Users from 4chan claim to have discovered an exposed database hosted on Google’s mobile app development platform, Firebase, belonging to the newly popular women’s dating safety app Tea. Users say they are rifling through peoples’ personal data and selfies uploaded to the app, and then posting that data online, according to screenshots, 4chan posts, and code reviewed by 404 Media.

  • @gnu@lemmy.zip
    link
    fedilink
    English
    15622 days ago

    People sign up to app intended to share personal information about others without their permission, end up having their own personal information shared without permission - the irony is impressive.

    • @surewhynotlem@lemmy.world
      link
      fedilink
      English
      10922 days ago

      At first I was going to call bullshit because I thought you were exaggerating and being ridiculous.

      Nope. That’s the app. “Anonymous” sharing of pictures and info of other people. Presumably without their permission. That’s fucked up.

      • @blarghly@lemmy.world
        link
        fedilink
        English
        5022 days ago

        Yeah. I mean, I get it. The concept of the app makes sense. And I would be that, on average, it is/would be used for good.

        On the other hand, as a guy, the idea that people are out there sharing reviews of me as a person on the open internet, and I have no way of knowing this, is deeply unsettling. Like, I haven’t done anything wrong - just the whole concept feels very gross.

        • @InFerNo@lemmy.ml
          link
          fedilink
          English
          1021 days ago

          You could ask someone you know to register and share the login, it’s a flawed concept. There’s probably a bunch of partners in there who didn’t even know their boyfriend used their info to create an account to check on themselves.

        • @Donkter@lemmy.world
          link
          fedilink
          English
          3621 days ago

          Especially because the app is called “tea”, like the slang term for gossip. The letter of the intention may have been good but the whole thing is toxic.

        • @surewhynotlem@lemmy.world
          link
          fedilink
          English
          621 days ago

          My problem is how it’s implemented.

          An app where you simply post a name and a location, and then people can DM you with their experiences directly, would be a lot less invasive.

    • Zomg
      link
      fedilink
      English
      2221 days ago

      I think it depends on people’s intent and purpose for using this service. I’m overall not a fan of someone taking and sharing pictures of me without my consent, or making claims that can’t be defended…

      The group of women legitimately using it for safety is fine, in a general sense.

      The group of women using it as gossip and entertainment is not.

      • @DrSteveBrule@mander.xyz
        link
        fedilink
        English
        37
        edit-2
        21 days ago

        Considering that “tea” is common slang for gossip I’m not convinced there was many of the latter former.

      • @lunardroid@lemmy.blahaj.zone
        link
        fedilink
        English
        1321 days ago

        It makes sense using it for safety, but I would worry about whether all the information on there is accurate. Most of the feedback on the app is probably negative, I doubt anyone would really post anything on Tea that’s positive about their former partner. But people like to believe they are in the right. Someone who got in a fight with their partner might post something on Tea that isn’t accurate, but makes them feel better since they can spin the story how they want, and make the other person at fault. However, unlike regular social media, the person being attacked by their partner on Tea has no idea that it happened, and no way to refute what was said. It promotes the opposite of any type of communication between partners after a fight or breakup. It promotes safety, but at the same time it promotes some toxicity in relationships. What would you think if you knew that if your got into a disagreement with your partner that you could end up posted on this app, without any way of arguing back?

  • @LibertyLizard@slrpnk.net
    link
    fedilink
    English
    11422 days ago

    I would not under any circumstances give my drivers license to a for profit app. I don’t even like to give my email.

          • Echo Dot
            link
            fedilink
            English
            121 days ago

            Ed Davey, I can’t imagine Bad Enoch doing anything and Labour were the ones to implement this.

        • @HereIAm@lemmy.world
          link
          fedilink
          English
          2022 days ago

          Unfortunately this is the better of the two main parties. This isn’t republicans winning because dems didn’t vote. Labour won, and this still went through. The UK government as a whole has been on an anti porn brigade for decades. I can’t wait for the day labour and the Tories just die off.

          • @Djehngo@lemmy.world
            link
            fedilink
            English
            1021 days ago

            Technically the act passed in 2023 under the Sunak government.

            That said; I can’t seem to find a vote breakdown and I would not be at all surprised if labour also backed it.

            I’m hoping enough public dissatisfaction leads to labour repealing it but I won’t hold my breath.

  • @sunglocto@lemmy.dbzer0.com
    link
    fedilink
    English
    21622 days ago

    This is what happens when you decide to vibecode a service with zero attention to safety or web development. This is why you don’t immediately jump onto a new service without it being vetted properly. Now one of the worst communities on the Internet is in possession of over a hundred thousand women’s driving licenses and faces. This is going to be an absolute disaster.

    • @Darrell_Winfield@lemmy.world
      link
      fedilink
      English
      16322 days ago

      This is ALSO why no service should ever require or get my driver’s license information. Fuck that. Also, yet another Constance to those who can’t afford a car or want to improve the environment by living car free.

      • @shiroininja@lemmy.world
        link
        fedilink
        English
        3022 days ago

        My only exception to that are uber drivers. But then again we live in an age where somehow better help has become popular, even though they sell your data.

        • TXL
          link
          fedilink
          English
          1221 days ago

          I disagree on even that. It should be enough to have some trusted “notary” tick a box that they have verified your driver’s license as valid. It should not be stored out sent anywhere at any time. Just showed to a human. Regularly, if needed.

      • @Alaik@lemmy.zip
        link
        fedilink
        English
        221 days ago

        The only site I ever felt comfortable scanning shit like that into was a site that sold things only to military/medics/fire fighters so I had to upload my medic license and my FF cert.

        Anything beyond that is a no go from me.

      • JackbyDev
        link
        fedilink
        English
        521 days ago

        Instead, just prove you have a credit card by submitting the details. Also totally safe. Be sure to include the CVV, please!

      • ByteOnBikesOP
        link
        fedilink
        English
        -15
        edit-2
        22 days ago

        I honestly don’t understand what op is talking about.

        Leaks happen all the time, even in billion dollar companies.

        Their comment is the equivalent like, “This is why you should lock your doors!” Like uh okay.

        • @prof@infosec.pub
          link
          fedilink
          English
          2022 days ago

          This situation would have been easily preventable with basic understanding of what they’re doing is what OP is saying. This leak is not something highly complex, it is painfully stupid on the side of the developers.

          There’s a difference between a hack, where data is exposed, compared to data exposure due to negligence or ignorance on the development side.

          • @Eheran@lemmy.world
            link
            fedilink
            English
            621 days ago

            Again, how should the end use know anything about what is going on at their end? How does anyone “vett” that? It is a nonsense “argument” to put blame on the users.

            • @prof@infosec.pub
              link
              fedilink
              English
              1
              edit-2
              21 days ago

              Where I’m from there’s certificates a company can get, that confirm a certain level of process and IT security. Also a company existing for at least 5-10 years without incidents is a “vetted” company in my books. At least anything that managed to produce a working IT system before 2021 when AI came around.

              I also believe there’s a bit of bad wording going on with the original comment. Take it up with that guy, lol.

        • Tlaloc_Temporal
          link
          fedilink
          English
          1222 days ago

          This was more like leaving all your valuables in a cardboard box on your front lawn. Anyone can just take it, if they care to look inside the complete unsecured box.

          Someone just drove up and tossed the box in their truck. No lock involved.

        • @Eheran@lemmy.world
          link
          fedilink
          English
          -321 days ago

          I love how people just jump on whatever they like, instead of actually thinking about the stuff they read/comment on/upvote. Exactly like on Reddit, no difference.

      • Thymos
        link
        fedilink
        English
        721 days ago

        This is something I worry about all the time as well, especially since I’ve started to learn how to code and experienced how easy it is to mess up and send a list with all registered users to everyone opening a page. (This was in a test environment.)

        As a user, there is no proper way I know of to verify an app’s security. Most apps are closed source, but even if you could view the code, what would you look for?

        Both Apple and Google have a verification process for apps that are published in their app stores, but if these worked, we wouldn’t see this happening.

        There are academic researchers working on apps and privacy as well, but it’s not like you can ask them for a report on an app you’re thinking of installing.

        I think it basically comes down to trust. Check if a developer has messed up in the past and how they dealt with that, that sort of stuff. And for dating apps there is this interesting article: https://www.privacyguides.org/articles/2025/06/24/queer-dating-apps-beware-who-you-trust/#reducing-the-risks-when-using-dating-apps

        It’s a long read (haven’t fully read it myself yet) and it paints a bleak picture, but that’s the world we live in today.

        • @troglodyke@lemmy.federate.cc
          link
          fedilink
          English
          220 days ago

          You can pay for a 3rd party to penetration test your app, it’s good practice to do this before you launch an app, after any significant changes, and annually at a minimum.

          There are also a growing number of companies offering continuous penetration testing - basically, automated pen tests - but these are expensive and it’s difficult to convince companies that the cost is worth it

          • Thymos
            link
            fedilink
            English
            120 days ago

            Thanks, that’s good to know! If I do ever decide to release an app, I’ll definitely look into this.

    • @4am@lemmy.zip
      link
      fedilink
      English
      6822 days ago

      Now now, I like to shit on vibecoders too but let’s not pretend this is some new problem.

      Idiots leave databases on cloud servers exposed all the time rather than deal with their companies often arcane rules for generating certificates

    • @panda_abyss@lemmy.ca
      link
      fedilink
      English
      2722 days ago

      To be fair, I’m not sure why firebase even has a public access option. That’s a recipe for issues.

      Though if it’s anything like Google Cloud Store, they hopefully make it very clear that your bucket is public.

    • @zarkanian@sh.itjust.works
      link
      fedilink
      English
      321 days ago

      Anybody oblivious enough to create something like this isn’t someone you should trust your most private data with. This service had red flags from the concept phase, never mind the execution.

      This is not to say, of course, that the victims deserved it. It just really sucks that they had to learn this lesson this way.

    • @Zetta@mander.xyz
      link
      fedilink
      English
      -1122 days ago

      “Vibe coded” you just made that up didn’t you, because you don’t like llms. I don’t see anything in the article about “Ai” and this service has been operating for 2 years.

      • @shalafi@lemmy.world
        link
        fedilink
        English
        1322 days ago

        My thoughts as well. But hey, it’s lemmy! Just accuse someone of doing something we hate, good to go!

      • redjard
        link
        fedilink
        English
        821 days ago

        The og 4chan post brought up the vibe coding. Using it as an insult to quality is wider spread than just lemmy.

  • @Wispy2891@lemmy.world
    link
    fedilink
    English
    5222 days ago

    Protecting our users’ privacy and data is our highest priority. We are taking every necessary step to ensure the security of our platform

    Since sensitive data was put on a public bucket, maybe they meant it was their lowest priority?

      • @phutatorius@lemmy.zip
        link
        fedilink
        English
        120 days ago

        I live in the UK and, like nearly everyone else in the UK, have never been required to do this. The only time it’s required is when accessing adult-only sites, and there are some obvious workarounds in those cases, yarr.

  • @sp3ctr4l@lemmy.dbzer0.com
    link
    fedilink
    English
    104
    edit-2
    22 days ago

    Wow that was fast.

    I did not even know this app existed untill about 8 hours ago.

    Already comprimised.

    EDIT: Also, lol, this arguably is not even largely a hack.

    These idiots just had everything stored in a fucking publically accesible firebase bucket… amazing.

    They didn’t delete anything they claimed to.

    Either way you look at it, anywhere on the spectrum from:

    A ] A bunch of women reasonably concerned for their safety

    B ] A bunch of gossip mongers

    … well, they’ve now all been doxxed, ironic from each angle.

    What a fucking disaster.

    • JackbyDev
      link
      fedilink
      English
      221 days ago

      this arguably is not even largely a hack.

      While I agree in principle, I think we should still call it a hack. As in “to gain illegal access to (a computer network, system, etc.)” as Merriam-Webster puts it. It shouldn’t be legal to do do this just because the website had horrible (non-existent) security. You shouldn’t be allowed to rob a house just because the door wasn’t locked.

      • @db2@lemmy.world
        link
        fedilink
        English
        020 days ago

        This is more like the door was left open and the lights were on, and you took pictures of the artwork on the entryway walls and then left.

        • JackbyDev
          link
          fedilink
          English
          020 days ago

          Except it wasn’t artwork, it was driver’s licenses. You know, things you obviously shouldn’t have access to.

      • @DreamlandLividity@lemmy.world
        link
        fedilink
        English
        -1
        edit-2
        21 days ago

        At which step should it turn illegal? You accessing publicly available website? How exactly are you to know if it is supposed to be public or not, if there is not even an attempt at security?

        • JackbyDev
          link
          fedilink
          English
          221 days ago

          The thing is we don’t need to come up with some absolute definition of what should and shouldn’t be illegal to talk about this case specifically. They didn’t accidentally stumble on this. They doxxed the users instead of responsibly disclosing the problem. This is extremely cut and dry.

          If the story here was “I mistyped something and got to a page I shouldn’t have access to, I disclosed it to the company, didn’t dox anyone by sharing the problem, and now the FBI is after me” it would be different.

          • @DreamlandLividity@lemmy.world
            link
            fedilink
            English
            1
            edit-2
            21 days ago

            They were looking through publicly accessible buckets on firebase. They literally did stumble upon this by accident while going through public data. And then just told other people about what they found. Should they have disclosed it once they realized what it was instead of spreading it? Sure, morally speaking. But I don’t see how you could write a law to make this illegal without just trampling on free speech.

            • JackbyDev
              link
              fedilink
              English
              120 days ago

              And then just told other people about what they found.

              That’s a weird way to say they doxxed people instead of ethically disclosing what they found. Hiding that detail is why I have a problem with defending this.

              If someone steals something they didn’t know belonged to someone (say through an unlocked door), should we prosecute them? I don’t know. What did they do next after they found out they shouldn’t be there? Did they give it back and tell the building owners “hey, you have an unlocked door” or did they yell to the street “hey everyone, come get free stuff!” How did they behave once they knew they did something wrong.

              • @DreamlandLividity@lemmy.world
                link
                fedilink
                English
                -1
                edit-2
                20 days ago

                From what I have seen, they initial guys shared a link to the database, not any content. The equivalent of telling people: “Look at this unlocked door I found.” They did not “steal” anything as far as I know.

                Also, the analogy doesn’t work either. What if it really was intended to be public? Making a copy is not analogous to stealing something, it’s analogous to taking a picture.

                PS: Maybe to make it clearer what I am thinking of. A real court case that happened: A person found a bunch of documents on a government website, just sitting there. He decided to share them. Turns out they were not supposed to be public. The government tried to prosecute the guy who had no idea the files were not public. They thankfully lost.

                How can it be the responsibility of a person to try to figure out if these files are supposed to be public or are public on accident? Yes, these guys had a good guess that this was an accident, but so what. We don’t prosecute people for having good guesses.

                • JackbyDev
                  link
                  fedilink
                  English
                  120 days ago

                  Damn, do you think this link I found that has a ton of women’s drivers licenses is supposed to be public? Better share it to 4chan. They’ll know what to do.

    • 𝕛𝕨𝕞-𝕕𝕖𝕧
      link
      fedilink
      English
      621 days ago

      if that’s truly how the leak happened then these people, in any reasonable jurisdiction, would be considered criminally negligent, at the least.

      yay compsci ethics courses :D

      boo courts failing to uphold the law >:(

  • ByteOnBikesOP
    link
    fedilink
    English
    4922 days ago

    My friend came over and told me a story about this crazy date she was on. The guy love bombs her, sets her up with a massage, then in the morning, goes out and eats McDonalds alone and ghosts her. Then repeats every few weeks with love bombs.

    I shared that with my discord group and someone said they know that guy too.

    Im assuming that’s what Tea is for.

  • @ToiletFlushShowerScream@lemmy.world
    link
    fedilink
    English
    8422 days ago

    Not sure if this is ironic that the users are now less safe after using the safety app. But I still feel bad for the users. Dating is hard enough without the fear of being harmed.

  • Jesus
    link
    fedilink
    English
    2621 days ago

    Hungry data privacy lawyers when they learned about Tea this week:

  • zkfcfbzr
    link
    fedilink
    English
    2722 days ago

    I thought 4chan shut down permanently like 2 months ago?

    • @Hozerkiller@lemmy.ca
      link
      fedilink
      English
      3421 days ago

      Seeing as the word hack is doing a lot of heavy lifting. They didn’t bother to actually secure the data and then put it on the internet for anyone to access.

  • @BackgrndNoize@lemmy.world
    link
    fedilink
    English
    4521 days ago

    This is why there should be a nationwide rule that PII data should be deleted after the users identity has been verified

  • @Bronzebeard@lemmy.zip
    link
    fedilink
    English
    2521 days ago

    I had been under the impression that 4chan had also basically died due to their own site getting hacked

    • @Revan343@lemmy.ca
      link
      fedilink
      English
      1221 days ago

      It’s not like it was a complicated site, they just rebuilt it in some modern framework on the cheap.

    • Ricky Rigatoni
      link
      fedilink
      English
      1821 days ago

      the site got hacked and most of the admins were revealed to have .gov emails but everyone pretty much already expected that so nobody actually cared and it’s back to business as usual

      • ObjectivityIncarnate
        link
        fedilink
        English
        321 days ago

        most of the admins were revealed to have .gov emails

        I remember reading that this was something someone just made up and was spread a bunch, but wasn’t true at all.

  • Maybe I’m just getting old, but the idea of “verifying” my real identity to a faceless website or mobile app is abhorrent.

    I guess it doesn’t help that governments in some countries (UK, Australia that I know of) are encouraging this bullshit with Trojan horse laws claiming to protect children from adult websites / social media.

    Can’t help but think there is also an element of pot meet kettle here, when users of an app designed to dox and slander people without their knowledge are now the ones getting doxxed themselves.

    • @kalpol@lemmy.ca
      link
      fedilink
      English
      821 days ago

      California, Utah, Texas all have laws now requiring age verification to use an app store

    • omniman
      link
      fedilink
      English
      -1322 days ago

      What if they take people’s biometric aka fingerprint and to view nsfw stuff you goota use the biometric and I am not talking about passkey