{"id":5855,"date":"2025-08-04T00:03:26","date_gmt":"2025-08-04T00:03:26","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/04\/weekly-update-463\/"},"modified":"2025-08-04T00:03:26","modified_gmt":"2025-08-04T00:03:26","slug":"weekly-update-463","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/04\/weekly-update-463\/","title":{"rendered":"Weekly Update 463"},"content":{"rendered":"<p>    Weekly Update 463<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/www.troyhunt.com\/content\/images\/2025\/08\/Splash-Template%401x_1.jpg?ssl=1\" alt=\"Weekly Update 463\"><\/p>\n<p>I&#8217;ve listened to a few industry podcasts discussing the Tea app breach since recording, and the thing that really struck me was the lack of discussion around the privacy implications of the service <em>before<\/em> the breach. Here was a tool where people were non-consensually uploading photos of others and leaving fairly intimate commentary about them. That MO seems to be, at least in part, related to the motive to take a service that presented massive privacy implications for the subject matters and, to vet their participants&#8217; gender, create an even bigger privacy issue by collecting selfies and IDs, which in turn created yet another privacy issue when they were leaked and misused. There were so many red flags about this service <em>before<\/em> the breach that it&#8217;s kinda fascinating the focus is now so heavily on the aftermath. A bit more pre-emptive focus on privacy next time, everyone.<\/p>\n<p><!--kg-card-begin: html--><\/p>\n<div>\n<div style=\"width: 170px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/itunes.apple.com\/au\/podcast\/troy-hunts-weekly-update-podcast\/id1176454699?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2018\/05\/Listen-on-Apple-Podcasts.svg\" alt=\"Weekly Update 463\"><\/a><\/div>\n<div style=\"width: 175px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/www.youtube.com\/playlist?list=PL7LAAxaabizMAXnJe0s3xjQ30q12EVmjt&amp;ref=troyhunt.com\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2024\/09\/Watch-and-Listen-on-YouTube.svg\" alt=\"Weekly Update 463\"><\/a><\/div>\n<div style=\"width: 118px; display: inline-block; margin-right: 3px;\"><a href=\"https:\/\/open.spotify.com\/show\/7jMtKFohdrw6qmz8AkLqit?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2019\/10\/spotify.svg\" class=\"kg-image\" alt=\"Weekly Update 463\"><\/a><\/div>\n<div style=\"width: 120px; display: inline-block;\"><a href=\"https:\/\/omny.fm\/shows\/troy-hunt-weekly-update\/playlists\/podcast.rss?ref=troy-hunt\"><img decoding=\"async\" src=\"https:\/\/www.troyhunt.com\/content\/images\/2018\/07\/Download-via-RSS.svg\" alt=\"Weekly Update 463\"><\/a><\/div>\n<p><iframe loading=\"lazy\" width=\"100%\" height=\"480\" src=\"https:\/\/www.youtube.com\/embed\/OPePBIQH0hs\" frameborder=\"0\" allow=\"autoplay; encrypted-media\" allowfullscreen><\/iframe>\n<\/div>\n<p><!--kg-card-end: html--><\/p>\n<h2 id=\"references\">References<\/h2>\n<ol>\n<li>\n<a href=\"https:\/\/report-uri.com\/?src=troyhunt.com&amp;ref=troyhunt.com\" rel=\"noopener\">Sponsored by:\u00a0Report URI: Guarding you from rogue JavaScript! Don\u2019t get pwned; get real-time alerts &amp; prevent breaches #SecureYourSite<\/a>legislation<\/li>\n<li>\n<a href=\"https:\/\/x.com\/troyhunt\/status\/1948858450492129476?ref=troyhunt.com\" rel=\"noreferrer\">The Tea app breach is many layers of privacy irresponsibility<\/a> (with some pretty alarming outcomes for users <em>and<\/em> victims of the service)<\/li>\n<li>\n<a href=\"https:\/\/pi-hole.net\/blog\/2025\/07\/30\/compromised-donor-emails-a-post-mortem\/?ref=troyhunt.com#page-content\" rel=\"noreferrer\">My favourite creator of network-level nasties blocking was compromised<\/a> (and it wasn&#8217;t even the Pi-hole&#8217;s fault, thanks to a dodgy WordPress plugin with an <em>egregiously<\/em> dumb flaw)<\/li>\n<li>\n<a href=\"https:\/\/x.com\/troyhunt\/status\/1948941790276436041?ref=troyhunt.com\" rel=\"noreferrer\">I was asked about the UK&#8217;s Online Safety Act during the live stream<\/a> (that&#8217;s a link to a thread which effectively amounts to it being more &#8220;thoughts and prayers&#8221; of infosec rather than practical legislation)<\/li>\n<\/ol>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Troy Hunt<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/www.troyhunt.com\/weekly-update-463\/\">Go to troyhunt<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Weekly Update 463 I&#8217;ve listened to a few industry podcasts discussing the Tea app breach since recording, and the thing that really struck me was the lack of discussion around the privacy implications of the service before the breach. Here was a tool where people were non-consensually uploading photos of others and leaving fairly intimate [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[51,135],"tags":[143,1644,148],"class_list":["post-5855","post","type-post","status-publish","format-standard","hentry","category-troyhunttroyhunt","category-weekly-update","tag-breach","tag-privacy","tag-was"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5855"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5855"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5855\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5855"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5855"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5855"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}