时间:2026-03-02 06:45:46 来源:网络整理编辑:綜合
Next time you make a payment on Venmo, beware: almost anyone can track it.The popular mobile payment
Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
TopicsCybersecurityPrivacy
Dog elected for third term as mayor of Minnesota town2026-03-02 06:36
韓喬生:10年後國足必定能湊齊11個會踢球的本土球員2026-03-02 06:31
馬凡舒上熱搜 :中國足球上不了春晚 足球主持人可以先上2026-03-02 06:12
水慶霞:希望球員們不斷增加自信 對陣日本享受比賽2026-03-02 06:08
Tyler, the Creator helped Frank Ocean celebrate 'Blonde' release in a delicious way2026-03-02 05:44
全力爭勝!國足對陣越南大概率推出攻擊型戰陣2026-03-02 05:19
奧巴梅揚滿麵笑容離開巴薩 拉波爾塔興奮到直揮拳2026-03-02 05:09
官方 :熱刺將恩東貝萊租借至裏昂 可5400萬鎊買斷2026-03-02 04:19
U.S. pole vaulter skids to a halt for national anthem2026-03-02 04:19
央視:越南足球裏程碑比賽 國足不幸成為背景板2026-03-02 04:02
Michael Phelps says goodbye to the pool with Olympic gold2026-03-02 06:32
官方 :熱刺中場阿裏加盟埃弗頓 潛在轉會費1200萬2026-03-02 06:28
利雅得新月官宣前申花外援加盟 聯賽已轟12球領跑射手榜2026-03-02 06:04
範誌毅神預言成真:中國足球臉都不要了 再下去要輸越南了2026-03-02 06:03
Samsung Galaxy Note7 teardown reveals the magic behind the phone's iris scanner2026-03-02 05:55
蘭帕德同意成為埃弗頓新帥 周一將官宣簽約兩年半2026-03-02 05:50
利物浦隊史紀錄 :新援並列第五 紅箭四俠皆不如他2026-03-02 05:18
國米官宣租借33歲老槍凱塞多 小因紮吉迎心腹愛將2026-03-02 04:42
Two astronauts just installed a new parking spot on the International Space Station2026-03-02 04:35
官方:本坦庫爾加盟熱刺簽至2026 轉會費1900萬歐2026-03-02 04:08