No apology, but Snapchat responds to leak of 4.6 million users’ phone numbers

Graham Cluley

Snapchat has now responded to the leak of 4.6 million usernames and phone numbers, after it failed to adequately prevent hackers from abusing its private API.

Snapchat

Here’s the timeline of what’s been happening up until now:

August 2013: Researchers at security group Gibson Research tell Snapchat that they have found weaknesses in the photo-sharing service that could be exploited through its API.

December 24 2013: Frustrated by a lack of response from Snapchat (Gibson Security claimed the problem could be fixed easily – “if they can’t rewrite ten lines of code in that time they should fire their development team”), the researchers published the Snapchat API and detailed how it could be exploited to scoop up users’ details.

December 27 2013: Snapchat dismisses the weakness as “theoretical”.

New Year 2014: Hackers put “theory” into practice, making available a database of 4.6 million Snapchat usernames and partially redacted phone numbers.

The publishing of that database on the internet became huge news, and a PR headache for Snapchat. The firm has now responded – saying it will release an updated version of the app which will allow users to opt-out of appearing in the “Find Friends” feature which leaked phone numbers in the first place.

SnapchatIn addition, Snapchat says it will further improve “rate limiting and other restrictions” to address future abuse of its API. By George, lets hope they get it right this time.

Finally, Snapchat has announced it has created a specific email address for security researchers to report flaws and concerns in future: security@snapchat.com.

In conclusion Snapchat says:

The Snapchat community is a place where friends feel comfortable expressing themselves and we’re dedicated to preventing abuse.

What a shame the firm didn’t comfortable expressing an apology to the 4.6 million Snapchat users who have already had their privacy exposed by this incident.

Graham Cluley Graham Cluley is a veteran of the anti-virus industry having worked for a number of security companies since the early 1990s when he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows. Now an independent security analyst, he regularly makes media appearances and is an international public speaker on the topic of computer security, hackers, and online privacy. Follow him on Twitter at @gcluley, or drop him an email.

2 Replies to “No apology, but Snapchat responds to leak of 4.6 million users’ phone numbers”

  1. Amazing stupidity for ignoring the reports in the first place and then complete arrogance in their approach to the aftermath. You would hope that some senior people paid the price for the initial mess but judging by their response that is unlikely !

  2. Another in a depressingly long line of new tech companies that prefer the denial, head-in-sand, make it a huge story approach rather than fess up quick, fix it fast, no story approach.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Never miss a thing. Sign up for the free GCHQ newsletter from Graham Cluley.
GET EMAIL UPDATES