Skip to main content

Popsugar’s Twinning app was leaking everyone’s uploaded photos

I thought the worst thing about Popsugar’s Twinning tool was that it matched me with James Corden.

Turns out, the hundreds of thousands of selfies uploaded to the tool were easily downloadable by anyone who knew where to look.

The popular photo matching tool is fairly simple. “It analyzes a selfie or uploaded photo, compares it to a massive database of celebrity photos to find matches, and finally gives you a ‘twinning percentage’ for your top five look-alikes,” according to Popsugar, which developed the tool. Then, you share those matched photos on Facebook and Twitter so everyone knows that you don’t look at all like one of the many Kardashians.

All of the uploaded photos are stored in a storage bucket hosted on Amazon Web Services. We know because the web address of the bucket is in the code on the Twinning tool’s website. Open that in your web browser, and we saw a real-time stream of uploaded photos.

We verified the findings by uploading a dummy photo of a certain file size at a specific time. Then, we scraped a list of filenames uploaded during that time period from the bucket’s web address, downloaded them, and found our uploaded image by searching for that photo of a certain file size. (We didn’t download any more than necessary to preserve people’s privacy.)

TechCrunch reached out to Popsugar president Lisa Sugar and vice-president of engineering Mike Patnode, but did not hear back. The bucket was locked down shortly after.

As data leaks go, this is definitely on the low-end. You might not care that their selfies were exposed and easily downloadable. (Many photos were already leaking out of Google’s search results — even before people shared their selfie matches on Twitter!) It’s not as if the site was leaking your passwords or your Social Security number. Most probably didn’t go in expecting any reasonable level of security or privacy to begin with.

But like any free app, quiz or some viral web tool, it’s worth reminding that you’re still putting your information out there — and you can’t always get it back. Worse, you almost never know how secure your data will be, or how it might end up being used — and abused — in the future.

This is Captain Buzzkill, signing off.



from TechCrunch https://tcrn.ch/2Amv4TA
via IFTTT

Comments

Popular posts from this blog

Max Q: Psyche(d)

In this issue: SpaceX launches NASA asteroid mission, news from Relativity Space and more. © 2023 TechCrunch. All rights reserved. For personal use only. from TechCrunch https://ift.tt/h6Kjrde via IFTTT

Max Q: Anomalous

Hello and welcome back to Max Q! Last week wasn’t the most successful for spaceflight missions. We’ll get into that a bit more below. In this issue: First up, a botched launch from Virgin Orbit… …followed by one from ABL Space Systems News from Rocket Lab, World View and more Virgin Orbit’s botched launch highlights shaky financial future After Virgin Orbit’s launch failure last Monday, during which the mission experienced an  “anomaly” that prevented the rocket from reaching orbit, I went back over the company’s financials — and things aren’t looking good. For Virgin Orbit, this year has likely been completely turned on its head. The company was aiming for three launches this year, but everything will remain grounded until the cause of the anomaly has been identified and resolved. It’s unclear how long that will take, but likely at least three months. Add this delay to Virgin’s dwindling cash reserves and you have a foundation that’s suddenly much shakier than before. ...

What’s Stripe’s deal?

Welcome to  The Interchange ! If you received this in your inbox, thank you for signing up and your vote of confidence. If you’re reading this as a post on our site, sign up  here  so you can receive it directly in the future. Every week, I’ll take a look at the hottest fintech news of the previous week. This will include everything from funding rounds to trends to an analysis of a particular space to hot takes on a particular company or phenomenon. There’s a lot of fintech news out there and it’s my job to stay on top of it — and make sense of it — so you can stay in the know. —  Mary Ann Stripe eyes exit, reportedly tried raising at a lower valuation The big news in fintech this week revolved around payments giant Stripe . On January 26, my Equity Podcast co-host and overall amazingly talented reporter Natasha Mascarenhas and I teamed up to write about how Stripe had set a 12-month deadline for itself to go public, either through a direct listing or by pursuin...