Company given security warning, months pass and bugs still linger

Dec 27, 2013 12:11 GMT  ·  By

Gibsonsec.org is reporting that Snapchat users are at high risk of having their phone number exposed and stolen because of a big security hole.

Apparently the security-focused group gave Snapchat the heads up about four months ago, trusting that the photography-centric social network will fix the bugs. As it turns out, they didn’t.

“Given that it's been around four months since our last Snapchat release, we figured we'd do a refresher on the latest version, and see which of the released exploits had been fixed (full disclosure: none of them),” writes Gibsonsec.

“Seeing that nothing had been really been improved upon (although, stories are using AES/CBC rather than AES/ECB, which is a start), we decided that it was in everyone's best interests for us to post a full disclosure of everything we've found in our past months of hacking the gibson,” the group adds.

Their post is fairly long, and all security-focused readers are encouraged to give it a read. The best advice at this point is probably just to avoid Snapchat altogether.