Clubhouse says it has added security safeguards and banned a user after some Clubhouse audio and metadata was found on a third-party website
- The app's creators had been warned user data was vulnerable — An unidentified user streamed audio chats to their own website
Bloomberg
Context & Ripple Effects
Clubhouse had already responded to researchers’ data-privacy concerns by seeking to stop clients from sending pings to Chinese servers. The third-party hosting of audio and metadata turns that earlier concern into a concrete access-control incident.
Clubhouse is tightening safeguards around its service and has removed the unidentified user who streamed chats to an outside website.
People participating in Clubhouse rooms face an immediate loss of confidence that conversations and associated metadata stay inside the app.
Second-order effects
Clubhouse’s safeguards will be judged against the privacy practices later documented for stored room audio and non-deletable account data, rather than as an isolated response to one user.
The outside posting of Clubhouse profile data keeps pressure on Clubhouse to distinguish publicly accessible profile information from data exposed through a breach.
Third-order effects
The episode points to live-audio platforms treating client and access controls as core privacy infrastructure, because moderation actions after an external stream do not by themselves restore the expectation of room confidentiality.
The trend: Social audio’s growth is making data handling, client access, and participant expectations of privacy inseparable product and security concerns.
Some Chinese developer made an Android / PC compatible player for Clubhouse, put it on GitHub, and this guy is like “Clubhouse has been hacked & it's coming out of China.” Then he goes on Clubhouse chatrooms to “verify this hack.” https://twitter.com/...
Seeing reports that “Clubhouse has been hacked.” Looks like there is a bot that's entering & recording public CH rooms in order to retransmit the audio to non-users. That violates CH's policies and is ethically questionable, but I wouldn't call it “hacking the app.”
Conversations on Clubhouse are being recorded as described by this report from Stanford cyber teams and proven tonight via a web page showing the audio and people involved (aka meta data) https://cyber.fsi.stanford.edu/ ...
Someone built a webpage rerouting audio data from public Clubhouse rooms This is exactly what I don't hope to see (but it's a matter of time) Even if the intent of that webpage is to bring CH to non-iOS users, without a safeguard, it could be abused
There is a mistaken assumption by some people that Clubhouse audio can't be recorded. It's just an app with an internal API, anyone can reverse engineer it and interact with the service with their own client. Even if not, Ted Cruz's group chats leaked. Any participant can leak. h…
Wow , I love how this gets spun heavy on the Sinophobia and not on how security and accessibility for ephemeral audio is poor. And tends to be kept poor when they see “content” as Black https://twitter.com/...
Not hacked. It's a client. And to be clear you can record clubhouse conversations on iOS. Did anyone presume that rooms were private conversations? I don't think so. Is this bad if you were anti-government in an authoritarian regime having unfettered conversations? Maybe. https:/…
I've also seen people speculating that the Chinese government (which banned CH) is behind this, since the bot is hosted in Hong Kong. That strikes me as completely absurd. If anything, the bot would be a way of circumventing Chinese censorship of CH.