TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

We found critical vulnerabilities in Hive Social

219 pointsby pantalaimonover 2 years ago

16 comments

lehiover 2 years ago
Hive is a My First App project from a teen who taught herself to code in 2019 (<a href="https:&#x2F;&#x2F;www.hivesocial.app&#x2F;about-us" rel="nofollow">https:&#x2F;&#x2F;www.hivesocial.app&#x2F;about-us</a>).<p>Caveat emptor.
评论 #33811802 未加载
linksbroover 2 years ago
Hive just shut down their entire app: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;TheHIVE_Social&#x2F;status&#x2F;1598119071907991552" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;TheHIVE_Social&#x2F;status&#x2F;159811907190799155...</a>
评论 #33815538 未加载
评论 #33813324 未加载
评论 #33812768 未加载
drunkenmagicianover 2 years ago
4 days from reporting to public posting is not a responsible disclosure policy. Even if they are slow in responding, the usual grace period is about 4 weeks if I recall.
评论 #33811193 未加载
评论 #33810721 未加载
评论 #33811260 未加载
评论 #33811048 未加载
jacooperover 2 years ago
I wanted Mastodon to replace Twitter so we can finally see a mainstream Federated social media, to break free of corporate control over social expressions.<p>But with the Hive there is nothing unique, its a Twitter clone, which doesn&#x27;t offer any technical or operational benefits, and also no major features.<p>if we are still going to use a centralized network, might as well just continue using Twitter, a network with an existing social circle.
评论 #33814345 未加载
评论 #33812074 未加载
csande17over 2 years ago
Critical security vulnerability in an iOS-exclusive app? I bet they&#x27;re using CloudKit and forgot to implement server-side access control. (Even Apple screws that up half the time: <a href="https:&#x2F;&#x2F;labs.detectify.com&#x2F;2021&#x2F;09&#x2F;13&#x2F;hacking-cloudkit-how-i-accidentally-deleted-your-apple-shortcuts&#x2F;" rel="nofollow">https:&#x2F;&#x2F;labs.detectify.com&#x2F;2021&#x2F;09&#x2F;13&#x2F;hacking-cloudkit-how-i...</a>)
spindleover 2 years ago
summary quotes:<p>&gt; The issues we reported allow any attacker to access all data, including private posts, private messages, shared media and even deleted direct messages. This also includes private email addresses and phone numbers entered during login.<p>&gt; Attackers can also overwrite data such as posts owned by other users
评论 #33811598 未加载
rurclipedover 2 years ago
At least one other person reported Hive Social vulnerabilities recently: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;zhuowei&#x2F;status&#x2F;1597739467645030400" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;zhuowei&#x2F;status&#x2F;1597739467645030400</a>
culanuchachamimover 2 years ago
Slightly off topic:<p>In the video of the post you can see an option of run a script in an iPhone.<p>What&#x27;s that option? It&#x27;s really an iPhone? What are the capabilities of that functionality?
评论 #33811675 未加载
评论 #33811672 未加载
leohover 2 years ago
Don’t worry, I won’t.<p>Snark aside, I think the current platforms are going to be the only ones folks use; and then there’s going to be stuff that is entirely different.<p>These clones are getting just silly.
dncornholioover 2 years ago
Wouldn&#x27;t be surprised if it was just replacing a post ID in the update call to someone else&#x27;s post and server thinks it&#x27;s fine. Anyone investigated yet?<p>[edit] Just read they took the server down, we will never know now.<p>[edit2] Astonishing how supportive the users are. I don&#x27;t think a lot of users want to understand that all their data is on the streets. It&#x27;s like they&#x27;re actually deciding in what they want to believe. Seems to be a trend in society.
bagelsover 2 years ago
They couldn&#x27;t have given them even a week before disclosing? Seems more black hat than white hat to do the disclosure this way (resulted in the app getting taken down).
评论 #33812957 未加载
StanislavPetrovover 2 years ago
Just want to point out that Hive Social is completely unrelated to Hive Blog (which is also a social network of sorts on the Hive blockchain).<p><a href="https:&#x2F;&#x2F;hive.blog&#x2F;" rel="nofollow">https:&#x2F;&#x2F;hive.blog&#x2F;</a>
评论 #33810958 未加载
评论 #33813948 未加载
评论 #33812911 未加载
bevenkyover 2 years ago
Would love to see insights on how <a href="https:&#x2F;&#x2F;www.kooapp.com&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.kooapp.com&#x2F;</a> is?
评论 #33813130 未加载
mudream4869over 2 years ago
TLDR: Mastodon is more secure than Hive Social.
评论 #33816390 未加载
评论 #33811872 未加载
ThePowerOfFuetover 2 years ago
Did you really have to add one of the internet&#x27;s most-hated songs to your screen recording like it was some cheap TikTok?
评论 #33812466 未加载
Holidayloginover 2 years ago
It would helpful if the reporter confirmed that this is an issue with this particular front-end and not with Hive in general.<p>Steem&#x2F;Hive was the first web3 offering and a lot of new &#x27;web3&#x27; projects that are getting a lot of publicity have yet to catch up the basics that Steem&#x2F;Hive had in place 6 years ago.
评论 #33811064 未加载
评论 #33811074 未加载