Slashdot Mirror


Snapchat Update Addresses Security Hole

Snapchat has released an update to address the security problems exposed recently by Gibson Security and subsequently (and quickly) exploited. From the article: "Snapchat also said researchers could email the firm at security@snapchat.com for any vulnerability discoveries. 'We want to make sure that security experts can get a hold of us when they discover new ways to abuse our service so that we can respond quickly to address those concerns. The best way to let us know about security vulnerabilities is by emailing us: security@snapchat.com,' Snapchat said."

10 of 58 comments (clear)

  1. Big lesson by Anonymous Coward · · Score: 5, Informative

    Pity that it took such a brutal action by GRC to change this companies point of view.

    1. Re: Big lesson by Anonymous Coward · · Score: 4, Funny

      They should have taken the $3 billion when they had the chance. These aren't real business people, they're techies who are holding on to a hot property. They need to know when to let the professionals start running things so they can turn it into a viable company.

    2. Re: Big lesson by DarkOx · · Score: 3, Insightful

      You mean the business people who usually buy these "tech firms" for a billions and sell them a few years later for millions as is the usually pattern, those business people?

      --
      Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
    3. Re: Big lesson by MrBingoBoingo · · Score: 2

      Well, the big problem here is how his CEOness handled the aftermath. This everything is everyone else's fault mentality he has is going to keep him from ever getting that three billion dollars. I mean when asked if it would kill him to take one iota of responsibility he answered "Yes".

  2. NSA email by Anonymous Coward · · Score: 5, Funny

    To: security@snapchat.com
    From: NSAops@langly.gov

    Subject: Latest Snapchat security update

    We were using that you bastards!

    1. Re:NSA email by TheP4st · · Score: 2

      Isn't it 'Langley'?

      As far as I know it's neither. Langley, Virginia is where the CIA HQ are located while NSA have their HQ in Fort Meade, Maryland.

      --
      "I have downloaded hundreds and hundreds of records, why would I care if somebody downloads ours?" Robin Pecknold
  3. Caveat by StikyPad · · Score: 5, Funny

    ...adding that emails sent to that address would be deleted after 10 seconds.

  4. Still one of the stupidest things of 2013. by Anonymous Coward · · Score: 4, Insightful

    Turning down 3 billion. Just months before a giant security leak that makes gobs of people leave their service...

    Could have all been sitting on a beach somewhere warm and toasty reading about someone elses giant security problem while counting their 3 billion and laughing with relief that they got out and got rich when they did...

    Something tells me they won't be getting another offer in the billions.

    1. Re:Still one of the stupidest things of 2013. by cbhacking · · Score: 5, Insightful

      Don't be too sure of that. Purchasers routinely hire security experts to review the security of major acquisitions prior to the buy-out, with various stipulations in the agreement as to what types of findings will be the responsibility of which party. Such a review would likely have found the issue before it was announced publicly.

      So few companies are smart enough to bring in security experts *before* they need them.

      --
      There's no place I could be, since I've found Serenity...
  5. Re:Too bad its news... by Desler · · Score: 2

    I'm not angry. Also, only doing anything after being exploited is not a correct response. Especially after handwaving the issue away by claiming the attack was only theoretical.