October 5, 2020 12:08 pm GMT
Original Link: https://boingboing.net/2020/10/05/grindr-hack-let-anyone-steal-email-login-tokens.html
Grindr hack let anyone steal email login tokens
Security researcher Troy Hunt reports on a security flaw that let attackers change the email address of Grindr accounts. All you had to do was know the account's current email address and trigger a password reset: the secret login URL was sent to the browser too, hidden in the code of the "check your email!" — Read the rest
Original Link: https://boingboing.net/2020/10/05/grindr-hack-let-anyone-steal-email-login-tokens.html
Share this article:
Tweet
View Full Article