Researchers have made a shocking discovery: nearly 1.5 million private photos from five dating apps, including kink site BDSM People and LGBT platforms like Pink and Translove, were found online without any password protection. These images, many containing explicit content, were accessible to anyone with the link, raising alarms about user privacy.
The company behind these apps, M.A.D Mobile, was first alerted to this serious security flaw back in January but failed to take adequate action until recently, after a BBC inquiry. Ethical hacker Aras Nazarovas found the vulnerable storage while analyzing the apps' code, realizing that, upon accessing it, he could see a number of sensitive images, some even removed by moderators.
While M.A.D Mobile has now rectified the issue and expressed appreciation for the research team's efforts, concerns linger about other potential hackers who might have exploited the breach. Nazarovas emphasized the serious risks, especially for users living in countries hostile to LGBT identities.
Public pressure led to the revelation of the flaw despite researchers’ usual restraint in such situations, highlighting the need for companies to prioritize user privacy and data security. An update for the apps is expected soon, but many users remain understandably worried about the exposure of their private materials.