Tantan, a close replica of Tinder, has vowed to improve its encryption after it was revealed the site had little to no protection against moderately competent hackers.

CEO and co-founder Yu Wang admitted in an email response that the lack of protection protocols was a โ€œbad ideaโ€ and that they are seeking to fix the problems as soon as possible. The vulnerabilities were exposed in a report last Friday by Hong Kong-based entrepreneur Larry Salibra, who founded his own crowdsourced site-testing service.

Mr. Salibra claimed the site was โ€œendangering young women and men by failing to use encryptionโ€, drawing a comparison to the recent Ashley Madison hack which exposed thousands of personal data points.

Tantanโ€™s CEO reached out to Mr. Salibra directly via email to respond to the allegations, saying that the company is now โ€œworking on releasing a version that fixes these two issues within the week,โ€ though he claimed that the comparison with Ashley Madisonโ€™s breach was not accurate.

Among the vulnerabilities the report showed that sensitive data including personal telephone numbers and passwords were left unencrypted by Tantan. Other information including gender, sexual orientation, interests and hobbies were also left exposed through various means.

By viewing Tantanโ€™s exposed console log though Appleโ€™s developer kit Xcode, potential hackers are able to see a host of information about the app which is typically โ€œturned offโ€ in other apps to increase performance and protect sensitive information.

The report also revealed that Tantan had been using a list of โ€˜rude wordsโ€™ to chide users who used certain phrases, such as colloquialisms for โ€œletโ€™s meet for sexโ€ and โ€œsend nudes.โ€

China has a booming market of apps designed to facilitate romantic encounters, some with better reputations than others. Tantan is one of a handful of services that has an interface almost identical to Tinder. The latest breach reignites concerns surrounding the security of the many social apps flooding China-focussed app stores.

The country has seen a spate of high-level hacks and malware threats over the past year. In September a handful of the countryโ€™s most popular apps, including Didi, WeChat and NetEase Music, were infected with malware due to a tainted version of Appleโ€™s developer kit.

Tantanโ€™s most recent funding round was in February this year, when they raised $5 million USD led by Bertelsmann Asia Investments.

Cate is a tech writer. She worked as a journalist in Australia, Mongolia and Myanmar. You can reach her (in Chinese or English) at: @catecadell or catecadell@ovau.ip-ddns.com

Leave a comment

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.