A public S3 bucket? Whoever used the app should start a class action lawsuit, this is beyond misconduct.
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
Imagine the other gaping security holes in this thing if storing all the data on a public s3 bucket flew under the radar until after release.
It was literally just a gossip site. Glad it got what it deserved, even if 4channers suck. The male version of this got shut down too.
Just curious, what was the male version?
Gossip sites suck, but nobody deserves to get their data leaked.
How do you think anyone who had their face and details posted by a vindictive ex feels? Yeah nobody does, but I feel less devestated when it was already happening from them against people.
4channer try not be bigoted for 1 nanosecond challenge (IMPOSSIBLE) (GONE SEXUAL)
Yeah there was absolutely no need to include unfounded racist shit about “DEI hires” but it seems to be some sort of rule in 4chan that you have to be a bigoted fucknut in order to post
Damn, if they had PII in a public bucket like that it’s criminally negligent. Well, at least it should be but I’m no lawyer
It's at least a hefty fine in the EU - enough to kill a business.
The higher of €20m or 4% of global annual turnover.
Indeed, and the kicker is that 4% is on turnover, not profit. That can really hurt.
Ah publicly exposed bucket. Tale as old as time.
Gives me no pleasure to add it to idcaboutprivacy
Free and open source—feel free to contribute.
Uh... What's the tea app?
Edit: from what I can gather based on the last link attached to this post it seems to be some kind of app for women to talk about men they've dated. Why that needs drivers license uploads is a whole other question and definitely should have raised some massive red flags for anyone thinking about using it.
"talk"
They try to get a pass on this by saying it's about "safety" and reporting creeps. But it's filled with women posting dudes and gossip. It gives me the same vibes as those sites back in the day that were shut down because they were essentially revenge porn sites. Same shit different form.
Found this article after a quick web search: https://www.forbes.com/sites/kateoflahertyuk/2025/07/24/what-is-tea-the-viral-women-only-app-with-1-million-downloads/
It's an app where women upload photos of men they're dating to get "the tea" on them (red flags, catfishing, etc.). I always wondered if something like this existed. Sucks that it has to, sucks even more if their users are being targeted like this.
The reason that up until now an app like that hasn't existed is because it is an absolutely awful idea if you spend more than 10 seconds thinking about it.
It's ripe for abuse in fact I would be surprised if even half of the reports are legitimate. Isn't absolutely god awful system and whoever thought this up is an absolute prat, who seriously needs to get outside and actually experience real life and real people.
Talk about adding to the toxic nature of the world. Anyone thinking we should have a digital record of social reputation isn't thinking it through.
The original incarnation on Facebook got sued for posting libel and shut down. There's no judge of truth on these apps it's all she said and no he said.
Sucks that it has to
It doesn't have to.
I understand the reasoning for the public intent of the app and would generally support it within reason cause society right now amirite.. but its not so subtle real world application has now leaked a DB of catty women for whom the majority ALSO show massive red flags. This isn't a sexist men vs women critique, if there was an app for men to rate women and dox them I'd feel the same way. Love it when shitty people bamboozle themselves.
I mean it's even in the app name that it's not about protecting women and keeping them safe, it's literally about "spilling the tea" aka gossip. It's pretty gross and can be used for nonconsenual sharing of images and even slander too since there's no way to know if what someone is writing on there about someone is true or not.
So like, when do we get a government-run service to issue zero-knowledge proofs about us so companies have no reason to store stuff like this in the first place?
Oh aye, I am the #1 government truster, they should "not record" where I visit and should be trusted to ignore my internet history
If I had to choose between a government and a private entity to store my personal governmental records (e.g. age and name), I'd 100% choose the government first.
They wouldn’t see what sites you give the tokens to — unless those sites choose to phone home, for some reason.
- You log in to the government site
- You ask for a token to prove your age/gender/whatever
- You copy the token
- You go to the age/gender-restricted site
- You provide the token
- The restricted site asks the government site how to verify any arbitrary token (but doesn’t mention your specific token)
- The restricted site verifies the token
I can't wait till I read a similar article about porn sites; especially one where the doxxed individuals are politicians.
I mean, we kinda already ended up there with the Ashley Madison hack in 2015. Problems with that site aside, I feel like it's kinda the blueprint for everything wrong with companies that retain personally identifable info on folks. If a company collects details like your driver's license, it's not a question of if it gets out but when. There's just no way to collect that sort of data and truly keep it safe.
But, it seems like we've kinda forgotten how to learn lessons in the modern day, so I'm sure this was an isolated issue and we'll never see it's like again.
(/s on that last part, just in case that wasn't blindingly obvious.)
Someone spilt the tea...
well isn't that just ironic
Friendly reminder that some services do need your ID otherwise they cannot help you or at least they need to very you (accountants, notaries, etc)
edit: I can´t do your tax report if I 1 don´t identify you and 2 I don't have the social security for which I need to do the report