Feeds

Snapchat vows to shut its hole in wake of 4.6 million user data breach

Words like 'apologize' and 'sorry' notably absent

High performance access to file storage

Mobile image-sharer Snapchat has promised an update to its service to seal off a security hole that allowed hackers to harvest the account details of some 4.6 million users.

The company said that its update will allow users to opt out of the Find Friends system and prevent others from looking up their account information through address books. In doing so, users will no longer appear in results when others seek to match their address book numbers with potential Snapchat friends.

"When we first built Snapchat, we had a difficult time finding other friends that were using the service," Snapchat told users. "We wanted a way to find friends in our address book that were also using Snapchat – so we created Find Friends."

The move looks to close a security hole in the Snapchat service which left users subject to a "brute force" hacking process in which an attacker could build a database of contact information by uploading an archive of phone numbers to the service and saving those which returned links for Snapchat users.

Such methods were described by researchers at security firm Gibson Security, who claim to have notified Snapchat of the flaw several months ago. The company said that by exploiting flaws in the Snapchat API, the process of searching and collecting account information for mobile spam and other services could be largely automated.

Though initially dismissed by Snapchat as a "theoretical" flaw, the vulnerability was soon seized upon to build a partially secured archive of 4.6 million user names and phone numbers.

Snapchat said that in addition to implementing an opt-out for Find Friends, the company is updating its systems to help prevent automated brute force attacks or exploits.

According to security vendor AdaptiveMobile, the leaked numbers are largely concentrated to California and New York, with the two states accounting for some 2.3 million accounts. Other regions impacted include Illinois, Colorado, and Florida.

Snapchat accounts by state

Leaked accounts are largely confined to the coasts (source: AdaptiveMobile – click to enlarge)

Snapchat noted that no other personal data or user photos were collected in the attack, and CEO Evan Spiegel stopped short of issuing a mea culpa for the incident when speaking with The Today Show.

"I believe at the time we thought we had done enough," he said, "but in a business like this that is moving so quickly, if you spend your time looking backwards, you're just going to kill yourself." ®

High performance access to file storage

More from The Register

next story
Parent gabfest Mumsnet hit by SSL bug: My heart bleeds, grins hacker
Natter-board tells middle-class Britain to purée its passwords
Obama allows NSA to exploit 0-days: report
If the spooks say they need it, they get it
Web data BLEEDOUT: Users to feel the pain as Heartbleed bug revealed
Vendors and ISPs have work to do updating firmware - if it's possible to fix this
Samsung Galaxy S5 fingerprint scanner hacked in just 4 DAYS
Sammy's newbie cooked slower than iPhone, also costs more to build
Snowden-inspired crypto-email service Lavaboom launches
German service pays tribute to Lavabit
One year on: diplomatic fail as Chinese APT gangs get back to work
Mandiant says past 12 months shows Beijing won't call off its hackers
Call of Duty 'fragged using OpenSSL's Heartbleed exploit'
So it begins ... or maybe not, says one analyst
NSA denies it knew about and USED Heartbleed encryption flaw for TWO YEARS
Agency forgets it exists to protect communications, not just spy on them
prev story

Whitepapers

Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Five 3D headsets to be won!
We were so impressed by the Durovis Dive headset we’ve asked the company to give some away to Reg readers.
HP ArcSight ESM solution helps Finansbank
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.