back to article Sarahah anonymous feedback app told: 'You're riddled with web app flaws'

The web-based version of anonymous feedback app Sarahah is riddled with security flaws, according to a researcher. Sarahah is a well established mobile app that allows people to receive anonymous feedback messages from friends and co-workers. Flaws in the technology make it vulnerable to web-based attacks including cross-site …

  1. John Smith 19 Gold badge
    Unhappy

    Hmmm. Let me see if I can write the firms reply.

    "We take the privacy and security of our customers/users/data sources very seriously and are studying the information we have been provided. We expect a patch shortly."

    Time will tell what, if anything they actually do.

  2. Warm Braw

    Flaws in the technology

    The fundamental flaw would seem to be the concept. Complaining about the implementation is rather like saying the blood tends to pool awkwardly at the bottom of the Iron Maiden.

    1. Zippy's Sausage Factory
      Pint

      Re: Flaws in the technology

      Or that beer tends to pool stickily at the bottom of the bar at an Iron Maiden concert...

  3. David Roberts
    Trollface

    We contacted our developer

    Jus the one, then?

    1. Anonymous Coward
      Anonymous Coward

      Re: We contacted our developer

      Just waiting for the timezone to catch up for a response.

  4. David Roberts
    Windows

    While I'm here - Sarahah?

    These names, why?

    1st attempt I saw Sahara.

    Now Sara_hah? Sarah_ah? Sa_rah_hah?

    Too old to be down with the kidz.

    1. Mark 78

      Re: While I'm here - Sarahah?

      I believe they use the word sarahah as it is Arabic for Honesty.

      1. Anonymous Coward
        Anonymous Coward

        Not very honest themselves

        “But the app is collecting more than just feedback messages. When launched for the first time, it immediately harvests and uploads all phone numbers and email addresses in your address book.”

        https://theintercept.com/2017/08/27/hit-app-sarahah-quietly-uploads-your-address-book/

        1. John Smith 19 Gold badge
          Joke

          "immediately harvests..uploads all phone numbers..email addresses in your address book.”

          Many other applications are available.

    2. Robert Carnegie Silver badge

      Re: While I'm here - Sarahah?

      They are privacy focussed so you cannot get in touch with them.

      In the bible, Abraham was told by an angel of God that he and his wife would bear children. They were in their nineties and she laughed so hard that her false teeth came out. Then she said, "Wasn't me", but it was, so God changed her name to Sarahah.

      Some of this actually is in the bible, some I made up.

    3. Cirieno
      Boffin

      Re: While I'm here - Sarahah?

      Sontar-hah! Sontar-hah!

  5. Wiltshire

    Ha Ha Ras !

  6. Bob Dole (tm)
    Coat

    Filing under D for Dumb

    The only way this could be better is if they do an IPO on a $2B valuation. Then to combat all of the horrible things people post they'll build an AI bot to send nice things to people.

    Call it the Stuart Smalley bot... Wait, I think I need to go write a business plan.

  7. sloshnmosh

    I have seen an ugly pattern on Google's play store, the higher number of (supposed) downloads the higher the amount of advertising SDK's, analytic engines and permission abuses.

    Nefarious developers pay ratings farms or offer rewards through App Bounty for people to rate their apps to give the impression of it being popular.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like