/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Jack'd, a gay dating app with 1M+ downloads from the Play store, stored users' images, posted and marked as private in chat sessions, on an unsecured AWS server

Sean Gallagher / Ars Technica : Tweets: @hexadecim8 Tweets: H E X A / @hexadecim8 : If you're building dating apps, you have to get the security right. There's no excuse for getting the security so wrong & stubbornly not fixing the issues when a reporter has gone above and beyond to disclose, and even offered to kill the story if it gets fixed. Irresponsible. http://twitter.com/...

Ars Technica Sean Gallagher

Context & Ripple Effects

Researcher Sean Gallagher's disclosure via Ars Technica lands in a dating-app security arc that already included Tinder's encryption failures, and it ends with consequences: Jack'd's parent company later settled the complaint over private photos sitting on a public server for over a year.

What makes this report stand out is the refusal loop — the reporter disclosed responsibly, offered to hold the story if the flaw was fixed, and the company left the unsecured AWS bucket up anyway, turning a fixable misconfiguration into a published exposure for an app serving a vulnerable user base.

First-order effects

  • Users who marked chat images as private on Jack'd had those photos readable by anyone who found the bucket — an immediate privacy harm weighted by the sensitivity of sexual-orientation data.
  • Jack'd's parent company moves from quiet bug to public incident, facing disclosure pressure it already declined once when given the chance to fix it pre-publication.

Second-order effects

  • Regulators treat the outcome as precedent material: the complaint over the year-long exposure ends in a settlement, raising the cost of ignoring responsible disclosure for every dating app operator.
  • Rivals must audit their own cloud storage defaults, because the same misconfiguration pattern recurs across the category — from livestreaming platform CAM4's exposed records to messaging apps leaving private media open.

Third-order effects

  • If the pattern holds — Jack'd, then CAM4, then Go SMS Pro, then JusTalk — basic cloud-storage misconfiguration looks less like isolated error and more like a structural gap in how consumer apps handle intimate media, inviting regulatory scrutiny of sensitive-data categories specifically.
  • For AWS and other cloud providers, repeated customer breaches of this kind build the case for secure-by-default object storage rather than leaving access controls entirely to app developers.

The trend: Consumer apps holding users' most intimate media keep failing at elementary cloud configuration, turning private-photo exposure into a recurring structural risk that regulators increasingly answer with settlements.