Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO: Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
Copyright © 2023 Powered by
Researcher discovers Venmo exposes 'an alarming amount' of personal data in public API-拍板定案网
sitemap
文章
6
浏览
4862
获赞
11592
What TechSpot Writers Want in Windows 10
What is going on with the chair emoji on TikTok?
Confused why the comment sections on TikTok are flooded with chair emoji? You're not alone.In the paThe 'IWasGoingToQuitTwitterBut' hashtag is going viral on Twitter
Back in April when Elon Musk said he was buying Twitter, an intense debate kicked off online over whSpotify Wrapped's Audio Aura knows you better than you know yourself
Spotify Wrapped is here, and one of its new 2021 features is "Your Audio Aura," a reading of your twJudge won't let 'Fortnite' back into App Store as Apple fight crawls on
The battle royale between Epic Games and Apple is far from over. The ongoing debate over whether ForElon Musk says SpaceX and Apple discussed iPhone 14 satellite features
Always just a tweet away from the spotlight, Elon Musk tweeted that SpaceX and Apple talked about saScreenshots of texts with your freaking boss are taking over Twitter
You must have heard by now: there's a labor shortage, and not all bosses are acting like it. Take aThis app beeps every time you send data to Google
What if you got an audio cue every time your computer sent data to Google?Enter Googerteller, an appSecure Email and Cloud Alternatives to Gmail and Dropbox
Back in June last year, confidential documents leaked by Edward Snowden indicated that major email a18 best tweets of the week, including $10 mode, Joseph Thee Stallion, and Gregor Samsa
Thanksgiving is over with, good friends, so deck the halls, pull out your credit cards, flip on HallApple's new M2 MacBook Air is coming July 15, report says
When Apple launched its new MacBook Air with the M2 chip at WWDC in June, it never gave us an exactHow to create a QR codes for Instagram posts
I hate to squash the hopes of QR code haters, but it appears to bet one piece of pandemic tech that'Oscar Mayer is releasing a hot dog
A food evil greater than pineapple pizza has emerged, and we need to band together for some good ol'Google Maps update improves cycling directions and location sharing
That scorching summer weather isn’t going away anytime soon, so Google Maps is introducing a fBecome besties with the reigning king of college TikTok
Welcome toSmall Talk, a series where we catch up with the internet's favorite Extremely Online indiv