Security News > 2020 > September > What an IDORable Giggle: AI-powered 'female only' app gets in Twitter kerfuffle over breach notification

What an IDORable Giggle: AI-powered 'female only' app gets in Twitter kerfuffle over breach notification
2020-09-11 15:59

A "Female social network" called Giggle whose operators left its user database unsecured has triggered a wave of Twitter controversy after its founder threatened to sue a UK infosec firm who pointed out the vulnerability.

Even for those who stay the hell away from Twitter there are potentially some lessons to be learnt from the Giggle debacle about responsible disclosure as well as operating an app that collects and stores users' data.

With data privacy concerns in mind, Coplans and fellow DI Security researcher Jay Harris started probing the Giggle app.

She told The Register: "I am frequently attacked on Twitter but it went up a notch. So when someone Tweeted at me that there was a vulnerability in Giggle's security, prefaced with 'we don't agree with your views', I thought it was just another run of the mill Twitter attack."

Knowledgeable folk from Pen Test Partners are still discussing on Twitter whether the lat/long co-ords leak from Giggle has truly been fixed.


News URL

https://go.theregister.com/feed/www.theregister.com/2020/09/11/giggle_female_app_data_breach_notification/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Twitter 5 0 6 2 0 8