Skip to main content

A Second Tea Breach Reveals Users' DMs About Abortions and Cheating

1 month 1 week ago
A second, far more recent data breach at women's dating safety app Tea has exposed over a million sensitive user messages -- including discussions about abortions, infidelity, and shared contact info. This vulnerability not only compromised private conversations but also made it easy to unmask anonymous users. 404 Media reports: Despite Tea's initial statement that "the incident involved a legacy data storage system containing information from over two years ago," the second issue impacting a separate database is much more recent, affecting messages up until last week, according to the researcher's findings that 404 Media verified. The researcher said they also found the ability to send a push notification to all of Tea's users. It's hard to overstate how sensitive this data is and how it could put Tea's users at risk if it fell into the wrong hands. When signing up, Tea encourages users to choose an anonymous screenname, but it was trivial for 404 Media to find the real world identities of some users given the nature of their messages, which Tea has led them to believe were private. Users could be easily found via their social media handles, phone numbers, and real names that they shared in these chats. These conversations also frequently make damning accusations against people who are also named in the private messages and in some cases are easy to identify. It is unclear who else may have discovered the security issue and downloaded any data from the more recent database. Members of 4chan found the first exposed database last week and made tens of thousands of images of Tea users available for download. Tea told 404 Media it has contacted law enforcement. [...] This new data exposure is due to any Tea user being able to use their own API key to access a more recent database of user data, Rahjerdi said. The researcher says that this issue existed until late last week. That exposure included a mass of Tea users' private messages. In some cases, the women exchange phone numbers so they can continue the conversation off platform. The first breach was due to an exposed instance of app development platform Firebase, and impacted tens of thousands of selfie and driver license images. At the time, Tea said in a statement "there is no evidence to suggest that current or additional user data was affected." The second database includes a data field called "sent_at," with many of those messages being marked as recent as last week.

Read more of this story at Slashdot.

BeauHD

Anker Is No Longer Selling 3D Printers

1 month 1 week ago
Anker has indefinitely paused sales of its 3D printers, with no clear plans to resume or release new models. Despite promises of ongoing support, critical replacement parts like hotends and extruders have quietly vanished from the EufyMake site, leaving customers and the maker community in the lurch. The Verge reports: In March, charging giant Anker announced it would spin out its 3D printer business into an "independent sub-brand," stating that the new EufyMake would "continue to provide comprehensive customer service and support" for its original 3D printers the AnkerMake M5 and M5C. Now, the 3D printing community is wondering whether that was all a euphemism for exiting the 3D printer business. eufyMake is no longer selling any 3D printers and has stopped selling some of the parts it would need to provide anything close to "comprehensive support." Anker confirms to The Verge that it has stopped selling the M5 and M5C 3D printers indefinitely. Spokesperson Brett White could not confirm that the company will resume selling them or create any future models. He says that "sales have been paused." "My understanding is that eufyMake has not ruled out creating new 3D printer models in the future. But the brand has ended sales of the M5 and M5C for the time being," White tells The Verge. The 3D printing section of EufyMake's website is currently empty of printers. The only gadget EufyMake now sells is a UV printer that creates a 3D texture atop flat materials.

Read more of this story at Slashdot.

BeauHD

OpenAI's ChatGPT Agent Casually Clicks Through 'I Am Not a Robot' Verification Test

1 month 1 week ago
An anonymous reader quotes a report from Ars Technica: On Friday, OpenAI's new ChatGPT Agent, which can perform multistep tasks for users, proved it can pass through one of the Internet's most common security checkpoints by clicking Cloudflare's anti-bot verification -- the same checkbox that's supposed to keep automated programs like itself at bay. ChatGPT Agent is a feature that allows OpenAI's AI assistant to control its own web browser, operating within a sandboxed environment with its own virtual operating system and browser that can access the real Internet. Users can watch the AI's actions through a window in the ChatGPT interface, maintaining oversight while the agent completes tasks. The system requires user permission before taking actions with real-world consequences, such as making purchases. Recently, Reddit users discovered the agent could do something particularly ironic. The evidence came from Reddit, where a user named "logkn" of the r/OpenAI community posted screenshots of the AI agent effortlessly clicking through the screening step before it would otherwise present a CAPTCHA (short for "Completely Automated Public Turing tests to tell Computers and Humans Apart") while completing a video conversion task -- narrating its own process as it went. The screenshots shared on Reddit capture the agent navigating a two-step verification process: first clicking the "Verify you are human" checkbox, then proceeding to click a "Convert" button after the Cloudflare challenge succeeds. The agent provides real-time narration of its actions, stating "The link is inserted, so now I'll click the 'Verify you are human' checkbox to complete the verification on Cloudflare. This step is necessary to prove I'm not a bot and proceed with the action."

Read more of this story at Slashdot.

BeauHD

Google’s latest renewable energy deal is all gas bags and hot air

1 month 1 week ago
At least big bags of CO2 can be built faster than a fusion plant

Caught in a constant race between its AI power needs and carbon emissions reduction pledges, Google's latest sustainability commitment sees it considering giant bags of carbon dioxide as a solution to dirty energy.…

Brandon Vigliarolo