent like, “This is why you should lock your doors!” Like uh okay.

        • Tlaloc_Temporal@lemmy.ca
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          This was more like leaving all your valuables in a cardboard box on your front lawn. Anyone can just take it, if they care to look inside the complete unsecured box.

          Someone just drove up and tossed the box in their truck. No lock involved.

        • prof@infosec.pub
          link
          fedilink
          English
          arrow-up
          1
          ·
          2 months ago

          This situation would have been easily preventable with basic understanding of what they’re doing is what OP is saying. This leak is not something highly complex, it is painfully stupid on the side of the developers.

          There’s a difference between a hack, where data is exposed, compared to data exposure due to negligence or ignorance on the development side.

        • Eheran@lemmy.world
          link
          fedilink
          English
          arrow-up
          0
          ·
          2 months ago

          I love how people just jump on whatever they like, instead of actually thinking about the stuff they read/comment on/upvote. Exactly like on Reddit, no difference.

            • Eheran@lemmy.world
              link
              fedilink
              English
              arrow-up
              0
              ·
              2 months ago

              The thing is that many here think they are better, they look down on Reddit. There is a certain shift in what demographic switched over but generally it is the same.

    • Zetta@mander.xyz
      link
      fedilink
      English
      arrow-up
      0
      arrow-down
      1
      ·
      2 months ago

      “Vibe coded” you just made that up didn’t you, because you don’t like llms. I don’t see anything in the article about “Ai” and this service has been operating for 2 years.

      • shalafi@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        2 months ago

        My thoughts as well. But hey, it’s lemmy! Just accuse someone of doing something we hate, good to go!