TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Snapchat Security Advisory

1 点作者 leef超过 11 年前

1 comment

leef超过 11 年前
Highlights:<p>* They encrypt all snaps with the same encryption key (AES in ECB mode). The key is embedded in the app and is the same key on iOS and android.<p>* They have an API that, given a phone number, will return a users snapchat handle and name if the phone is valid. This is a batch API with no limit. The security firm was able to successfully send a request with 75k phone numbers.<p>Not mentioned in the post is that snapchat appears to run over HTTP and sends an auth token. Anyone listening to traffic should be able to grab that auth token as well.