Skip to main content

Are you going to get hacked while looking for love online?

online dating sites hack
stokkete/123RF
As the stigma around online dating begins to fade, an increasing number of young (and older) Americans are wading out into the sometimes turbulent waters of sites and apps like OKCupid, Match.com, and Tinder. In fact, 15 percent of our nation’s inhabitants now say they’ve used some sort of digital matchmaking tool, which means that a lot of these sites and apps have a lot of people’s personal information. Sure, signing up for Tinder isn’t quite like applying for a credit card, but it should still be noted that many of these online dating services collect quite a bit of data on its users. And according to recent research from security provider Seworks and security tech company UpGuard, dating apps are ripe for the picking when it comes to the next big hack.

This Valentine’s Day, Pew Research estimated that some 38 percent of U.S. singles had a profile on a dating site or app. But according to Min-Pyo Hong of Seworks, these services are all extremely vulnerable to attack. Last Month, Hong and his team reviewed five “top dating apps,” and found that “all were vulnerable to hacking, containing exploits that would enable breaches similar to the infamous attack on Snapchat … or … the leaking of users’ data from an HIV-positive dating app.” And while Hong did not disclose which apps his team analyzed in his guest post for VentureBeat, he noted that “the two very most popular we analyzed have been downloaded between 10 million and 100 million times from Google Play alone.”

Recommended Videos

Key to Seworks findings were the fact that all five of the apps were 100 percent decompilable, which Hong explains as “a process that enables hackers to reverse engineer and compromise an app.” Worse yet, “none of the dating apps [they] analyzed had protections to prevent or delay unauthorized decompiling,” and one of the apps “was not using secure communications, making it easy for hackers to intercept data being exchanged between the app and the server.” And perhaps most alarming was the fact that the source code of these apps was obfuscated, or in plain text. Some of this text included “hard-coded key values, website addresses, and other critical information that could allow hackers access to sensitive data.”

But it’s not just apps that are problematic. When UpGuard used its Website Risk Grader on some of  “the world’s top dating sites,” they were met with some disappointing and rather alarming results. Websites can earn a maximum score of 950 based on “publicly accessible security factors, such as whether SSL is enabled, whether cookies are secure, how easily someone could falsify communication as the company and a number of other factors.” The lower the score, the higher the potential for security breaches.

EHarmony, one of the most famous (and perhaps oldest) of the dating sites, scored just 504, and PlentyOfFish, whose mobile application allows for use anytime, scored just 361. Even better known sites like Match.com could stand for some improvement — it scored a 741, with UpGuard noting that the site lacks “HSTS, secure cookies, and DNSSEC.”

So if you’re looking for love online, have at it — but be careful where you’re fishing.

Lulu Chang
Former Digital Trends Contributor
Fascinated by the effects of technology on human interaction, Lulu believes that if her parents can use your new app…
WhatsApp’s online backups are getting end-to-end encryption
The WhatsApp logo.

Facebook is tightening WhatsApp's security by extending end-to-end encryption (E2EE) to cloud backups via an update to the app on iOS and Android. This was already allowed this on local WhatsApp backups, but the company will extend these security tools to online backups made to iCloud and Google Drive.

"Starting today, we are making available an extra, optional layer of security to protect backups stored on Google Drive or iCloud with end-to-end encryption. No other global messaging service at this scale provides this level of security for their users' messages, media, voice messages, video calls, and chat backup," the WhatsApp team shared this week.

Read more
Animal Crossing won’t take away your DLC items if you ditch Switch Online
Key art for Animal Crossing Happy Home Paradise.

Nintendo has clarified some details about the upcoming Animal Crossing: New Horizons -- Happy Home Paradise DLC and how it interacts with Nintendo Online memberships. In a statement sent to Digital Trends, Nintendo of America confirms that players will be able to keep items they earned through the DLC, even if they cancel their Nintendo Switch Online + Expansion Pack membership. However, they will not be able to play the DLC once they unsubscribe from the service.

According to Nintendo, players will need an active Expansion Pack membership to play the DLC. The archipelago will become inactive if players unsubscribe and do not own a copy of the DLC. Nintendo confirms that save data will still remain stored on the console. So if a player unsubscribes, they will not lose their save data and will be able to resume where they left off if they buy the DLC or resubscribe.

Read more
PAW Patrol dogs will get you where you’re going with new Waze feature
Characters from the PAW Patrol.

Waze likes to roll out fun features from time to time, and the latest one is timed to the launch of PAW Patrol: The Movie.

Aimed at kids, or, more accurately, parents who are eager to keep their little ones entertained on long drives, Waze users globally can now get driving directions from Ryder and his loyal team of rescue dogs.

Read more