Snapchat Photo Leak Exposes Flawed Premise, Security Challenge

Advertisement
By Reuters | Updated: 15 October 2014 09:20 IST
The prospect of tens of thousands of potentially racy Snapchat photos hitting the Internet has driven home a simple fact: the mobile app's core feature - delivering photos and videos that vanish seconds after viewing - is flawed.

The negative publicity surrounding that speculation has spurred criticism about its lax security. But whether this will affect the valuation of the 3-year-old Silicon Valley start-up as it seeks another round of funding remains to be seen.

A range of venture capitalists and tech insiders say they believe it will not, for now. One person close to the company's fundraising efforts who asked not to be named said Snapchat is still expecting a $10 billion valuation in the current funding round, one of the startup industry's richest and the same level being considered by investors before news of the breach surfaced last week.

"Once a company is hot, investors will be keen to continue investing unless the issue seems to be life-threatening," said Anand Sanwal, chief executive of venture capital consultancy CB Insights.

Advertisement

The brouhaha has not yet hurt the popularity of Snapchat among teenagers, partly because no mass publication of leaked photos has materialized. The messaging service remained among the five most-downloaded photo and video apps over the weekend, according to analytics service App Annie.

Advertisement

The issue arose last week when hacker forums claimed unknown parties had created a file holding at least 100,000 stolen Snapchat photos, including many of minors, that could end up being posted online. The anticipated event, dubbed "the snappening," was widely reported, including by Reuters.

While Snapchat said its servers were not breached, it confirmed that rogue third-party apps have been storing its users' pictures. That points to a longer-term challenge for the Los Angeles company: its inability to fully block the external parties it blames for undermining its business.

Advertisement

The snappening
Even before any talk of "the snappening," security experts were faulting Snapchat for what they call a cavalier approach toward privacy, which may have given users a false sense of comfort.

The third-party apps, which allow users to enter their Snapchat password and log-in information, connect to the main service and provide unauthorized features such as image-saving.

Advertisement

Such software can be pernicious since the people whose pictures are stored are often unaware of the privacy breach by the downloaders of the third-party apps.

Snapchat does not allow other apps to interact with its service, but many developers manage to break the rules. The company says it monitors for such "illegal" apps and has succeeded in removing some culprits from Google and Apple app stores.

One website, Snapsaved.com, claimed on Monday on its Facebook page that its servers had been hacked and that intruders had accessed its trove of Snapshot photos.

"Any application that isn't ours but claims to offer Snapchat services violates our Terms of Use and can't be trusted," Snapchat warned in a Tuesday blogpost.

But Snapchat should have been able to detect multiple requests for information originating from external services, or to detect when users were alternately logging on from different apps, cybersecurity experts said.

In addition, Snapchat used very elementary encryption to protect photos and videos on its service, said Chris Wysopal, chief technology officer of Veracode, a firm specializing in testing apps for security vulnerabilities.

Instead of requiring two separate cryptographic keys to access images transmitted across Snapchat, the service relied on a single universal key that unlocked everything, "the bare minimum," he said.

"Someone who knew what they were doing, probably in a few hours could reverse-engineer it, find the key and write a program to decrypt the photos as they go over the network."

In May, Snapchat settled charges with U.S. regulators accusing it of deceiving customers by promising that photos on its service disappeared forever. The U.S. Federal Trade Commission also faulted Snapchat for storing unencrypted videos on users' phones, which could be accessed by connecting the device to a personal computer.

Still, even the best security measures could leave Snapchat playing an unwinnable cat-and-mouse game with hackers.

At a very basic level, Snapchat cannot stop anyone from taking a photo of a photo. Anyone who receives a Snapchat image on the phone can use another camera to capture the screen picture, said Michael Coates, director of product security at Shape Security.

Still, Snapchat may have little to worry in the near term, at least on the valuation front, industry insiders say.

David Cowan, a partner at Bessemer Venture Partners, which has not invested in Snapchat but has backed other consumer startups like dating service Zoosk and online bulletin board Pinterest, said Snapchat has little to worry about.

"These types of breaches will definitely stop people from using Snapchat," Cowan said, "until they have a really cool picture to share."

© Thomson Reuters 2014

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Realme 15T 5G India Launch Today: All You Need to Know
  3. Razer Pro Click V2 and V2 Vertical Review
  4. Su From So OTT Release Date is Here! Know all the Details
  5. YouTube Reportedly Cracks Down on Premium Family Plan Sharing
  6. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  7. Apple Marks iPhone 8 Plus as Vintage Alongside These MacBook Models
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.