TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Yo App Allegedly Hacked By College Students

55 pointsby intullalmost 11 years ago

12 comments

DigitalSeaalmost 11 years ago
The Yo joke keeps on getting funnier. First 1.2 million dollars of funding for an app that allows you to send, &quot;yo&quot; to your friends and now this hack. What the hell was the money spent on? It certainly wasn&#x27;t security. I&#x27;d imagine the developers threw a massive party with kegs and thousands of pizzas with the funding money because lets be honest: Yo is an MVP product that is not refined nor innovative and could be built by a 14 year old with a Udemy course on Objective-C. The fact it supposedly took 8 hours to build and started off as an April Fools Day joke says it all, right?<p>I like stupid apps and things like this, but the fact this received funding just reminds me of 1999. Apps like this shouldn&#x27;t take funding, they&#x27;re short-lived hype apps, they&#x27;re not the next Twitter or Facebook. Can the bubble just pop already please? Save the VC funding for startup ideas that actually deserve it. This is the pet rock of mobile apps.<p>At least Mike Judge has a plot he can adopt for season two of Silicon Valley though.
评论 #7920365 未加载
评论 #7920297 未加载
评论 #7920275 未加载
评论 #7920593 未加载
评论 #7920363 未加载
评论 #7920336 未加载
评论 #7920267 未加载
评论 #7920371 未加载
评论 #7923325 未加载
评论 #7920298 未加载
Spearchuckeralmost 11 years ago
I have little sympathy for Yo - it&#x27;s indicative of the cavalier (arrogant?) attitude many seem to have towards security these days. There&#x27;s this prevalent minimum viable product attitude lately that seems to make app developers think security is something you can think about later.<p>It isn&#x27;t. You have an obligation to your users and the personal data they entrust you with. Build it in. Today. And know that you can&#x27;t write secure code as part of an agile process. Security means sitting down and working out a threat model before you jump into code, user needs and backlogs. In other words, choose design up front, or have a contingency ready because you&#x27;re going to get hacked.
评论 #7920406 未加载
评论 #7920285 未加载
paul9290almost 11 years ago
Great marketing, everyone is talking about the app now. Just heard it on the FM radio.<p>The title of the article even hints to this be marketing.. &quot;allegedly.&quot;<p>I don&#x27;t believe much of anything I see on the Internet. I think you shouldn&#x27;t either!
评论 #7920548 未加载
评论 #7920348 未加载
sillysaurus3almost 11 years ago
Is it wise to advertise that you&#x27;ve hacked any app in this social climate?<p>Theoretically, could the founder of Yo have pressed charges against the student? (This would, of course, be complete suicide for any startup. But companies aren&#x27;t always rational actors.)
评论 #7920119 未加载
评论 #7920131 未加载
isaiahturneralmost 11 years ago
I came here to talk a little about Yo. I was one of the original people to &quot;hack&quot; the app and updated the message to say &quot;Tweet #YoBeenHacked&quot; at about 3AM EST on June 20th. This is the hashtag that has sense been used. Approximately 15 minutes after doing this, I received a call from Or, the founder and CEO of Yo. Or, Chris, and I talked for about an hour and fixed a few issues then. From that point on, the message could not be updated.<p>The issues with Yo were not entirely Or&#x27;s fault. As he put it, the app was intended as a &quot;prototype&quot; and had it not blown up so fast, this would not have been an issue. A common claim is &quot;You have 1 million dollars, hire someone to fix this!&quot; which Or had already done. A meeting with the parse team had already been scheduled long before today and had everyone tried to hack the app today, the attempts would fail. During this meeting Parse&#x27;s Security team, Or and I fixed the security issues. I would be happy to answer any other questions, post below.<p>During the conversation Chris and I were both offered freelance jobs. Chris declined, I accepted. I currently am working on a feature for Yo to update your username.
评论 #7923868 未加载
评论 #7923812 未加载
评论 #7923813 未加载
jyzalmost 11 years ago
Georgia tech alum here. Whoever did this, I may have a job offer for you! Awesome!
uptownalmost 11 years ago
And suddenly &#x27;Yo&#x27; has a path to monetization ... litigation!
irfanalmost 11 years ago
The app uses parse.com API for all communication (and probably for all data storage) and I haven&#x27;t seen it communicating with anything other than parse, getsentry and flurry services.<p>Does hacking the app means hacking parse.com?
评论 #7920292 未加载
评论 #7920218 未加载
ulfwalmost 11 years ago
Those students have done a better jop than the original app developers and deserve a million dollar more than funding for a &#x27;Yo&#x27; app. Please. Let&#x27;s be serious.
jacquesmalmost 11 years ago
App now sends &#x27;Ya!&#x27;.
评论 #7920239 未加载
jwheeler79almost 11 years ago
&#x27;bringing on a specialist security team&#x27; (i.e. better programmers who know what the fuck theyre doing)
mantraxCalmost 11 years ago
Quick! Give those students one million dollars in VC funding!<p>Just think about it. We have more and more flash-in-the-pan shoddily written apps in mobile.<p>And because they&#x27;re flash-in-the-pan, for a time, they&#x27;re popular. And because they&#x27;re shoddily written, they&#x27;re easily exploited at the peak of their popularity, so you can amass a ton of personal information from the app users and abuse it any way you want.<p>Hacking crappy mobile apps may soon become the new &quot;my WordPress blog got hacked&quot;. Think of the potential, it can be a whole new industry. Not to mention all the fake diplomas, mortgages, Russian brides and Cialis pills that&#x27;ll get sold in there.