TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Grindr Shares Personal Information With Third-Parties

840 pointsby tjwdsabout 7 years ago

33 comments

JumpCrisscrossabout 7 years ago
Even within its confines, Grindr&#x27;s data are rich for blackmail. (Consider: images and messages sent and received within 100 feet of Capitol Hill.) It was recently acquired by an offshore billionaire [1].<p>[1] <a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;articles&#x2F;2016-01-12&#x2F;china-tech-billionaire-buys-control-of-us-gay-dating-app-grindr" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;news&#x2F;articles&#x2F;2016-01-12&#x2F;china-tec...</a>
评论 #16737228 未加载
评论 #16736561 未加载
评论 #16737195 未加载
评论 #16739108 未加载
评论 #16737577 未加载
评论 #16738685 未加载
评论 #16738476 未加载
评论 #16741458 未加载
评论 #16736577 未加载
评论 #16736991 未加载
josecastilloabout 7 years ago
It might be worth making another post to highlight an additional concern: this repository itself appears to leak profile images of many Grindr users. The raw-data folder includes nearly 14,000 files, including many ads and scripts, but also thumbnails of many user profiles. This file[1] for example, once you strip out the HTTP headers, is a JPEG that shows the legs and gym socks of one user. This one [2] shows a user&#x27;s bare torso.<p>I would link to others, but most of the ones that I&#x27;ve found include clear views of users&#x27; faces, sometimes clothed and sometimes shirtless. In some cases it looks like the photos were taken in their homes. It&#x27;s ironic that in exposing Grindr&#x27;s mishandling of users&#x27; personal data, this party appears to have mishandled personal data themselves.<p>[1]: <a href="https:&#x2F;&#x2F;github.com&#x2F;SINTEF-9012&#x2F;grindr-privacy-leaks&#x2F;blob&#x2F;master&#x2F;raw-data&#x2F;raw&#x2F;2992_s.txt" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;SINTEF-9012&#x2F;grindr-privacy-leaks&#x2F;blob&#x2F;mas...</a><p>[2]: <a href="https:&#x2F;&#x2F;github.com&#x2F;SINTEF-9012&#x2F;grindr-privacy-leaks&#x2F;blob&#x2F;master&#x2F;raw-data&#x2F;raw&#x2F;3006_s.txt" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;SINTEF-9012&#x2F;grindr-privacy-leaks&#x2F;blob&#x2F;mas...</a>
评论 #16742499 未加载
评论 #16742832 未加载
评论 #16780213 未加载
buro9about 7 years ago
If you are using Grindr on Android, install and use NetGuard.<p><a href="https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=eu.faircode.netguard&amp;hl=en_GB" rel="nofollow">https:&#x2F;&#x2F;play.google.com&#x2F;store&#x2F;apps&#x2F;details?id=eu.faircode.ne...</a><p><a href="https:&#x2F;&#x2F;github.com&#x2F;M66B&#x2F;NetGuard" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;M66B&#x2F;NetGuard</a><p>NetGuard is an open source local VPN that allows you to block DNS lookups to prevent calls to 3rd parties, and it does not require root access.<p>Calls to all of the 3rd parties mentioned are blockable. Grindr does not need many domains to be operational to work, just their own domains (.grindr.com on 443, grindr.mobi on 443) and a couple of Google static domains like csi.gstatic.com on 443 .<p>Of course this does not prevent Grindr from rolling up the data and sharing that with 3rd parties, but the linked analysis suggests that this is all via the app making calls rather than the company selling it in bulk.
评论 #16736590 未加载
评论 #16737665 未加载
评论 #16736838 未加载
评论 #16765699 未加载
评论 #16744718 未加载
olliejabout 7 years ago
So vending HIV status is a straight up HIPAA violation, I&#x27;m fairly sure that&#x27;s been found to be the case over and over again -- it doesn&#x27;t matter what your business is, health information is covered by HIPAA.<p>That&#x27;s 250k per violation fine, and leaking status positive or negative is a violation. And every person, and every time they pass that information to every &quot;partner&quot; is a distinct violation.
评论 #16739887 未加载
评论 #16737380 未加载
评论 #16737474 未加载
评论 #16738895 未加载
评论 #16739852 未加载
评论 #16737415 未加载
评论 #16740009 未加载
评论 #16742815 未加载
werberabout 7 years ago
Does anyone have any information on how Scruff handles that information? Also, does HIPAA say anything about technology companies outside of the medical field&#x27;s data that may voluntarily collect HIV status?
评论 #16738283 未加载
评论 #16736163 未加载
评论 #16736352 未加载
评论 #16736278 未加载
评论 #16736270 未加载
评论 #16736193 未加载
joshstrangeabout 7 years ago
I&#x27;d be interested to see how Scruff&#x2F;Jack&#x27;d&#x2F;etc stacks up. My guess is Scruff does better (it has always been a better designed&#x2F;developed app) but I understand why they focused only on Grindr as it does have the largest market share (admittedly a guess).<p>Grindr has never been exactly a bastion of good programming... Their app has always been subpar at best with infrequent updates, months&#x2F;year long bugs, terrible UI&#x2F;Navigation, lack of features that could be coded up in a weeks time that would GREATLY improve the experience (Message archival&#x2F;hiding), and I could go on. It would be one thing if they features were relegated to the paid version (Grindr Xtra) but the only really big feature for Xtra is push notifications for when you get a new message.<p>All of this is to say the fact they are using HTTP to talk to these analytics&#x2F;ad companies doesn&#x27;t shock me at all. My bet is they haven&#x27;t updated the libraries for these services in forever (which wouldn&#x27;t be too hard to investigate).<p>As for HIV status getting sent it really depends on the service. They are not subject to HIPAA (even if you wish they were) so they can do this and I&#x27;m sure for targeting ads it makes sense. No need to waste ad dollars on &quot;Get tested for HIV&quot; for people who already know they are positive. As someone in this community and knows the orgs that pay for some of these ads are severely underfunded I have hard time saying this isn&#x27;t important to make sure your ad dollars go as far as they can.<p>Lastly for people saying &quot;just don&#x27;t enter your status&quot; you clearly don&#x27;t understand this community, I&#x27;m sorry. But people who are positive face a HUGE stigma. Chatting on Grindr&#x2F;Scruff is already an emotionally draining experience in a lot of cases, I don&#x27;t you all want the details but let&#x27;s just say failed conversations (for most people at least) don&#x27;t exactly fill you with confidence&#x2F;self-worth (yes there is a whole other discussion to be had there I&#x27;m sure). So waiting until you start a conversation to tell someone you are positive (instead of it being in your profile) is going to lead to even more failed conversations. If I were positive I think I&#x27;d trade my status away to analytics&#x2F;ad companies in exchange for not having to talk to people who aren&#x27;t interested in the first place. I&#x27;m saying that as a white male living in the US so depending on your situation you may disagree.
评论 #16740651 未加载
评论 #16743208 未加载
amqabout 7 years ago
A bit unrelated, but imagine how much data has Tinder collected, if Cambridge Analytica could do that much with just a comparatively unpopular quiz app.
评论 #16736466 未加载
评论 #16736518 未加载
评论 #16736464 未加载
ordinaryradicalabout 7 years ago
We need a new business model for social media, one which actually serves the customer instead of trying to lure them into productizing themselves.
评论 #16736250 未加载
评论 #16736781 未加载
评论 #16736458 未加载
评论 #16738454 未加载
评论 #16736414 未加载
评论 #16736476 未加载
评论 #16736264 未加载
评论 #16736357 未加载
评论 #16736243 未加载
评论 #16736409 未加载
morleyabout 7 years ago
For what it&#x27;s worth, the most private data here is shared to analytics companies for Grindr&#x27;s only analytical use. My guess is that Grindr&#x27;s agreement with Apptimize and Localytics asks for the strictest possible protection of that data. If anyone at Apptimize or Localytics has access to that data, I&#x27;d be incredibly surprised.<p>This sort of deal isn&#x27;t the same as sharing the HIV status to Google or Facebook so that advertisers can target or exclude that user information for the purposes of advertising.<p>For people who think this is still wrong, I&#x27;m curious what their pragmatic alternative is. How else are app developers supposed to analyze their app performance? The open source, self-hosted pickings are slim. (I can only think of Piwik, which in my experience has a dated feature set and severe performance issues.) Not everyone can afford to perform their own product analysis. Using a third-party analytics saas is kind of the only way to go and seems like a reasonable tradeoff of security for product visibility.
评论 #16736431 未加载
评论 #16737142 未加载
评论 #16736282 未加载
评论 #16737077 未加载
评论 #16736262 未加载
评论 #16736400 未加载
评论 #16736283 未加载
评论 #16753368 未加载
评论 #16736665 未加载
评论 #16738087 未加载
评论 #16736287 未加载
Guyneedhamabout 7 years ago
I used to be a data engineer at an ad tech company, Blis. A huge proportion of the GPS data we relied upon for retargeting and enrichment of the bids came from Grindr, but even so we almost never bid on traffic from them, the brands we worked with were opposed to being associated with that app. So we benefited a lot from Grindr data without giving much back.
olivierduvalabout 7 years ago
Grindr has health-related datas and share it... And I guess that they have some european customers, right? Might be a really nice case for GDPR in 2 months !!! :-)
dawhizkidabout 7 years ago
It&#x27;s also 100% owned now by a Chinese software company, so might as well assume everything you share there is visible to the Chinese gov&#x27;t while you&#x27;re at it.
dschuetzabout 7 years ago
It&#x27;s scary that it doesn&#x27;t surprise me anymore.<p>Especially <i>social networks</i> are considered most lucrative in terms of targeted marketing and data mining, and it&#x27;s obvious why. Social networking remains a big deal, it&#x27;s almost mandatory to have some social networking footprint online, or else you miss out on social life. Why is it still OK to trade data distilled from social media accounts? It&#x27;s not! One of the many reasons and implications are in that article.<p>Is independent social media possible? How to fund basic service infrastructure if not by running online ads, or trading user data? Is decentralized social media feasible, and who maintains a decentralized service if it is?<p>EDIT: If an app developer wants to analyze how the app performs, why share most intimate user data with third parties, Facebook being one of them?
评论 #16737809 未加载
评论 #16737997 未加载
napoluxabout 7 years ago
I think we all agree on how stupid is to track all the little details (including positions, hiv status, etc...) for the only purpose of making money, but I would like to underline that there are only two reasons to not use https today. You’re stupid or you’re lazy.<p>Can’t tell the worst, but I can tell that users should completely delete their Grindr account, now.
jonbarkerabout 7 years ago
Also, many mobile users name their device their whole name, effectively deanonymizing all their app usage for the massive ecosystem of marketing companies out there. Having worked in the mobile marketing industry I was shocked at how many people were doing this and probably had no idea this was the case.
评论 #16736372 未加载
arcasterabout 7 years ago
This is deeply troubling. Anyone who uses Tinder or any other dating site should try requesting their data and realize that these services could likely label you a sexual deviant, racist or otherwise based on your swipes alone.
评论 #16736413 未加载
评论 #16737993 未加载
评论 #16736436 未加载
adamzkabout 7 years ago
1) it&#x27;s all in the terms of service. Idk why anybody is surprised. They own everything you enter into the app anywhere full stop.<p>2) it&#x27;s not going anywhere. Its the gay Facebook. It has monopolized the market of an already vulnerable demographic so they can do whatever they want and still charge an extraordinary amount (almost $20 per month??) and provide no customer service.<p>The app doesn&#x27;t even function as advertised (at least on Android). Push notifications and read receipts have been broken for years. Btw if you restrict the permissions of the app they permanently change your status to offline.
Sideloaderabout 7 years ago
I am shocked, truly shocked at this development. An app that collects user data and passes it on to third parties without users’ consent? Unprecedented!
wackspurtabout 7 years ago
I remember this paper on ad intelligence I read a few weeks ago: &quot;Exploring ADINT: Using Ad Targeting for Surveillance on a Budget — or — How Alice Can Buy Ads to Track Bob&quot;.<p><a href="https:&#x2F;&#x2F;adint.cs.washington.edu&#x2F;ADINT.pdf" rel="nofollow">https:&#x2F;&#x2F;adint.cs.washington.edu&#x2F;ADINT.pdf</a>
jessaustinabout 7 years ago
ISTM that &quot;poz&quot; &quot;tribe&quot; is largely equivalent to a positive HIV status?<p>If they&#x27;re this sloppy when the client device is on one end of the connection, how sloppy are they once the data is on their end and we can&#x27;t see what they&#x27;re doing?
product50about 7 years ago
These are 3rd party analytics firms and not any random companies. Both these firms have strong data protection processes and are very secure. From Grindr&#x27;s perspective, they are probably looking for analytics for different segments of their users and send all data to Localytics who help them with this (vs. trying to build these internally).<p>Here is a thought. Do we think that the data is more secure with Grindr itself or with Localytics? I feel the answer might be the latter given data security means a lot to Localytics (as they provide analytics as a service to thousands of apps) vs. Grindr itself who may not go to the extent of Localytics to safefuard user info.
评论 #16737192 未加载
billmalarkyabout 7 years ago
It&#x27;s become clear over the last year there is a strong need for a data privacy regulatory agency in US government. I understand that regulation hampers growth, but the tech industry is mature and developed to the point that it&#x27;s time to reel in &quot;moving fast and breaking things&quot; a bit.
评论 #16736432 未加载
评论 #16736445 未加载
评论 #16737272 未加载
评论 #16736604 未加载
ransom1538about 7 years ago
Why wouldn&#x27;t HIV status be protected by HIPAA?
评论 #16736693 未加载
评论 #16737119 未加载
评论 #16736702 未加载
Redoubtsabout 7 years ago
They also scrape your clipboard aggressively...
评论 #16738418 未加载
dumbfounderabout 7 years ago
&quot;Grindr&#x27;s users may not be aware that they are sharing such data with them&quot;<p>I believe that to be an understatement!
ponderatulabout 7 years ago
I see they have some instructions there for how they did it. Any chance anyone could make a small instructive tutorial, so we can start replicating this process for other apps as well?<p>Then we can put everything in a giant repo and make it publicly accessible information.
GeneralTspoonabout 7 years ago
Looks like the repo got deleted. Can&#x27;t find an arhive.org version either.<p>According to a friend, an article he saw earlier also got pulled. Are Grindr attempting to do some damage control?
onewhonknocksabout 7 years ago
Image of the data structure.<p><a href="https:&#x2F;&#x2F;i.imgur.com&#x2F;hstbZio.png" rel="nofollow">https:&#x2F;&#x2F;i.imgur.com&#x2F;hstbZio.png</a>
asow92about 7 years ago
Does anyone actually find this surprising? It&#x27;s fairly normal to send user data to third party analytics providers. If you want to know which, check your terms of service.
gsichabout 7 years ago
&quot;shares&quot; sounds too friendly.
dangabout 7 years ago
Please don&#x27;t use allcaps for emphasis in HN comments. This is in the site guidelines: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;newsguidelines.html</a>.
评论 #16737350 未加载
jdelsmanabout 7 years ago
None of that data seems to be &quot;private&quot; according to Grindr&#x27;s privacy policy: <a href="https:&#x2F;&#x2F;www.grindr.com&#x2F;privacy-policy" rel="nofollow">https:&#x2F;&#x2F;www.grindr.com&#x2F;privacy-policy</a>
评论 #16738017 未加载
frgtpsswrdlameabout 7 years ago
So there&#x27;s lots of talk about how we&#x27;re going to regulate&#x2F;manage data protection going forward but what are we going to do about the stuff that is already out there? I mean HIV status is a pretty toxic thing to just be floating around. It doesn&#x27;t seem that we can even be sure who has this data and who doesn&#x27;t.