How using dating apps can turn you from dater to victim

  DUBAI - Dating apps are quickly becoming more popular all over the world, but did you know that using them could leave you vulnerable to hackers? As many as one in three people are currently using an online dating service, but with the increasing popularity of these services comes an important security issue. A recent analysis of popular dating apps revealed that users face multiple risks when using online dating apps, according to Kaspersky Lab researchers. Kaspersky experts studied various dating apps to look for various vulnerabilities that could affect users’ real lives and change their status from "daters" to "victims". How your info is exposed For example, dating app users can be identified by finding out their names and surnames from social network profiles and can also be found in the physical world through the use of geolocation data. They can also lose access to their accounts, or have their personal data fall into the wrong hands. “Users are putting themselves at risk by sharing sensitive personal information in their profiles such as their place of education and work. Users should be sure to carefully monitor their privacy, security and data protection when dating online,” said Roman Unuchek, security expert at Kaspersky Lab. "Intruders can easily find victims’ real accounts on Facebook and LinkedIn networks. It also opens possibilities for stalking – to harass users and track their movements in real life," Unuchek added. Experts alsoe discovered a common security risk in several applications, related to the token-based authentication method used by dating apps for new registration and sign-up processes. A token is created on request by a server in order to uniquely identify the user and usually asks for access to a Facebook account. It then provides access to general user information, including first and last names, the user’s e-mail address and their profile picture. By using this method, applications receive all the necessary data to enable them to authenticate the user on its servers. Tokens are often stored or used insecurely and, therefore, can be easily stolen. As a result, intruders are able to gain temporary access to victims’ accounts even without their login and password details. Following this vulnerability with insecure token storage, users may also face another threat related to the safety of message histories which are stored on the device and can be accessed and read by intruders. Such attacks are a particular threat to users of Android devices. Some of them, those running outdated software, have unclosed vulnerabilities that enable attackers to gain root access to the device, which can be used to gain access to private information, including that about user activity in dating apps such as messages written and photos viewed. In addition, users of 6 of the analyzed apps can be detected by their location. In some of the apps Kaspersky Lab also identified risks in data transmission process. Although most applications use SSL (Secure Sockets Layer) to secure communication with servers, some data is sent via the HTTP protocol and is not encrypted. This provides hackers with opportunities to intercept these communications, which often contain personal information such as the user’s location, profiles visited, messages, device data etc. Using an insecure connection, intruders can also gain control of a victim’s account. How to prevent your data from theft • Avoid public Wi-Fi hotspots which offer limited protection, • Use a VPN to ensure a secure connection, • Don’t share your sensitive ID information, such as education, work place, etc., • Install a reliable security solution on your deviceJTNDJTIxLS0lMjBDb2RlcyUyMGJ5JTIwSFRNTC5hbSUyMC0tJTNFJTBBJTBBJTNDJTIxLS0lMjBDU1MlMjBDb2RlJTIwLS0lM0UlMEElM0NzdHlsZSUyMHR5cGUlM0QlMjJ0ZXh0JTJGY3NzJTIyJTIwc2NvcGVkJTNFJTBBYS5HZW5lcmF0ZWRMaW5rJTNBbGluayUyMCU3QiUwQWZvbnQtc2l6ZSUzQThweCUzQnRleHQtZGVjb3JhdGlvbiUzQW5vbmUlM0Jjb2xvciUzQSUyMzAwMDAzMyUzQmJhY2tncm91bmQtY29sb3IlM0ElMjNmOWY1ZjUlM0IlMEElN0QlMEFhLkdlbmVyYXRlZExpbmslM0F2aXNpdGVkJTIwJTdCJTBBY29sb3IlM0ElMjMwMDAwMzMlM0IlMEElN0QlMEFhLkdlbmVyYXRlZExpbmslM0Fob3ZlciUyMCU3QiUwQWNvbG9yJTNBJTIzRkY2NjMzJTNCJTBBJTdEJTBBYS5HZW5lcmF0ZWRMaW5rJTNBYWN0aXZlJTIwJTdCJTBBY29sb3IlM0ElMjNGRjk5MDAlM0IlMEElN0QlMEElM0MlMkZzdHlsZSUzRSUwQSUwQSUwQSUzQ2ElMjBjbGFzcyUzRCUyMkdlbmVyYXRlZExpbmslMjIlMjBocmVmJTNEJTIyaHR0cCUzQSUyRiUyRnd3dy5leHBhdG1lZGlhLm5ldCUyRmFkdmVydGlzZS13aXRoLXVzJTIyJTIwdGFyZ2V0JTNEJTIyX2JsYW5rJTIyJTIyJTNFQURWRVJUSVNFJTIwSEVSRSUzQyUyRmElM0UlM0NhJTIwaHJlZiUzRCUyMmh0dHAlM0ElMkYlMkZleHBhdG1lZGlhLm5ldCUyRmNsYXNzaWZpZWRzJTJGJTIyJTNFJTBBJTNDaW1nJTIwYm9yZGVyJTNEJTIyMCUyMiUyMGFsdCUzRCUyMkZpbmQlMjBvciUyMHBvc3QlMjBuZXclMjBqb2JzJTJDJTIwbW90b3IlMjBhZHMlMjBhbmQlMjBjbGFzc2lmaWVkcyUyMiUyMHNyYyUzRCUyMmh0dHAlM0ElMkYlMkZleHBhdG1lZGlhLm5ldCUyRndwLWNvbnRlbnQlMkZ1cGxvYWRzJTJGMjAxNiUyRjA1JTJGRmluZC15b3VyLW5leHQtam9iLTIuanBnJTIyJTIwd2lkdGglM0QlMjIxMDAlMjUlMjIlMjBoZWlnaHQlM0QlMjIxMDAlMjUlMjIlM0UlMEElM0MlMkZhJTNFJTBBJTNDYnIlM0UlMEElM0NiciUzRSUwQSUzQyUyMS0tJTIwSFRNTCUyMENvZGUlMjAtLSUzRQ==JTNDc2NyaXB0JTIwc3JjJTNEJTIyJTJGJTJGcGFnZWFkMi5nb29nbGVzeW5kaWNhdGlvbi5jb20lMkZwYWdlYWQlMkZqcyUyRmFkc2J5Z29vZ2xlLmpzJTIyJTIwYXN5bmMlM0QlMjIlMjIlM0UlM0MlMkZzY3JpcHQlM0UlMEElMjAlM0MlMjEtLSUyMGluLWFydGljbGUlMjBhZCUyMC0tJTNFJTBBJTIwJTNDaW5zJTIwY2xhc3MlM0QlMjJhZHNieWdvb2dsZSUyMiUyMHN0eWxlJTNEJTIyZGlzcGxheSUzQSUyMGJsb2NrJTNCJTIyJTIwZGF0YS1hZC1jbGllbnQlM0QlMjJjYS1wdWItNTAwNjI0MTU4MzU4MTg0OSUyMiUyMGRhdGEtYWQtc2xvdCUzRCUyMjg1MjYwOTM2MTElMjIlMjBkYXRhLWFkLWZvcm1hdCUzRCUyMmF1dG8lMjIlM0UlM0MlMkZpbnMlM0UlMEElM0NzY3JpcHQlM0UlMkYlMkYlMjAlM0MlMjElNUJDREFUQSU1QiUwQSUyOGFkc2J5Z29vZ2xlJTIwJTNEJTIwd2luZG93LmFkc2J5Z29vZ2xlJTIwJTdDJTdDJTIwJTVCJTVEJTI5LnB1c2glMjglN0IlN0QlMjklM0IlMEElMkYlMkYlMjAlNUQlNUQlM0UlM0MlMkZzY3JpcHQlM0UlMEE=