Weekly Update 463
Tea应用的数据泄露事件揭示了其在隐私保护方面的多重问题,包括非自愿上传他人照片、收集敏感信息以及后续的数据滥用,这些问题在事发前已有诸多警示却未被重视。 2025-8-3 07:12:24 Author: www.troyhunt.com(查看原文) 阅读量:15 收藏

I've listened to a few industry podcasts discussing the Tea app breach since recording, and the thing that really struck me was the lack of discussion around the privacy implications of the service before the breach. Here was a tool where people were non-consensually uploading photos of others and leaving fairly intimate commentary about them. That MO seems to be, at least in part, related to the motive to take a service that presented massive privacy implications for the subject matters and, to vet their participants' gender, create an even bigger privacy issue by collecting selfies and IDs, which in turn created yet another privacy issue when they were leaked and misused. There were so many red flags about this service before the breach that it's kinda fascinating the focus is now so heavily on the aftermath. A bit more pre-emptive focus on privacy next time, everyone.

Listen on Apple Podcasts

Watch and Listen on YouTube

Download via RSS

References

  1. Sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSitelegislation
  2. The Tea app breach is many layers of privacy irresponsibility (with some pretty alarming outcomes for users and victims of the service)
  3. My favourite creator of network-level nasties blocking was compromised (and it wasn't even the Pi-hole's fault, thanks to a dodgy WordPress plugin with an egregiously dumb flaw)
  4. I was asked about the UK's Online Safety Act during the live stream (that's a link to a thread which effectively amounts to it being more "thoughts and prayers" of infosec rather than practical legislation)
Weekly update

文章来源: https://www.troyhunt.com/weekly-update-463/
如有侵权请联系:admin#unsafe.sh