PogoWasRight.org

Menu
  • About
  • Privacy
Menu

D’OH! Use Tumblr on iPhone or iPad, give your password to the WORLD

Posted on July 17, 2013 by pogowasright.org

John Leyden reports:

Tumblr’s iOS app fails to log users in through a secure (SSL) server, it has emerged. As a result users’ plaintext passwords are exposed to anyone able to sniff traffic on any Wi-Fi network an iOS user happens to use to connect to the popular cats’n’grumble free-content platform.

The wide-open security howler was discovered by a Reg reader during the course of auditing for his employer which iOS apps were permissible for use on corporate smartphones.

“I was asked to investigate various iOS apps at work to see if they are suitable for company use (no unauthorised access to company data, contacts, etc),” he explains.

Read more on The Register.

And kudos to the unnamed company who actually had their staff investigate what apps might be – or not be – safe for corporate use.

Category: BreachesBusiness

Post navigation

← Metadata, the NSA, and the Fourth Amendment: A Constitutional Analysis of Collecting and Querying Call Records Databases
UK: Statement on GCHQ’s Alleged Interception of Communications under the US PRISM Programme →

Now more than ever

Search

Contact Me

Email: [email protected]

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

Categories

Recent Posts

  • Sky Views Personal Data as a Potential Weapon in IPTV Piracy War
  • Florida Used a Nationwide Surveillance Camera Network 250 Times To Aid in Immigration Arrests
  • Federal Court Strikes Down HIPAA Reproductive Health Care Privacy Rule
  • The Markup caught 4 more states sharing personal health data with Big Tech
  • Privacy in the Big Sky State: Montana’s Consumer Privacy Law Gets Amended
  • UK Passes Data Use and Access Regulation Bill
  • Officials defend Liberal bill that would force hospitals, banks, hotels to hand over data

RSS Recent Posts on DataBreaches.net

  • Why Dumping Sensitive Data on Network Shares is a Liability
  • A militarily degraded Iran may turn to asymmetrical warfare – raising risk of proxy and cyber attacks
  • Pro-Russian hackers disrupt Dutch government websites ahead of NATO summit
  • Iran-Linked Threat Actors Leak Visitors and Athletes’ Data from Saudi Games
  • UK: Oxford City Council still investigating cyberattack from earlier this month
©2025 PogoWasRight.org. All rights reserved.