时间:2026-01-08 06:32:53 来源:网络整理编辑:綜合
Next time you make a payment on Venmo, beware: almost anyone can track it.The popular mobile payment
Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
TopicsCybersecurityPrivacy
Honda's all2026-01-08 06:21
音樂旅行電影《極淨之路》殺青 “來,是為了更好的回去”2026-01-08 05:39
《追光吧!》四大工作室微電影致敬無名英雄 ,全情演繹平凡中的偉大2026-01-08 05:29
易烊千璽又一作品官宣,大年初一兩部作品上線,累計票房衝破百億2026-01-08 05:24
This app is giving streaming TV news a second try2026-01-08 05:04
新版《畫皮》上映 ,古樸有趣 ,不失為一部還原聊齋味道的電影2026-01-08 04:52
某音蹭易烊千璽電影小紅花的熱度 ,不但沒有令人反感,反而很開心2026-01-08 04:50
《獵狐行動》定檔2021,梁朝偉、段奕宏首次同框飆演技2026-01-08 04:38
Donald Trump's tangled web of Russian influence2026-01-08 04:27
電影《破局錦衣衛》橫店開機2026-01-08 04:13
This chart shows just how high Simone Biles can jump2026-01-08 06:01
《全世界唯一的你》心動開機 奇幻愛情治愈都市男女2026-01-08 05:58
《真假美猴王之大聖無雙》 定檔12月5日,吳孟達攜新老西遊人驚喜上線 !2026-01-08 05:43
宋曉峰自導自演《讓我過過癮》 ,智盛聯合瞄準喜劇賽道2026-01-08 05:42
U.S. government issues warning on McDonald's recalled wearable devices2026-01-08 05:38
電影《幸運電梯》定檔1.15,幾大看點提前揭秘2026-01-08 05:04
賈玲導演新片玩穿越,還找來沈騰張小斐,網友 :海報一看就像過年2026-01-08 04:56
《真假美猴王之大聖無雙》 定檔12月5日,吳孟達攜新老西遊人驚喜上線!2026-01-08 04:49
Snapchat is about to explode in popularity, report says2026-01-08 04:45
聊齋新傳畫皮人熱映 演員周宇鵬雨戲張力十足2026-01-08 04:31