Jack'd, a gay dating app with 1M+ downloads from the Play store, stored users' images, posted and marked as private in chat sessions, on an unsecured AWS server
Sean Gallagher / Ars Technica : Tweets: @hexadecim8 Tweets: H E X A / @hexadecim8 : If you're building dating apps, you have to get the security right. There's no excuse for getting the security so wrong & stubbornly not fixing the issues when a reporter has gone above and beyond to disclose, and even offered to kill the story if it gets fixed. Irresponsible. http://twitter.com/...
Context & Ripple Effects
Researcher Sean Gallagher's disclosure via Ars Technica lands in a dating-app security arc that already included Tinder's encryption failures, and it ends with consequences: Jack'd's parent company later settled the complaint over private photos sitting on a public server for over a year.
What makes this report stand out is the refusal loop — the reporter disclosed responsibly, offered to hold the story if the flaw was fixed, and the company left the unsecured AWS bucket up anyway, turning a fixable misconfiguration into a published exposure for an app serving a vulnerable user base.
First-order effects
- Users who marked chat images as private on Jack'd had those photos readable by anyone who found the bucket — an immediate privacy harm weighted by the sensitivity of sexual-orientation data.
- Jack'd's parent company moves from quiet bug to public incident, facing disclosure pressure it already declined once when given the chance to fix it pre-publication.
Second-order effects
- Regulators treat the outcome as precedent material: the complaint over the year-long exposure ends in a settlement, raising the cost of ignoring responsible disclosure for every dating app operator.
- Rivals must audit their own cloud storage defaults, because the same misconfiguration pattern recurs across the category — from livestreaming platform CAM4's exposed records to messaging apps leaving private media open.
Third-order effects
- If the pattern holds — Jack'd, then CAM4, then Go SMS Pro, then JusTalk — basic cloud-storage misconfiguration looks less like isolated error and more like a structural gap in how consumer apps handle intimate media, inviting regulatory scrutiny of sensitive-data categories specifically.
- For AWS and other cloud providers, repeated customer breaches of this kind build the case for secure-by-default object storage rather than leaving access controls entirely to app developers.
The trend: Consumer apps holding users' most intimate media keep failing at elementary cloud configuration, turning private-photo exposure into a recurring structural risk that regulators increasingly answer with settlements.