Monday, 15 Dec 2025
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Twitter alternative Spoutible spouts a massive leak
Security

Twitter alternative Spoutible spouts a massive leak

Last updated: February 6, 2024 2:11 pm
Published February 6, 2024
Share
Authy is shutting down its desktop app
SHARE

Security consultant and Have I Been Pwned creator Troy Hunt has detailed a vulnerability in the API of Spoutible, a social platform that emerged following Elon Musk’s takeover of Twitter, that could allow hackers to take full control of users’ accounts.

After someone alerted Hunt to the vulnerability, he discovered that hackers could exploit Spoutible’s API to obtain a user’s name, username, and bio, along with their email, IP address, and phone number. Spoutible has since addressed the vulnerability, writing in a post on its site that it didn’t leak decrypted passwords or direct messages, while confirming the “information scraped included email addresses and some cell phone numbers.” It invited anyone who still wants to use the service back for a “special Pod session” at 1PM ET. Both Spoutible and Hunt recommend that users change their passwords and reset 2FA.

As mentioned by Hunt, this isn’t entirely uncommon, as seen in similar data-scraping incidents on platforms like Facebook and Trello.

However, Hunt discovered something much more alarming: bad actors could also use the exploit to obtain a hashed version of users’ passwords. While they were protected with bcrypt, short or weak passwords could be fairly easy to decipher, and the service blocked people from setting longer passwords that would be harder to crack.

And, to top it all off, Hunt found that the API returned the 2FA code used to sign in to someone’s account, as well as the reset tokens generated to help a user change a forgotten password. This could let hackers easily gain access to and hijack someone’s account without alerting them to the breach.

See also  AI, greed cause massive spike in memory prices

According to Hunt, the exploit exposed the emails of around 207,000 users. That’s nearly everyone on the whole platform, as a June 2023 report from Wired indicated Spoutible had 240,000 users.

Source link

TAGGED: alternative, leak, massive, Spoutible, spouts, Twitter
Share This Article
Twitter Email Copy Link Print
Previous Article Silicon wafer for manufacturing data center semiconductor The World’s Chip Industry Poised to Bounce Back After Tough 2023 | DCN
Next Article UK announces over £100M to support 'agile' AI regulation UK announces over £100M to support ‘agile’ AI regulation
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

JumpCloud Acquires Resmo

JumpCloud, a Louisville CO-based firm serving to IT groups and managed service suppliers, acquired Resmo,…

March 20, 2024

US examines security risks posed by China Telecom and China Mobile’s operations

The Biden administration is conducting a evaluation of China Cell, China Telecom, and China Unicom…

June 28, 2024

Prudentia Sciences Raises $7M in Funding

Prudentia Sciences, a Cambridge, MA-based supplier of an AI-powered expertise platform for all times sciences,…

January 13, 2025

EDB unveils EDB Postgres AI

Relational database supplier EnterpriseDB (EDB) on Thursday launched EDB Postgres AI, a brand new database geared toward transactional,…

May 28, 2024

How Certified SASE Solutions Build Trust and Resilience

Implementing a certified SASE solution improves interoperability and enables an enterprise to take advantage of…

February 6, 2024

You Might Also Like

Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble
Security

Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble

By saad
Immersion Cooling: Lagging Today, Leading Tomorrow
Security

Immersion Cooling: Lagging Today, Leading Tomorrow

By saad
Cloudflare Outage Blocks NJ Transit, ChatGPT Websites
Security

Cloudflare Outage Blocks NJ Transit, ChatGPT Websites

By saad
EU Considers Cracking Down on Big Tech's Cloud Power
Security

EU Considers Cracking Down on Big Tech’s Cloud Power

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.