Connect with us

News

Grindr security flaw exposes user location data

the breach put more than three million daily users at risk

Published

on

Grindr, social media app, gay news, Washington Blade

(Logo courtesy of Grindr)

More than three million of Grindr’s daily users were temporarily put at risk because of a major security flaw in the app that was exposed by a third-party site.

C*ckblocked, a now-defunct site that allowed Grindr users to view who blocked them by entering a Grindr user name and password, was able to access user information from Grindr’s Application programming interface (API). The information included email addresses, deleted photos, personal messages and the location of users.

Trever Faden, founder of C*ckblocked, told NBC that it would be easy for anyone to access a user’s private information.

“One could, without too much difficulty or even a huge amount of technological skill, easily pinpoint a user’s exact location,” Faden told NBC. 

In a separate security issue, Faden claimed that Grindr users’ location, which must be inputed directly into the app and not via a third-party site, was not encoded and could be accessed by anyone monitoring public online traffic.

Faden emphasized that the ability to find a user’s location was “a feature, not a bug.”

NBC reports that two independent cybersecurity researchers confirmed the security flaw.

After Faden informed Grindr of the security issues, Grindr blocked the flaw that allowed third-party sites like C*ckblocked to receive data.

Grindr released a statement advising users not to use their username and password for other sites.

“Grindr moved quickly to make changes to its platform to resolve this issue. Grindr reminds all users that they should never give away their username and password to any third parties claiming to provide a benefit, as they are not authorized by Grindr and could potentially have malicious intent,” the statement reads.

However, Grindr denied that user location isn’t encoded.

“Grindr is a location-based app. Location is a critical element of our social network platform. This allows our users to feel connected to our community in a world that would seek to isolate us. That said, all information transmitted between a user’s device and our servers is encrypted and communicated in a way that does not reveal your specific location to unknown third parties,” Grindr’s Chief Technology Officer Scott Chen told the Huffington Post. 

The company also released a statement on Twitter to inform users that the problems have been addressed and to be safe using their service.

The flaw is similar to the one in the Facebook/Cambridge Analytica scandal, which allegedly exposed the personal data of 50 million users.

Advertisement
FUND LGBTQ JOURNALISM
SIGN UP FOR E-BLAST

Ghana

Ghanaian lawmakers approve anti-LGBTQ bill

Measure that would criminalize allyship awaits president’s signature

Published

on

Ghanaian flag (Public domain photo from Pixabay)

Ghanaian lawmakers on Friday approved a bill that would, among other things, criminalize LGBTQ allyship.

Reuters reported MPs approved the Human Sexual Rights and Family Values Bill, 2025, in a voice vote after parliament’s Constitutional and Legal Affairs Committee backed it.

MPs in 2024 approved a similar bill, but it faced legal challenges and then-President Nana Akufo-Addo didn’t sign it. Lawmakers last year reintroduced the measure after President John Dramani Mahama took office.

The bill awaits his signature.

Rightify Ghana, a Ghanaian LGBTQ advocacy group, in a series of social media posts notes MPs passed the bill days before the 4th African Inter-Parliamentary Conference on Family Values and Sovereignty will take place in Accra, the country’s capital.

Continue Reading

Russia

Nine Russian LGBTQ groups deemed ‘extremist’ banned

Human Rights Watch: authorities ‘intensifying their criminalization’ of queer people

Published

on

(Washington Blade photo by Ernesto Valle)

Nine LGBTQ groups in Russia have been banned so far this year after authorities deemed them as “extremist.”

Human Rights Watch on Thursday noted courts in seven regions between March and May banned Coming Out, the LGBT Resource Center, Parni Plus, the Moscow Community Center for LGBT+ Initiatives, Irida, the Russian LGBT Network, the Kallisto movement, T9 NSK, and Center T. Human Rights Watch also pointed out a lawsuit has been filed against the Alliance of Straights and LGBT for Equality.

Parni Plus is an LGBTQ media outlet.

“Russian authorities are intensifying their criminalization of those who provide critical support to the very LGBT people they have systematically persecuted,” said Human Rights Watch Europe and Central Asia Director Hugh Williamson in a press release. “Authorities should vacate all court decisions and criminal convictions based on these spurious ‘extremism’ charges.”

The Kremlin over the last decade has faced global criticism over its crackdown on LGBTQ rights.

The Russian Supreme Court in 2023 ruled the “international LGBT movement” is an extremist organization and banned it.

The country in January designated ILGA World, a global LGBTQ and intersex rights group, as an “undesirable” organization. ILGA World in response to the designation noted Russians who are found guilty of engaging with “undesirable” groups face up to six years in prison.

Continue Reading

District of Columbia

D.C. Pride flag raising ceremony set for June 1

Mayor, council members to participate

Published

on

D.C. Mayor Muriel Bowser at the flag-raising of the Progress Pride flag at the Wilson Building in D.C. on June 1, 2023. (Washington Blade photo by Michael Key)

D.C. Mayor Muriel Bowser’s Office of LGBTQ Affairs is inviting the LGBTQ community and friends to attend the city’s annual Pride flag raising ceremony scheduled for 4 p.m. Monday, June 1, outside the John Wilson Building that serves as the D.C. City Hall.

Like in prior years, members of the D.C. Council and officials with the Office of LGBTQ Affairs were expected to join Bowser in delivering remarks on the front entrance steps at the Wilson Building before raising the Pride flag atop one of the tall flagpoles next to the building’s entrance.

Gaby Vincent, a spokesperson for the LGBTQ Affairs Office, said attendees of the flag raising ceremony will be invited to attend a reception immediately following the ceremony in the main lobby of the Wilson Building, which is located on Pennsylvania Avenue at 14th Street, N.W.

She said the reception will feature a DJ, dancing, and refreshments provided by the D.C. LGBTQ bar and café Spark Social House.  

Vincent said the flag raising event will also mark the 20th anniversary of the opening of the D.C. Mayor’s Office of LGBTQ Affairs.

In its official announcement of the flag raising event the LGBTQ Affairs Office also announced it is hosting the 7th annual District of Pride Showcase event to be held Friday, June 17, at 7 p.m. at the Lincoln Theater.

The announcement says LGBTQ community members, families, and allies are also invited to walk with Bowser in the Capital Pride Parade scheduled for Saturday, June 20. It says the mayor’s parade contingent will assemble at 2 p.m. at the parade’s starting location at 14th and U Streets, N.W.

“As we also celebrate the 20th anniversary of the Mayor’s Office of LGBTQ Affairs, we invite residents, community members, families and allies to join us throughout June for moments of pride, connection, visibility, and joy,” the announcement says.  

Continue Reading

Popular