Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Monday July 23 2018, @04:09PM   Printer-friendly
from the always-check-the-defaults dept.

Submitted via IRC for BoyceMagooglyMonkey

Anyone can track a Venmo user's purchase history and glean a detailed profile – including their drug deals, eating habits and arguments – because the payment app lacks default privacy protections.

This was the finding of a Berlin-based researcher, Hang Do Thi Duc, who analysed the more than 200 million public Venmo transactions made in 2017. Her aim was to highlight the privacy risk from using a seemingly innocuous peer-to-peer app.

By accessing the data through a public application programming interface, Do Thi Duc was able to see the names of every user who hadn't changed their settings to private, along with the dates of every transaction and the message sent with the payment. This allowed her to explore the lives of unsuspecting Venmo users and learn "an alarming amount about them".

The default state for transactions when a user signs up to the app is "public", which means they can be seen by anyone on the internet. Users can change this to "private" by navigating to the app's settings, but it's not clearly highlighted during sign-up.

Source: https://www.theguardian.com/world/2018/jul/17/venmo-payments-app-default-privacy-settings-public-information


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by archfeld on Monday July 23 2018, @04:44PM (8 children)

    by archfeld (4650) <treboreel@live.com> on Monday July 23 2018, @04:44PM (#711304) Journal

    Anyone stupid enough to buy drugs, legal or not, using an APP deserves whatever comes their way. That is one of the best reasons against a cashless society that I can think of.

    --
    For the NSA : Explosives, guns, assassination, conspiracy, primers, detonators, initiators, main charge, nuclear charge
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 0) by Anonymous Coward on Monday July 23 2018, @05:21PM (6 children)

    by Anonymous Coward on Monday July 23 2018, @05:21PM (#711322)

    Anyone stupid enough to buy drugs, legal or not, using an APP deserves whatever comes their way. That is one of the best reasons against a cashless society that I can think of.

    You mean reasons for? Transactions can be set to private so the issue is that some folks are stupid and "Do Thi Duc" research sounds like quackery!

    • (Score: 3, Insightful) by insanumingenium on Monday July 23 2018, @05:35PM

      by insanumingenium (4824) on Monday July 23 2018, @05:35PM (#711334) Journal

      A bad default is a problem, and that is a super common Vietnamese name.

    • (Score: 0) by Anonymous Coward on Monday July 23 2018, @06:00PM (1 child)

      by Anonymous Coward on Monday July 23 2018, @06:00PM (#711350)
      You can set your app to "private", but you do not know the settings on the other end of the transaction.
      • (Score: 3, Insightful) by maxwell demon on Monday July 23 2018, @08:31PM

        by maxwell demon (1608) on Monday July 23 2018, @08:31PM (#711428) Journal

        Since the app probably isn't open source, you cannot even know the setting on your end. You have no idea whether in that app “private” really means “only seen by you”.

        --
        The Tao of math: The numbers you can count are not the real numbers.
    • (Score: 3, Insightful) by archfeld on Monday July 23 2018, @10:00PM (2 children)

      by archfeld (4650) <treboreel@live.com> on Monday July 23 2018, @10:00PM (#711460) Journal

      It doesn't matter if the transaction can be set to private. Buying drugs, legal or not using anything but cash is foolish. Why leave a trail, paper or otherwise for a transaction that has a high probability of coming back to bite you in the a$$ if it is made public. Haven't the huge number of 'recovered' email scandals and 'hacked' data exposures taught anyone anything ? There is a reason most drug dealers don't take American Express or checks, and it isn't Squares' card processing fees either...

      --
      For the NSA : Explosives, guns, assassination, conspiracy, primers, detonators, initiators, main charge, nuclear charge
      • (Score: 0) by Anonymous Coward on Tuesday July 24 2018, @09:37AM (1 child)

        by Anonymous Coward on Tuesday July 24 2018, @09:37AM (#711648)

        Buying drugs, legal or not using anything but cash is foolish. Why leave a trail, paper or otherwise for a transaction that has a high probability of coming back to bite you in the a$$ if it is made public.

        It's a good thing pharmacies don't require any paperwork because those meds can be really embarrassing.

  • (Score: 4, Insightful) by DannyB on Monday July 23 2018, @06:10PM

    by DannyB (5839) Subscriber Badge on Monday July 23 2018, @06:10PM (#711356) Journal

    Anyone stupid enough to buy drugs, legal or not, using an APP deserves whatever comes their way.

    What comes their way should be exactly what they ordered. Even when using an APP.

    That is one of the best reasons against a cashless society that I can think of.

    Control. Just like control of the internet. Just like government approved weak encryption and back doors. It is the very reason that WE WILL have a cashless society. (I doubt we'll ever see a revolution because . . . oh, look! a shiny! version 2.0! And it's on sale!)

    --
    The lower I set my standards the more accomplishments I have.