Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Snapchat Responds to Security Breach Allegations, Promises App Update

No apology for the leaks, though.

Snapchat

After weeks of controversy surrounding user security concerns, ephemeral-messaging service Snapchat responded to allegations of hacking on Thursday, promising an update to its mobile application that may assuage the ire of upset users.

In December, an Australian security firm detailed a vulnerability in Snapchat’s application programming interface that effectively allowed savvy outsiders to connect Snapchat account names to telephone numbers. Shortly after the disclosure, an anonymous group did exactly that; around 5 million user names and phone numbers were searchable through the tool the hacker group built.

After days of radio silence, Snapchat responded:

“We will be releasing an updated version of the Snapchat application that will allow Snapchatters to opt out of appearing in Find Friends after they have verified their phone number,” the company said in a blog post. “We’re also improving rate limiting and other restrictions to address future attempts to abuse our service.”

In its current implementation, Snapchat’s app allows new users to find their friends also on the service by matching user names to cellphone address books. It has become a commonplace practice over the past few years — a simple way to jumpstart growth and engagement on a new app service by making more connections between friends.

Snapchat was dismissive of the security firm’s original findings, effectively waving off concerns in a blog post. Four days later, the loophole was exploited.

Some things to note here: The anonymous group that built the exploit tool has positioned itself as a group of “white hat” hackers, pointing out vulnerabilities so that companies will end up fixing them. In its statement on Thursday, Snapchat didn’t see it that way, painting the group as “attackers.” Make of that what you will.

More importantly, Snapchat will allow people to opt out of being found via the Find Friends address book tool in a forthcoming app update. That could have implications for Snapchat’s ability to continue growing as quickly — especially under its current spotlight of media attention and Silicon Valley hype. At one point, Snapchat also allowed newcomers the ability to find their Facebook friends who use the app, though that functionality has been removed.

In addition, the company announced a new venue for outsiders to report security vulnerabilities in the future, via an email alias at security@snapchat.com.

Snapchat made clear in its statement that “no other information, including Snaps, was leaked or accessed.”

This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh