时间:2025-10-29 05:24:13 来源:网络整理编辑:綜合
Next time you make a payment on Venmo, beware: almost anyone can track it.The popular mobile payment
Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
TopicsCybersecurityPrivacy
You will love/hate Cards Against Humanity's new fortune cookies2025-10-29 05:00
拜仁動手 ?巴薩折半價清洗天才右閘 隻標價1500萬2025-10-29 04:56
外媒 :莫雷諾將恢複自由身 他希望回歸老東家退役2025-10-29 04:46
萊科 :山東創造完美賽季 我們隻關心自身表現2025-10-29 04:22
Richard Branson 'thought he was going to die' in bike accident2025-10-29 03:58
不愧是你!拉莫斯巴黎第3戰即染紅 生涯28次被罰下2025-10-29 03:57
曝伊卡爾迪同意冬窗加盟尤文 巴黎不接受先租後買2025-10-29 03:53
雙喜臨門!登貝萊與女友完婚 下周將降薪續約巴薩2025-10-29 03:35
U.S. pole vaulter skids to a halt for national anthem2025-10-29 03:16
神劇情!梅州96分鍾絕平衝超 浙江2比1隻能踢附加賽2025-10-29 03:09
Photos show the Blue Cut fire blazing a path of destruction in California2025-10-29 05:05
2021英超11人:紅軍藍月平分天下 藍軍僅一席遮羞2025-10-29 04:59
薩拉赫續約談判神條款 將促成利物浦哈蘭德好事?2025-10-29 04:48
足協杯決賽1月9日成都踢 主辦方申請開放球迷看台2025-10-29 04:21
Donald Trump's tangled web of Russian influence2025-10-29 04:04
神劇情!梅州96分鍾絕平衝超 浙江2比1隻能踢附加賽2025-10-29 03:57
卡爾多納2場3球韓佳奇屢獻神撲 廣州城驚險帶走1分2025-10-29 03:55
還回來嗎?洛國富巴西休閑時光 :釣魚+沙灘足球(圖)2025-10-29 03:43
Old lady swatting at a cat ends up in Photoshop battle2025-10-29 03:20
山區女孩因足球改變命運 “追風計劃”故事獲全球華人短視頻大賽社會責任獎2025-10-29 03:08