Sunday, 1 Mar 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Security > Twitter alternative Spoutible spouts a massive leak
Security

Twitter alternative Spoutible spouts a massive leak

Last updated: February 6, 2024 2:11 pm
Published February 6, 2024
Share
Authy is shutting down its desktop app
SHARE

Security consultant and Have I Been Pwned creator Troy Hunt has detailed a vulnerability in the API of Spoutible, a social platform that emerged following Elon Musk’s takeover of Twitter, that could allow hackers to take full control of users’ accounts.

After someone alerted Hunt to the vulnerability, he discovered that hackers could exploit Spoutible’s API to obtain a user’s name, username, and bio, along with their email, IP address, and phone number. Spoutible has since addressed the vulnerability, writing in a post on its site that it didn’t leak decrypted passwords or direct messages, while confirming the “information scraped included email addresses and some cell phone numbers.” It invited anyone who still wants to use the service back for a “special Pod session” at 1PM ET. Both Spoutible and Hunt recommend that users change their passwords and reset 2FA.

As mentioned by Hunt, this isn’t entirely uncommon, as seen in similar data-scraping incidents on platforms like Facebook and Trello.

However, Hunt discovered something much more alarming: bad actors could also use the exploit to obtain a hashed version of users’ passwords. While they were protected with bcrypt, short or weak passwords could be fairly easy to decipher, and the service blocked people from setting longer passwords that would be harder to crack.

And, to top it all off, Hunt found that the API returned the 2FA code used to sign in to someone’s account, as well as the reset tokens generated to help a user change a forgotten password. This could let hackers easily gain access to and hijack someone’s account without alerting them to the breach.

See also  Apex Legends postpones competition amid hacking concerns

According to Hunt, the exploit exposed the emails of around 207,000 users. That’s nearly everyone on the whole platform, as a June 2023 report from Wired indicated Spoutible had 240,000 users.

Source link

TAGGED: alternative, leak, massive, Spoutible, spouts, Twitter
Share This Article
Twitter Email Copy Link Print
Previous Article Silicon wafer for manufacturing data center semiconductor The World’s Chip Industry Poised to Bounce Back After Tough 2023 | DCN
Next Article UK announces over £100M to support 'agile' AI regulation UK announces over £100M to support ‘agile’ AI regulation
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Meta will train AI models using EU user data

Meta has confirmed plans to utilise content material shared by its grownup customers within the…

April 15, 2025

Data Center World Conference and Expo

The Fall 2012 Knowledge Heart World Convention is slated for September 30 - October 3…

June 1, 2024

Lenovo unveils Truscale Hybrid Cloud for edge to empower data-driven workloads

Lenovo has unveiled the availability of Truscale Hybrid Cloud for edge. The company says the…

February 8, 2024

Province Receives Strategic Capital Investment From Trivest Partners

Province, a Las Vegas, NV-based restructuring and monetary advisory agency, acquired a strategic capital funding…

July 19, 2024

Runway debuts AI video generation API for developers

Be a part of our day by day and weekly newsletters for the newest updates…

September 17, 2024

You Might Also Like

AI (Artificial Intelligence) technology, chip IC on PCB, PCB circuit board, microprocessor
Global Market

AMD strikes massive AI chip deal with Meta

By saad
Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble
Security

Nvidia’s Upbeat Forecast Soothes Fears of AI Bubble

By saad
Immersion Cooling: Lagging Today, Leading Tomorrow
Security

Immersion Cooling: Lagging Today, Leading Tomorrow

By saad
Cloudflare Outage Blocks NJ Transit, ChatGPT Websites
Security

Cloudflare Outage Blocks NJ Transit, ChatGPT Websites

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.