In a new academic paper, researchers from the Belgian university KU Leuven detailed their findings when they analyzed 15 popular dating apps. Of those, Badoo, Bumble, Grindr, happn, Hinge and Hily all had the same vulnerability that could have helped a malicious user to identify the near-exact location of another user, according to the researchers.

While neither of those apps share exact locations when displaying the distance between users on their profiles, they did use exact locations for the “filters” feature of the apps. Generally speaking, by using filters, users can tailor their search for a partner based on criteria like age, height, what type of relationship they are looking for and, crucially, distance.

To pinpoint the exact location of a target user, the researchers used a novel technique they call “oracle trilateration.”

The good news is that all the apps that had these issues, and that the researchers reached out to, have now changed how distance filters work and are not vulnerable to the oracle trilateration technique.

Neither Badoo, which is owned by Bumble, nor Hinge responded to a request for comment.

  • PowerCrazy@lemmy.ml
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    4
    ·
    3 months ago

    Did you know that potential attackers can pinpoint your location if they are in the same public place as you?

    This really seems like complaining that a location enabled app that explicitly shares your location with other users is sharing your location with other users. That is 100% the purpose of the app to begin with!

    • lemmytellyousomething@lemmy.dbzer0.com
      link
      fedilink
      arrow-up
      11
      arrow-down
      1
      ·
      3 months ago

      Excuse me, but if they advertise that they don’t give others your exact location (only a larger radius), I expect that to be true and that an extremist can’t use a dating app to track down gay people to their home address.