/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Researchers show Tinder's lack of encryption lets hackers see all photos, inject their own images in users' photo streams, and watch users' every swipe

Andy Greenberg / Wired :

Wired Andy Greenberg

Context & Ripple Effects

This disclosure lands at the end of a two-year run of dating-app security research. Researchers had already shown they could pinpoint Grindr users via a colluding trilateration attack in 2016, then pulled real names, locations, and login details from Tinder and Ok Cupid that October. The new work goes further: with no encryption between app and servers, an attacker on the same network can see every photo, inject images into a user's stream, and log every swipe.

The stakes are behavioral, not just personal — swipe patterns are the core signal Tinder monetizes through products like Smart Photos, which reorders profile photos based on user interest. Match Group subsequently confirmed the fix, saying swipes and images are now encrypted and swipe payloads no longer leak their size.

First-order effects

  • Users on shared or untrusted networks were directly exposed: attackers could view all their photos, plant images in their streams, and record their swipe activity in real time.
  • Match was forced into an immediate engineering response, encrypting traffic between the Tinder app and its servers and padding swipe data so its size no longer reveals behavior.

Second-order effects

  • The fix follows the same researcher-pressure cycle as the earlier Tinder and Ok Cupid credential exposures, signaling that every major dating app now needs its transport layer audited, not just its API endpoints.
  • Competitors inherit the scrutiny: each new finding against one platform raises the bar for the whole category, since researchers treat these apps as a class rather than one-off targets.

Third-order effects

  • If the pattern holds, security becomes a competitive requirement for dating apps rather than a back-office concern — platforms will need to harden encryption and location handling proactively before researchers or regulators force the issue, especially given how much sensitive behavioral and location data these services concentrate.

The trend: Dating apps are being pushed from feature-led growth toward security hardening, as successive researcher disclosures turn swipe and location data from product assets into liabilities.

Discussion

  • Checkmarx Dafna Zahger on x
    Are You on Tinder? Someone May Be Watching You Swipe
  • @astepanovich Amie Stepanovich on x
    Anyone with Tinder should get ready to play my fav game: delete the app http://twitter.com/...
  • @manan @manan on x
    Tinder has 0 respect for privacy. It's the 1 app that forces you to give them ALL Facebook data to even have an active account. This makes it worse. Bumble, Hinge, CMB are not Facebook data hoarders http://www.techmeme.com/...