No apology, but Snapchat responds to leak of 4.6 million users’ phone numbers


Snapchat has now responded to the leak of 4.6 million usernames and phone numbers, after it failed to adequately prevent hackers from abusing its private API.


Here’s the timeline of what’s been happening up until now:

August 2013: Researchers at security group Gibson Research tell Snapchat that they have found weaknesses in the photo-sharing service that could be exploited through its API.

December 24 2013: Frustrated by a lack of response from Snapchat (Gibson Security claimed the problem could be fixed easily - “if they can’t rewrite ten lines of code in that time they should fire their development team”), the researchers published the Snapchat API and detailed how it could be exploited to scoop up users’ details.

December 27 2013: Snapchat dismisses the weakness as “theoretical”.

New Year 2014: Hackers put “theory” into practice, making available a database of 4.6 million Snapchat usernames and partially redacted phone numbers.

The publishing of that database on the internet became huge news, and a PR headache for Snapchat. The firm has now responded - saying it will release an updated version of the app which will allow users to opt-out of appearing in the “Find Friends” feature which leaked phone numbers in the first place.

SnapchatIn addition, Snapchat says it will further improve “rate limiting and other restrictions” to address future abuse of its API. By George, lets hope they get it right this time.

Finally, Snapchat has announced it has created a specific email address for security researchers to report flaws and concerns in future:

In conclusion Snapchat says:

The Snapchat community is a place where friends feel comfortable expressing themselves and we’re dedicated to preventing abuse.

What a shame the firm didn’t comfortable expressing an apology to the 4.6 million Snapchat users who have already had their privacy exposed by this incident.

Tags: , ,

Share this article:

   Join thousands of others and sign up to our free "GCHQ" newsletter.

Smashing Security podcast
Check out "Smashing Security", the award-winning weekly audio podcast, with Graham Cluley, Carole Theriault, and special guests from the world of information security.

"It's brilliant!" • "Three people having fun in an industry often focused on bad news" • Winner of the Best Security Podcast 2018

Latest episodes:
Listen on Apple Podcasts Listen on Google Podcasts

, ,

2 Responses

  1. Havenswift Hosting

    January 3, 2014 at 5:59 pm #

    Amazing stupidity for ignoring the reports in the first place and then complete arrogance in their approach to the aftermath. You would hope that some senior people paid the price for the initial mess but judging by their response that is unlikely !

  2. Philip Daly

    January 3, 2014 at 8:52 pm #

    Another in a depressingly long line of new tech companies that prefer the denial, head-in-sand, make it a huge story approach rather than fess up quick, fix it fast, no story approach.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.