Snapchat to make app more secure

  • Associated Press
  • Friday, January 3, 2014 7:23pm
  • Business

NEW YORK — Snapchat says it plans to put out a more secure version of its application following a breach that allowed hackers to collect the usernames and phone numbers of some 4.6 million of its users.

The disappearing-message service popular with young people said in a blog post late Thursday that the updated version of its app would allow users to opt out of its “Find Friends” feature, which was apparently at the heart of the breach, and would stem future attempts to abuse its service.

The breach occurred after security experts warned the company at least twice about a vulnerability in its system.

Before announcing its plans to update the app, Snapchat had been quiet. Its seemingly detached response caused some security specialists to wonder whether the young company can handle the spotlight that it’s been thrust into over the last year as its service has become enormously popular.

In response to a warning by Gibson Security on Dec. 25 —which followed an earlier alert in August — Snapchat said in a blog post last Friday that it had implemented “various safeguards” over the past year that would make it more difficult to steal large sets of phone numbers. Snapchat hasn’t detailed the changes it made.

As Americans rang in the New Year, hackers reportedly published 4.6 million Snapchat usernames and phone numbers on a website called snapchatdb.info, which has since been suspended. The breach came less than a week after the most recent warning from security experts that an attack could take place.

The incident bruises the company’s image and may threaten its rapid growth. Los Angeles-based Snapchat has no source of revenue, but its rapid rise to an estimated 20 million U.S. adult users prompted Facebook to extend a reported $3 billion buyout last year. Snapchat’s 23-year-old CEO Evan Spiegel turned down the overture. The user number estimate is based on census data and data from the Pew Research Center.

What should users do? Gibson Security, the firm that warned Snapchat of the security vulnerability on Christmas Day, has created a site, — http://lookup.gibsonsec.org/ — that lets users type in their username to see if their phone number was among those leaked. Of two user accounts that The Associated Press checked, one was found to have been compromised.

Gibson Security did not publish the last two digits of the phone numbers.

Gibson says users can delete their Snapchat account if they wish, but “this won’t remove your phone number from the already circulating leaked database.” Users can also ask their phone company to give them a new phone number.

“Lastly, ensure that your security settings are up to scratch on your social media profiles. Be careful about what data you give away to sites when you sign up — if you don’t think a service requires your phone number, don’t give it to them,” Gibson said.

This was Gibson’s second warning to Snapchat, following one in August that the security firm said was ignored.

“Given that it’s been around four months since our last Snapchat release, we figured we’d do a refresher on the latest version, and see which of the released exploits had been fixed (full disclosure: none of them),” Gibson wrote on the Gibson Security website.

The Snapchat breach comes just two weeks after Target was hit with a massive data security breach that affected as many as 40 million debit and credit card holders.

Gartner security analyst Avivah Litan said phone numbers are not considered “sensitive” personally identifiable information — such as credit card or social security numbers — so they are collected by all sorts of companies to verify a person’s identity.

A phone number is “not as bad as password or magnetic strip information, but it’s the piece of the puzzle that criminals need to impersonate identities,” she said.

Christopher Soghoian, principal technologist with the American Civil Liberties Union, agreed.

“The main problem was that they ignored a responsible report by security researchers,” he said, adding that his concern is not with the specific database of information that was released, but that Snapchat has “demonstrated a cavalier attitude about privacy and security.”

Many people use Snapchat because it feels more private than other messaging apps and social networks. Users can send each other photos and videos that disappear within a few seconds after they are viewed. While the recipient can take a screenshot of the message, a big draw of Snapchat is its ephemeral nature.

“This probably won’t be the last problem with Snapchat,” Soghoian said. Companies like Microsoft and Google, he added, actively court security researchers and even pay bounties for people to expose flaws in their systems.

“Snapchat may be too small to pay bounties, but they certainly should be treating researchers with respect and addressing issues as soon as they are told about them,” he said.

In its blog post Thursday, Snapchat listed an email address that security experts could use to contact the company “when they discover new ways to abuse our service so that we can respond quickly to address those concerns.”

Talk to us

> Give us your news tips.

> Send us a letter to the editor.

> More Herald contact information.

More in Business

ZeroAvia founder and CEO Val Mifthakof, left, shows Gov. Jay Inslee a hydrogen-powered motor during an event at ZeroAvia’s new Everett facility on Wednesday, April 24, 2024, near Paine Field in Everett, Washington. (Ryan Berry / The Herald)
ZeroAvia’s new Everett center ‘a huge step in decarbonizing’ aviation

The British-American company, which is developing hydrogen-electric powered aircraft, expects one day to employ hundreds at the site.

Allan and Frances Peterson, a woodworker and artist respectively, stand in the door of the old horse stable they turned into Milkwood on Sunday, March 31, 2024, in Index, Washington. (Ryan Berry / The Herald)
Old horse stall in Index is mini art gallery in the boonies

Frances and Allan Peterson showcase their art. And where else you can buy a souvenir Index pillow or dish towel?

Everett
Red Robin to pay $600K for harassment at Everett location

A consent decree approved Friday settles sexual harassment and retaliation claims by four victims against the restaurant chain.

magniX employees and staff have moved into the company's new 40,000 square foot office on Seaway Boulevard on Monday, Jan. 18, 2020 in Everett, Washington. magniX consolidated all of its Australia and Redmond operations under one roof to be home to the global headquarters, engineering, manufacturing and testing of its electric propulsion systems.  (Andy Bronson / The Herald)
Harbour Air plans to buy 50 electric motors from Everett company magniX

One of the largest seaplane airlines in the world plans to retrofit its fleet with the Everett-built electric propulsion system.

Simreet Dhaliwal speaks after winning during the 2024 Snohomish County Emerging Leaders Awards Presentation on Wednesday, April 17, 2024, in Everett, Washington. (Ryan Berry / The Herald)
Simreet Dhaliwal wins The Herald’s 2024 Emerging Leaders Award

Dhaliwal, an economic development and tourism specialist, was one of 12 finalists for the award celebrating young leaders in Snohomish County.

Lynnwood
New Jersey company acquires Lynnwood Land Rover dealership

Land Rover Seattle, now Land Rover Lynnwood, has been purchased by Holman, a 100-year-old company.

Szabella Psaztor is an Emerging Leader. (Olivia Vanni / The Herald)
Szabella Pasztor: Change begins at a grassroots level

As development director at Farmer Frog, Pasztor supports social justice, equity and community empowerment.

Simreet Dhaliwal is an Emerging Leader. (Olivia Vanni / The Herald)
Simreet Dhaliwal: A deep-seated commitment to justice

The Snohomish County tourism and economic specialist is determined to steer change and make a meaningful impact.

Nathanael Engen, founder of Black Forest Mushrooms, an Everett gourmet mushroom growing operation is an Emerging Leader. (Olivia Vanni / The Herald)
Nathanael Engen: Growing and sharing gourmet mushrooms

More than just providing nutritious food, the owner of Black Forest Mushrooms aims to uplift and educate the community.

Owner and founder of Moe's Coffee in Arlington Kaitlyn Davis poses for a photo at the Everett Herald on March 22, 2024 in Everett, Washington. (Annie Barker / The Herald)
Kaitlyn Davis: Bringing economic vitality to Arlington

More than just coffee, Davis has created community gathering spaces where all can feel welcome.

Emerging Leader John Michael Graves. (Ryan Berry / The Herald)
John Michael Graves: Champion for diversity and inclusion

Graves leads training sessions on Israel, Jewish history and the Holocaust and identifying antisemitic hate crimes.

Gracelynn Shibayama, the events coordinator at the Edmonds Center for the Arts, is an Emerging Leader. (Olivia Vanni / The Herald)
Gracelynn Shibayama: Connecting people through the arts and culture

The Edmonds Center for the Arts coordinator strives to create a more connected and empathetic community.

Support local journalism

If you value local news, make a gift now to support the trusted journalism you get in The Daily Herald. Donations processed in this system are not tax deductible.