时间:2026-03-29 13:58:09 来源:网络整理编辑:綜合
Next time you make a payment on Venmo, beware: almost anyone can track it.The popular mobile payment
Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
TopicsCybersecurityPrivacy
Watch MTV's Video Music Awards 2016 livestream2026-03-29 13:34
梅西專訪 :和C羅競爭感覺很棒 但我隻想超越自己2026-03-29 13:26
曼聯VS水晶宮首發:C羅B費領銜 桑喬拉師傅出戰2026-03-29 13:10
哈維輕敵迎首敗 !雪藏4大主力 為下周全力死磕拜仁2026-03-29 12:46
Man stumbles upon his phone background in real life2026-03-29 12:38
不配金球 ?萊萬榜首大戰梅開二度 2021年已攻入66球2026-03-29 12:36
防線告急 !切爾西單場狂丟3球 踢出賽季最差一戰2026-03-29 12:33
英媒盤點孫興慜豪車:法拉利賓利路虎 總價150萬鎊2026-03-29 12:06
This German startup wants to be your bank (without being a bank)2026-03-29 12:05
羅馬VS國米首發 :哲科先發戰舊主 巴雷拉恰球王登場2026-03-29 11:50
Dramatic photo captures nun texting friends after Italy earthquake2026-03-29 13:01
穆帥怒噴:裁判表現很好 羅馬是意甲最沒紀律的球隊2026-03-29 12:59
曼聯VS水晶宮首發:C羅B費領銜 桑喬拉師傅出戰2026-03-29 12:42
情商 !姆巴佩談自己偶像 :C羅梅西內少齊祖都是2026-03-29 12:37
One of the most controversial power struggles in media comes to a close2026-03-29 12:37
穆帥怒噴:裁判表現很好 羅馬是意甲最沒紀律的球隊2026-03-29 12:36
武磊第三次進大名單未出場 西甲293分鍾0球0助攻2026-03-29 12:17
4日賠率:拜仁戰多特或丟分 英超BIG3均高奏凱歌2026-03-29 12:05
Despite IOC ban, Rio crowds get their political messages across2026-03-29 11:53
人生贏家!《法國足球》曬梅西全家與七座金球合影2026-03-29 11:53