Current Weather
The Spy FM

Alleged Hackers Explain Reasons For Posting Snapchat Data

Filed by KOSU News in US News.
January 2, 2014

After millions of Snapchat usernames and other data were posted online, a group is saying they revealed the partial phone numbers and other information because the social-sharing service didn’t do enough to increase its security. The popular service allows users to send images that vanish 10 seconds after they’re seen.

Some 4.6 million Snapchat usernames and matching phone numbers were published online late Tuesday, a week after the hacking research group Gibson Security posted instructions for how to access Snapchat users’ information. The data were posted online this week — minus the final two digits of all the phone numbers.

Snapchat had previously acknowledged the vulnerability, which Gibson Security says it pointed out in August. The security group says it didn’t retrieve the data that were posted this week.

Others have claimed responsibility for the leak. And they told The Verge what they were thinking:

“‘Our motivation behind the release was to raise the public awareness around the issue, and also put public pressure on Snapchat to get this exploit fixed,’ they say. ‘Security matters as much as user experience does.’”

The hacking “exploit” that exposed users’ data relies on a feature in Snapchat that lets people find their friends by comparing their phone’s contacts list against phone numbers that are already registered with the service.

On Dec. 27, the company said that in theory, “a huge set of phone numbers, like every number in an area code, or every possible number in the U.S.” could be submitted, which could then yield a large list of matching usernames.

Those remarks come from a blog post in which Snapchat, which has reportedly rejected multibillion-dollar purchase offers from Google and Facebook, said it had taken several steps to improve security. The company has not posted an update on the issue.

“The linking of phone numbers to usernames in accounts from major cities within the United States and Canada is a private information disaster that could have been avoided if the company had acted when repeatedly warned,” ZDNet reports. “Gibson Security told ZDNet that fixing the threat would have only cost Snapchat ten lines of code.”

If you’re a Snapchat user who wants to see if your account was affected, you might want to consult a page posted by Gibson Security today that lets you compare a username against the exposed database.

The page also includes instructions about next steps. They include deleting a Snapchat account and getting a new phone number. [Copyright 2014 NPR]

Leave a Reply

12AM to 5AM The Spy

The Spy

An eclectic mix of the Spy's library of more than 10,000 songs curated by Ferris O'Brien.

Listen Live Now!

5AM to 9AM Morning Edition

Morning Edition

For more than two decades, NPR's Morning Edition has prepared listeners for the day ahead with two hours of up-to-the-minute news, background analysis, commentary, and coverage of arts and sports.

View the program guide!

9AM to 10AM The Takeaway

The Takeaway

A fresh alternative in morning news, "The Takeaway" provides a breadth and depth of world, national and regional news coverage that is unprecedented in public media.

View the program guide!

Upcoming Events in your area (Submit your event today!)

Streaming audio and podcasts

Stream KOSU on your smartphone

Phone Streaming

SmartPhone listening options on this page are intended for many iPhones, Blackberries, etc. with low-cost software applications available to listen to our full-time web streams, both News on KOSU-1 and Classical on KOSU-2.

Learn more about our complete range of streaming services

We're perfecting the patient experience - Stillwater Medical Center