back to article App designed for safe sending of naughty selfies is rife with risks

A smartphone app touted as a safe way to exchange naked pictures and saucy texts poses a huge privacy risk. Snapchat is available for both iPhone and Android devices, and is marketed towards teenagers and young adults. The app lets senders control how long a message or picture can be viewed, before it expires after a maximum …

COMMENTS

This topic is closed for new posts.
  1. Justice
    Paris Hilton

    Wait... what?

    10 seconds???

    That's not even enough for my reciepients to work out exactly what's going on in the photo.

    :(

    Paris, because if you're a teenager dumb enough to have these kicking about you deserve everything coming to you.

  2. Anonymous Coward
    Anonymous Coward

    Nude photo and a 12+ rating seem rather contradictory. I can remember stories of when children in the US have sent pictures of themselves have been arrested and charged with publishing child porn. Does this mean the publisher of this app will be charged with aiding and abetting of the said crime?

  3. Anonymous Coward
    FAIL

    That there is a market for an app like this is somewhat depressing.

    Also nice to see old Clueless gets another soundbite in which to pass on his expertise in stating the bleeding obvious.

  4. Richard Wharram

    Seriously?

    What sort of group of people would set up a business specifically aiming to get nude pictures of teenagers?

    ===

    Dear authorites,

    I can reassure you that all photos will be deleted after 10 seconds.

    Yours faithfully,

    G Glitter,

    J Savile,

    Managing Directors.

    1. Anonymous Coward
      Anonymous Coward

      Yes...

      It is rather suspicious that it requires the following permissions:

      * Your location

      * Your personal information

      * Network communication

      * Your accounts (use the authentication credentials of an account)

      in addition to the expected

      * Storage

      * Hardware controls

      1. foo_bar_baz
        Boffin

        Re: Yes...

        Network communication isn't exactly suspicious for an application that sends and receives images and text over the network.

  5. Vladimir Plouzhnikov

    After 10 seconds

    The message expires and is forwarded to www.xgfsexposed.com for archiving...

  6. Anonymous Coward
    Anonymous Coward

    10 seconds?

    That's not long enough to masturbate, which is surely the major reason for the naughty pics?

    1. Anonymous Coward
      Anonymous Coward

      Re: 10 seconds?

      Speak for yourself. It's perfectly adequate.

      1. Anonymous Coward
        Anonymous Coward

        Re: 10 seconds?

        Well, if you only need 10 seconds I feel sorry for your girlfriend.

        1. Anonymous Coward
          Anonymous Coward

          Re: 10 seconds?

          "Well, if you only need 10 seconds I feel sorry for your girlfriend."

          What makes you think she's a lesbian?

      2. Anonymous Coward
        Anonymous Coward

        Re: 10 seconds?

        Twice!

  7. Anonymous Coward
    Anonymous Coward

    Marketed towards teenagers...

    Sounds like someone needs a raid from the anti-paedo police.

    1. Anonymous Coward
      Anonymous Coward

      Re: Marketed towards teenagers...

      Someone need to learn what words mean

      paedo = before puberty

      paedophile = someone who's sexual preferences are towards pre-pubescent children

      1. Crisp

        Re: Marketed towards teenagers...

        Don't tell him what an ephebophile is. You'll make his tiny brain explode.

        1. Michael Dunn

          Re: Marketed towards teenagers...

          Or hebephile!

  8. A J Stiles
    FAIL

    This is an old problem

    Back when I was just 8 years old, I invented a method of creating a "self-destructing message". This involved making a recording on a tape cassette; then, after rewinding it, carefully opening up the cassette housing and inserting a small piece broken from an old loudspeaker magnet in the path to the take-up spool, where the tape would rub over it. This made a cassette that was only listenable once: the very act of playback wiped out the content.

    However, there was a fatal flaw, as follows: There was no way to tell whether or not the EARphone socket of the playback machine was plugged into the AUXiliary input of another machine; so the technique was insecure against anyone who knew the trick (and had another cassette recorder).

    Summary: Any kind of "limited read" is inherently insecure, because you only ever need to be able to read something once to make a copy of it.

    1. Anonymous Coward
      Anonymous Coward

      Re: This is an old problem

      Still, not bad thinking for an eight year old!

  9. Anonymous Coward
    Anonymous Coward

    Potential lawsuit?

    Apple gave the app a 12+ rating and so effectively allowing 12 year olds to snap and send pics of themselves in the nude. At some point this image is then being uploaded and hosted on a server and then distributed to it's recipient , surely this is child porn?

    Wasn't it only a year ago that the owner of mega upload was arrested for distributing illegal content hosted on his servers.

    1. Anonymous Coward
      Anonymous Coward

      Re: Potential lawsuit?

      Yeah, if they limited it to 18+, then 14 year old girls wouldn't take pictures of themselves naked and all of our problems would be solved. Also, don't let them buy condoms and they won't have sex.

      1. Anonymous Coward
        Anonymous Coward

        Re: Potential lawsuit?

        Well yeah, but your missing the point completely and obviously never read the full comment before posting your response.

        The images are being uploaded to a server before being distributed to the end-user. The owners of these servers, even for 10 seconds are distributing questionable images of younger children. Even if the images were uploaded willingly by the user they are still illegal images.

        The same thing happened with mega upload. Its users were uploading illegal content and Kim dot-com was arrested for owning the servers which were distributing the material. Copyright infringement or child porn it's still illegal content.

    2. Anonymous Coward
      Anonymous Coward

      Re: Potential lawsuit?

      But 12-year-olds can already do those things with an iPhone out of the box, or any cell phone for that matter.

    3. foo_bar_baz
      FAIL

      Re: Potential lawsuit?

      All of that also applies to the built in Photobooth app, you bollard. Any 4 year old is capable of using it, and has no rating.

      - take pictures of self

      - upload, hosted on a server (could even be an Apple hosted mac.com account)

      - distribute to recipient (build in email app)

      http://en.wikipedia.org/wiki/Safe_harbor_%28law%29

  10. Rich 2 Silver badge
    WTF?

    Eh???

    "...it limits the opportunity for others to forward it around the school campus, or (worse) upload it to Facebook or an image sharing site."

    I know it's stating the bleedin' obvious, but I'll do it anyway. If you're worried about this sort of thing then ...errr ....don't text/email naked pics of yourself to other people? Just a thought.

    Oh, and shut that stable gate on your way out will you... oh shit! Too late!!!!!

  11. Anonymous Coward
    Anonymous Coward

    old advice?

    Whatever happened to the common sense advice: face *or* bits - it's either naughty or identifiable - never both.

    Deniability, people... deniability...

    1. Anonymous Coward
      Anonymous Coward

      Re: old advice?

      And remove the EXIF tags.

  12. Senior Ugli
    FAIL

    Parasite porn sites

    X-rated pics of head lice and the such

    1. Anonymous Coward
      Anonymous Coward

      re: lice

      it would not be head lice ...

  13. localzuk Silver badge

    Anyone checked their servers?

    Any chance that they could be intercepted/archived by someone unscrupulous?

    1. Anonymous Coward
      Anonymous Coward

      @localzuk

      Our servers are completely safe because they are guarded by anonymous people. And as we all know; anonymous people are the heroes of the modern Internet, so there's no way this can go wrong.

    2. Khaptain Silver badge
      Big Brother

      Re: Anyone checked their servers?

      I would be suprised to learn that the images were not being intercepted why else would they make such an app.

      <--- Big brother probably is watching

      1. Anonymous Coward
        Anonymous Coward

        >Big brother probably is watching

        s/watching/masturbating/

    3. Robert Helpmann??
      Childcatcher

      Re: Anyone checked their servers?

      See previous discussion concerning phones being raided for similar pics by service people. The hosting site will be one of the most targeted by hackers for the naughty pics and various governments for potential use by their opponents as a way to pass notes. It's the stuff of spy novels: self eating messages.

  14. Destroy All Monsters Silver badge
    Facepalm

    It's just a stupid file transfer app

    Comes with all the problems of file transfer.

    As for the people reflexively yelling "child porn" and "ratings" in here that are not doing so in a cynical way but are actually Pennsylvania-level pants-on-head retarded:

    1) Go down to the newspaper stand

    2) Grab one of them magazines on the upper shelves

    3) ???

    4) You are now feeling better

    Then reflect on how FTP can be used by your daughter/son to pump around nudies of themselves.

    1. sabroni Silver badge
      Facepalm

      Re: It's just a stupid file transfer app

      It's possible to share stuff on the internet in all kinds of ways. An app that facilitates something by making it incredibly easy to do is likely to increase the number of people doing it. Those who don't have the technical ability to use the more complex methods of sharing can still download an app and use it. How many teens would go through the steps needed to share pictures using ftp?

      It's an app with as age restriction of over 12 designed for sending images that you want to keep private. And by the sound of it the images sent are hosted on a server owned by the app publisher. That doesn't sound dodgy to you? You don't think that's any dodgier than any other ftp site?

  15. IR

    Want an endless supply of free porn? Make an app that encourages people to send naked photos of themselves to each other, and save all the sent photos.

    1. Anonymous Coward
      Anonymous Coward

      Not so much.

      The thing about nude beaches is that you (almost) never see the people you want to see naked.

      1. Anonymous Coward
        Anonymous Coward

        Chatroulette

        The dick:tits ratio is not what I would like it to be.

        1. sabroni Silver badge
          Thumb Up

          Re:The dick:tits ratio is not what I would like it to be

          Well you've come to the right place, we have both in abundance.

  16. Robert Carnegie Silver badge

    Granted this sounds like a disastrous idea,

    What about using this stuff for the pictures?

    http://en.wikipedia.org/wiki/Magic_Eye

    Remember that? Could you ever see what it was? I couldn't, but I have sight problems - not terrible but probably enough to make this sort of trick impossible for me. Anyway, to get a snapshot off -that- seems like probably more trouble than just hiding a camera with timer in your date's bathroom.

  17. quatra

    Naughty Selfies

    It escapes me why somebody would want to send "naughty" pics of him/herself, other than to "sell the goods" exhibited. As with any wares it's much better to go to the interested party in person, negotiate the price and, if wanted, offer a test drive.

  18. Dire Criti¢

    Just a bit of perspective.

    A naked picture of a 12+ child is not automatically pornographic, it's just a pic of a naked child, which, courtesy of the kneejerk reactionists, has been corrupted into being changed from the beautiful creation of nature that it is into something crude and debasing.

    However, the subsequent use to which the picture is put is what can change its original purpose to one of pornographic.

    And of course, the necessary point needs to be made because of said kneejerk reactionists, I only find women above forty to be sexually appealing in case anyone deems the above comments to be pro-child porn.

    1. John G Imrie

      A naked picture of a 12+ child is not automatically pornographic

      But can you tell just by looking at it. Or do you have to take it down to the local plod shop and ask for expert advice.

  19. Anonymous Coward
    Anonymous Coward

    I did some prying into the app's internals

    The photos are encrypted with a static AES key, and then transferred with https. The addition of AES adds no real security whatsoever, since the key is sitting there in the app binary waiting for anyone to grab it. However, I suppose since it's being encrypted by one user's phone then decrypted by the others, it's easier for the company to say they never had access to the photo data.

    If it used proper asymmetric key generation with public keys shared through the network, that would be a different story, but I wouldn't expect this kind of app to get something like that right.

    It took me maybe an hour or so but I was able to modify the application to save the received images after being decrypted but before they were even opened, so the other person does not even think you've opened the photo, but you have the photo sitting on your phone.

    I took a totally work-safe picture of me wearing clothes and smiling naturally, sent it to some user names I found after a google search or two, and my first response was sure enough some random girl and a picture of her boob, which was saved without her ever knowing. Having completed my proof of concept, I deleted the photo and the app from my device. As far as she can tell, I have never seen the photo.

    1. Spoddyhalfwit

      Re: I did some prying into the app's internals

      @ AC 1502

      "I took a totally work-safe picture of me wearing clothes and smiling naturally, sent it to some user names I found after a google search or two, and my first response was sure enough some random girl and a picture of her boob, which was saved without her ever knowing. Having completed my proof of concept, I deleted the photo and the app from my device"

      This reminds me of the old days on fleet street where are intrepid reports always "made his excuses and left" the message parlour. I never had any doubt in my mind that he had indeed done that - I respect fleet street journalists as people of integrity.

  20. Paul Hovnanian Silver badge

    Never mind kids ....

    <p> ... can we stop government officials from messaging naked pix of themselves back and forth?

  21. baker402

    Is there software parents can purchase to still see the photos? I know that PhoneSheriff will not capture 3rd party ap photos.

    Snapchat is a very dangerous ap and should be taken off the market for underage children. Age 21 and over only.

  22. kissingthecarpet
    Facepalm

    Only in America

    "I can remember stories of when children in the US have sent pictures of themselves have been arrested and charged with publishing child porn. "

    Law = Ass

This topic is closed for new posts.

Other stories you might like