Check Point Research CPR recently analyzed several popular dating applications with over 10 million downloads combined in order to understand how safe they are for users. As dating apps traditionally utilize geolocation data, offering the opportunity to connect with people nearby, this convenience feature often comes at a cost. CPR discovered that the Hornet dating app radius sends precise coordinates to the server. Nevertheless, they claim to protect user locations by randomizing the distance displayed in the application, making it, in their opinion, impossible to determine the dating app radius location. However, this is not the case. At the time of our research, the measures taken by Hornet were insufficient to dating app radius user coordinates, allowing for the determination of user locations with very high accuracy. Following the responsible disclosure process, we attempted to contact the Hornet team, providing them with the results of our research. Just before this publication, we reexamined the Hornet application. Since the specified responsible disclosure deadlines have passed, we are publishing the results of our research. This information can range from very precise location details such as a specific address or location coordinates derived through GPS Global Positioning System to less precise location data obtained via IP address, Wi-Fi, cellular networks, or Bluetooth beacons. Geolocation technology, while beneficial, presents several risks, especially when it comes to privacy and security within apps. These include potential privacy breaches from unauthorized data access, unintended sharing of location data with third-party entities, risks of tracking and surveillance, and security vulnerabilities like location spoofing. This information could be exploited by stalkers, burglars, or other malicious actors. In Hornet and similar applications, users in the search results are sorted in ascending order of distance. If we find two users in the search results who allow the display of their distance, and the target user is located between them in the search results, we can determine the approximate distance to the target user as an average value of two known distances:. Figure 1 — Estimating the approximate distance to the user based on known distances to neighbors. However, the presence of users near the target is not a necessary condition. To determine the distance to the user, it is required to register an additional account, the coordinates of which can be controlled. You can determine the distance between two users by iteratively dividing the range in half and positioning an additional account at the midpoint. By analyzing the search results and refining the search based on the presence dating app radius the target user, progressively narrowing down the distance between the target and the additional account, we can achieve the desired precision. Figure 2 — Technique for determining the distance to the user using the positioning of an auxiliary account. We used two-step trilateration: first, we performed trilateration using two reference points to obtain two possible candidate locations intersection points of the circles. Then, we used the distance information from the third reference point to select the correct solution. For example, this could be a small town. Around this area, we randomly generated 30 sets of reference points in a ring with an inner radius of 5 km and an outer radius of 10 km. As a result of trilateration for each group of reference points, we obtained a set of possible coordinates for the target point. The maximum error in geolocation was meters, and the minimum was only 2 meters. We calculated the mean value of latitude and longitude for all points. The distance between the mean value and the target point appeared to be 24 meters. Being able to determine the approximate location, we generated reference points at a distance of 1 to 2 kilometers around the region where the target was supposed to be located. Applying our method, we obtained many estimates of the target location. The geolocation errors were distributed almost uniformly, with a minimum of 1. We also calculated the average latitude and longitude for the results. The resulting average point was less than 5 meters away from the target point:. Figure 3 — The dating app radius location estimate has an error of less than 5 meters. By repeating the experiment many times for different target points, we consistently obtained location accuracy within 10 meters. When it comes to dating applications, exposing user geolocation poses significant risks to privacy. Our experiments revealed potential vulnerabilities in the Hornet dating application, which has over 10 million downloads.
These include potential privacy breaches from unauthorized data access, unintended sharing of location data with third-party entities, risks of tracking and surveillance, and security vulnerabilities like location spoofing. Bei uns hast du richtig gute Dates und findest den Menschen, der zu DIR passt. Bin super begeistert. Tinder, OkCupid oder doch lieber Bumble? For example, this could be a small town.
Key Findings
Tinder: Die (fast) beliebteste Dating-App. Freu dich auf spannende Profile, gute Gespräche und Dates, die im Kopf bleiben. ElitePartner ist die App für Dating mit Niveau. Lovetastic shows you users of the desired age, radius and gender who are searching for your gender. Wir prüfen jedes Profil und. Discover verified profiles live in m radius - Decide when and for whom you are visible - Send pings to chat and reveal more profile details. • Swipe through users or press the heart, cross, Power.Jetzt App herunterladen und verlieben. Der Preis für dich bleibt dabei unverändert. The geolocation errors were distributed almost uniformly, with a minimum of 1. Your preferences. Obviously, we need to store profile pictures, texts, and messages to display your profiles and chats. Bin super begeistert. In short: a whole lot comes together. In Hornet and similar applications, users in the search results are sorted in ascending order of distance. ElitePartner ist die App für Dating mit Niveau. Wie bei den anderen Apps, die wir euch vorstellen, ist die Basisversion kostenlos nutzbar. DE EN. Anna is a doctor. Trustbased matching — in contrast to algorithms, your friends have only your interest in mind! Figure 3 — The final location estimate has an error of less than 5 meters. Allerdings will Badoo nicht nur eine Dating-, sondern auch eine Social-Media-App sein. Learn More. Sprachen Deutsch. By disabling location services, users can prevent apps from tracking their whereabouts and gathering information about their movements. Being a matchmaker is sooo much fun Mandarina von Nonsense Freunde und mehr durch Freunde kennenlernen - super Idee, weiter so : Liv Ich habe die app durch eine freundin empfohlen bekommen. There you have the possibility to exchange pictures. Das gefällt dir vielleicht auch. Betrügerische Matches aus Afrika oder Asien gibt es hier nicht! Website des Entwicklers App-Support Datenschutzrichtlinie. You can also add your voice to your profile. It's great to have you as a part of Lovetastic. Executive Summary: Since September, Check Point Research CPR has been Allerdings birgt Online-Dating auch Gefahren wie Ghosting oder Love Bombing. So he manages for maximum efficiency and constantly interrupts with new ideas. Contact us at info lovetastic.