时间:2025-01-18 19:09:52 来源:网络整理编辑:綜合
Next time you make a payment on Venmo, beware: almost anyone can track it.The popular mobile payment
Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
TopicsCybersecurityPrivacy
J.K. Rowling makes 'Harry Potter' joke about Olympics event2025-01-18 19:07
四進宮仍難救主!官方:斯科拉裏卸任格雷米奧主帥2025-01-18 19:01
女足新帥競聘4人已報名 肇俊哲熱門中國香港教練陳婉婷在列2025-01-18 18:59
銅牆鐵壁!馬丁內斯兩神撲讓蘇牙絕望 梅西 :他世界最佳2025-01-18 18:54
Visualizing July's astounding global temperature records2025-01-18 18:49
弗裏克接手德國5戰5勝第一隊出線 轟18球隻丟1球2025-01-18 18:48
中超多隊遇危機+中甲強隊專注衝超 足協杯又成冷門製造機?2025-01-18 18:20
意媒:紐卡斯爾開始采購行動 最快1月份報價拉姆塞2025-01-18 18:08
Darth Vader is back. Why do we still care?2025-01-18 17:15
米盧受訪為國足戰沙特支招 直言B組澳大利亞更強2025-01-18 17:05
One of the most controversial power struggles in media comes to a close2025-01-18 18:59
紐卡有意貝爾卻貼冷屁股 大聖隻想履行完皇馬合同2025-01-18 18:55
劉彬彬:絕殺越南有利於備戰 戰沙特已做相應的部署2025-01-18 18:47
中沙戰裁判或影響比賽 國足戰術平穩拿一分就可接受2025-01-18 18:45
Fake news reports from the Newseum are infinitely better than actual news2025-01-18 18:33
無心插柳!梅西挑傳直接破門得分 收獲國家隊第80球2025-01-18 18:28
國足需警惕沙特邊鋒穆瓦拉德 曾在天河破門絕殺恒大2025-01-18 18:08
國足對陣沙特或重推防守戰陣 忌憚對手魔鬼主場+濕熱天氣2025-01-18 17:20
Donald Trump's tangled web of Russian influence2025-01-18 17:06
巴薩官方:登貝萊阿圭羅恢複訓練 未來幾周或複出2025-01-18 16:52