Dating App ‘Raw’ Accidentally Rawdogs Users’ Location Data, Personal Info

Dating App 'Raw' Exposed Users' Personal and Location Data Due to Major Security Flaw
Photo: Gizmodo

Dating App ‘Raw’ Exposed Users’ Personal and Location Data Due to Major Security Flaw

The dating app Raw, which markets itself as a platform for ‘real and unfiltered love,’ recently suffered a serious data breach due to poor security practices. The app, known for using front and back cameras like BeReal, and for its controversial tracking device called the ‘Raw ring,’ exposed sensitive user data such as display names, dates of birth, sexual preferences, and precise location data. TechCrunch discovered the vulnerability during a routine test, revealing that the app’s servers lacked proper authentication protocols. Specifically, the flaw—an insecure direct object reference (IDOR)—allowed anyone with a web browser to access private data from other users by altering a user ID in the app’s server URL. Although Raw claimed to use end-to-end encryption, TechCrunch found no evidence of this being implemented. The app’s co-founder, Marina Anderson, stated that the vulnerabilities were patched and new safeguards have been introduced. This incident raises concerns about data protection in dating apps, which often handle extremely sensitive personal information. It underscores the need for companies to prioritize user privacy and enforce robust cybersecurity standards, especially in industries that deal with intimate and potentially risky user data.

Leave a Reply

Your email address will not be published. Required fields are marked *