Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Founder Sahil Lavingia says he was booted from DOGE after just 55 days 

    May 28, 2025

    Security startup Horizon3.ai is raising $100M in new round

    May 28, 2025

    Nvidia expects to lose billions in revenue due to H20 chip licensing requirements

    May 28, 2025
    Facebook X (Twitter) Instagram
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    My BlogMy Blog
    • Home
    • Features
      • Example Post
      • Typography
      • Contact
      • View All On Demos
    • Technology

      Is the Hyperloop Doomed? What Elon Musk’s Latest Setback Really Means

      March 10, 2022

      The Best Early Black Friday Deals on Gaming Laptops and Accessories

      March 10, 2022

      Apple Watch’s ECG Can Help Diagnose Heart Problem: Research

      January 19, 2021

      Simple Tips and Tricks to Take Care of Your Expensive DSLR Camera

      January 16, 2021

      Tech Study Reveals Effects of Mobile Technology on Professionals

      January 15, 2021
    • Typography
    • Phones
      1. Technology
      2. Gaming
      3. Gadgets
      4. View All

      Is the Hyperloop Doomed? What Elon Musk’s Latest Setback Really Means

      March 10, 2022

      The Best Early Black Friday Deals on Gaming Laptops and Accessories

      March 10, 2022

      Apple Watch’s ECG Can Help Diagnose Heart Problem: Research

      January 19, 2021

      Simple Tips and Tricks to Take Care of Your Expensive DSLR Camera

      January 16, 2021

      Game Development This Week: Save On Essential Tools and More

      November 19, 2022

      Riot Games Acquires a Wargaming Studio to Help With Live Game Development

      March 10, 2022

      Keep Talking and Nobody Explodes: A Boomer Gaming in VR

      March 12, 2021

      Hologate Announces New Plans for First Large Format World VR Arcade

      January 16, 2021
      8.9

      DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

      January 15, 2021
      8.9

      Bose QuietComfort Earbuds II: Noise-Cancellation Kings Reviewed

      January 15, 2021

      Thousands Of PC Games Discounted In New Black Friday Sale

      January 15, 2021

      Could Solar-Powered Headphones Be The Next Must-Have?

      January 15, 2021

      Will Using a VPN on Phone Helps Protect You from Ransomware?

      January 14, 2021

      Popular New Xbox Game Pass Game Being Review Bombed With “0s”

      January 14, 2021

      Google Says Surveillance Vendor Targeted Samsung Phones

      January 14, 2021

      Why Are iPhones More Expensive Than Android Phones?

      January 14, 2021
    • Buy Now
    Subscribe
    My BlogMy Blog
    Home»Uncategorized»Dating app Raw exposed users’ location data and personal information
    Uncategorized

    Dating app Raw exposed users’ location data and personal information

    Y U RajuBy Y U RajuMay 2, 2025No Comments5 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    A security lapse at dating app Raw publicly exposed the personal data and private locations data of its users, TechCrunch has found.

    The exposed data included users’ display names, dates of birth, dating and sexual preferences associated with the Raw app, as well as users’ location. Some of the location data included coordinates that were specific enough to locate Raw app users with street-level accuracy.

    Raw, which launched in 2023, is a dating app that claims to offer more genuine interactions with others in part by asking users to upload daily selfie photos. The company does not disclose how many users it has, but its app listing on the Google Play Store notes more than 500,000 Android downloads to date.

    News of the security lapse comes in the same week that the startup announced a hardware extension of its dating app, the Raw Ring, an unreleased wearable device that it claims will allow app users to track their partner’s heart rate and other sensor data to receive AI-generated insights, ostensibly to detect infidelity.

    Notwithstanding the moral and ethical issues of tracking romantic partners and the risks of emotional surveillance, Raw claims on its website and in its privacy policy that its app, and its unreleased device, both use end-to-end encryption, a security feature that prevents anyone other than the user — including the company — from accessing the data.

    When we tried the app this week, which included an analysis of the app’s network traffic, TechCrunch found no evidence that the app uses end-to-end encryption. Instead, we found that the app was publicly spilling data about its users to anyone with a web browser.

    Raw fixed the data exposure on Wednesday, shortly after TechCrunch contacted the company with details of the bug.

    “All previously exposed endpoints have been secured, and we’ve implemented additional safeguards to prevent similar issues in the future,” Marina Anderson, the co-founder of Raw dating app, told TechCrunch by email. 

    When asked by TechCrunch, Anderson confirmed that the company had not performed a third-party security audit of its app, adding that its “focus remains on building a high-quality product and engaging meaningfully with our growing community.”

    Anderson would not commit to proactively notifying affected users that their information was exposed, but said the company would “submit a detailed report to the relevant data protection authorities under applicable regulations.”

    It’s not immediately known how long the app was publicly spilling its users’ data. Anderson said that the company was still investigating the incident. 

    Regarding its claim that the app uses end-to-end encryption, Anderson said Raw “uses encryption in transit and enforces access controls for sensitive data within our infrastructure. Further steps will be clear after thoroughly analyzing the situation.” 

    Anderson would not say, when asked, whether the company plans to adjust its privacy policy, and Anderson did not respond to a follow-up email from TechCrunch.

    How we found the exposed data

    TechCrunch discovered the bug on Wednesday during a brief test of the app. As part of our test, we installed the Raw dating app on a virtualized Android device, which allows us to use the app without having to provide any real-world data, such as our physical location.

    We created a new user account with dummy data, such as a name and date of birth, and configured our virtual device’s location to appear as though we were at a museum in Mountain View, California. When the app requested our virtual device’s location, we allowed the app access to our precise location down to a few meters.

    We used a network traffic analysis tool to monitor and inspect the data flowing in and out of the Raw app, which allowed us to understand how the app works and what kinds of data the app was uploading about its users. 

    TechCrunch discovered the data exposure within a few minutes of using the Raw app. When we first loaded the app, we found that it was pulling the user’s profile information directly from the company’s servers, but that the server was not protecting the returned data with any authentication.

    In practice, that meant anyone could access any other user’s private information by using a web browser to visit the web address of the exposed server — api.raw.app/users/ followed by a unique 11-digit number corresponding to another app user. Changing the digits to correspond with any other user’s 11-digit identifier returned private information from that user’s profile, including their location data.

    a screenshot showing an exposed user's profile set up by TechCrunch, which includes the user's precise location.
    Image Credits:TechCrunch
    a screenshot showing the location of the TechCrunch user's profile on a map, hovering over Mountain View, California.
    Image Credits:TechCrunch

    This kind of vulnerability is known as an insecure direct object reference, or IDOR, a type of bug that can allow someone to access or modify data on someone else’s server because of a lack of proper security checks on the user accessing the data.

    As we’ve explained before, IDOR bugs are akin to having a key to a private mailbox, for example, but that key can also unlock every other mailbox on that same street. As such, IDOR bugs can be exploited with ease and in some cases enumerated, allowing access to record after record of user data.

    U.S. cybersecurity agency CISA has long warned of the risks that IDOR bugs present, including the ability to access typically sensitive data “at scale.” As part of its Secure By Design initiative, CISA said in a 2023 advisory that developers should ensure their apps perform proper authentication and authorization checks.

    Since Raw fixed the bug, the exposed server no longer returns user data in the browser. 



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleStartups Weekly: Drama or game-changer? You decide
    Next Article Uber’s latest autonomous vehicle partner? Chinese startup Momenta
    Y U Raju

    Related Posts

    Uncategorized

    Founder Sahil Lavingia says he was booted from DOGE after just 55 days 

    May 28, 2025
    Uncategorized

    Security startup Horizon3.ai is raising $100M in new round

    May 28, 2025
    Uncategorized

    Nvidia expects to lose billions in revenue due to H20 chip licensing requirements

    May 28, 2025
    Add A Comment
    Leave A Reply Cancel Reply

    Demo
    Top Posts

    TechCrunch Sessions: AI welcomes Tanka CEO Kisson Lin to talk AI-native startups

    May 6, 20252 Views

    Redpoint raises $650M three years after its last big early-stage fund

    May 15, 20251 Views

    Slate Auto crosses 100,000 refundable reservations in two weeks

    May 12, 20251 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    thf0oJanuary 15, 2021
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    thf0oJanuary 15, 2021
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    thf0oJanuary 15, 2021

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    TechCrunch Sessions: AI welcomes Tanka CEO Kisson Lin to talk AI-native startups

    May 6, 20252 Views

    Redpoint raises $650M three years after its last big early-stage fund

    May 15, 20251 Views

    Slate Auto crosses 100,000 refundable reservations in two weeks

    May 12, 20251 Views
    Our Picks

    Founder Sahil Lavingia says he was booted from DOGE after just 55 days 

    May 28, 2025

    Security startup Horizon3.ai is raising $100M in new round

    May 28, 2025

    Nvidia expects to lose billions in revenue due to H20 chip licensing requirements

    May 28, 2025

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.