Snapchat says it has fixed latest security flaw

A new security snafu hits Snapchat – as does another solution. 

|
Snapchat
Snapchat says it has fixed the latest security vulnerability.

Another month, another Snapchat snafu. 

In January, it was a hole, exposed by the Australian security group Gibson Security, through which hackers were able to extract the personal information of millions of users. (Snapchat eventually said it would build some "additional counter-measures" to prevent future breaches, although the belated nature of the response was criticized by many industry insiders.) 

Now it's a vulnerability in the iOS version of the Snapchat app that could facilitate massive denial-of-service attacks, causing Apple devices to completely crash. According to Jaime Sanchez, the security consultant credited with discovering the vulnerability, the problem is directly linked to the "tokens" used by Snapchat to authenticate the identify of a user. 

In an interview with the Los Angeles Times, Mr. Sanchez said old tokens could be used to send new messages. Send enough of those messages, and you could overwhelm a user's operating system altogether. To prove his point, Sanchez borrowed the phone of LA Times tech reporter Salvador Rodriguez. 

"Sanchez demonstrated how this works by launching a Snapchat denial-of-service attack on my account," Mr. Rodriguez later wrote. "He sent my account 1,000 messages within five seconds, causing my device to freeze until it finally shut down and restarted itself. Launching a denial-of-service attack on Android devices doesn’t cause those smartphones to crash, but it does slow their speed. It also makes it impossible to use the app until the attack has finished."

For its part, Snapchat has not said whether it was surprised by Sanchez's findings. But it has said the problem is solved. 

"We believe we have addressed the issue as early as Friday, and we continue to make significant progress in our efforts to secure Snapchat," a rep for Snapchat told the Huffington Post. 

You've read  of  free articles. Subscribe to continue.
Real news can be honest, hopeful, credible, constructive.
What is the Monitor difference? Tackling the tough headlines – with humanity. Listening to sources – with respect. Seeing the story that others are missing by reporting what so often gets overlooked: the values that connect us. That’s Monitor reporting – news that changes how you see the world.

Dear Reader,

About a year ago, I happened upon this statement about the Monitor in the Harvard Business Review – under the charming heading of “do things that don’t interest you”:

“Many things that end up” being meaningful, writes social scientist Joseph Grenny, “have come from conference workshops, articles, or online videos that began as a chore and ended with an insight. My work in Kenya, for example, was heavily influenced by a Christian Science Monitor article I had forced myself to read 10 years earlier. Sometimes, we call things ‘boring’ simply because they lie outside the box we are currently in.”

If you were to come up with a punchline to a joke about the Monitor, that would probably be it. We’re seen as being global, fair, insightful, and perhaps a bit too earnest. We’re the bran muffin of journalism.

But you know what? We change lives. And I’m going to argue that we change lives precisely because we force open that too-small box that most human beings think they live in.

The Monitor is a peculiar little publication that’s hard for the world to figure out. We’re run by a church, but we’re not only for church members and we’re not about converting people. We’re known as being fair even as the world becomes as polarized as at any time since the newspaper’s founding in 1908.

We have a mission beyond circulation, we want to bridge divides. We’re about kicking down the door of thought everywhere and saying, “You are bigger and more capable than you realize. And we can prove it.”

If you’re looking for bran muffin journalism, you can subscribe to the Monitor for $15. You’ll get the Monitor Weekly magazine, the Monitor Daily email, and unlimited access to CSMonitor.com.

QR Code to Snapchat says it has fixed latest security flaw
Read this article in
https://www.csmonitor.com/Technology/2014/0211/Snapchat-says-it-has-fixed-latest-security-flaw
QR Code to Subscription page
Start your subscription today
https://www.csmonitor.com/subscribe