"Tea" app - user database leaked today (incl. drivers license & IDs). Daily reminder not to give your ID to online services [THEY DO NOT PROTECT YOUR INFORMATION]
-
???? This is just textbook sso/openid but backed by the government. There's nothing intrinsically insecure about having third parties send you directly to a trusted government site for authorization.
And how does that prevent hacks that reveal the connection between ID and user account ?
-
Remember the UK new safety law.
https://techcrunch.com/2025/07/15/reddit-rolls-out-age-verification-in-the-uk-to-comply-with-new-rules/Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan
“DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!” the thread read before being deleted.
404 Media (www.404media.co)
Gives me no pleasure to add it to idcaboutprivacy
Free and open source—feel free to contribute.
-
And how does that prevent hacks that reveal the connection between ID and user account ?
What connection do you think a third party is saving when using openid? Generally speaking the only thing the third party needs is your identifier which in most cases is just an email. It's no more devastating for the user base for that information to be leaked than it is when they're handling authorization themselves. I personally think using a government backed authorization platform is a terrible idea and something completely liable to be abused by those in power, but it would objectively be better than trying to have every single service store your personally identifiable information themselves.
-
The drivers license thing is likely due to a law passed by the UK a few days ago requires all mature content to be behind an age check. And not a "Are you 18: Yes / No", more like "we will check using ID and photos of you".
It's the most hated piece of legislation in a while, with already 100 000 petition votes in 3 days to repeal it.
Oh yes the famous state of Colorado UK.
UK driving licences do not look like that, they don't have US states on them (major clue), are green, and if the person in the photo actually looks like a living human and not corpse, it gets sent back as unacceptable.
-
So like, when do we get a government-run service to issue zero-knowledge proofs about us so companies have no reason to store stuff like this in the first place?
Oh aye, I am the #1 government truster, they should "not record" where I visit and should be trusted to ignore my internet history
-
Found this article after a quick web search: https://www.forbes.com/sites/kateoflahertyuk/2025/07/24/what-is-tea-the-viral-women-only-app-with-1-million-downloads/
It's an app where women upload photos of men they're dating to get "the tea" on them (red flags, catfishing, etc.). I always wondered if something like this existed. Sucks that it has to, sucks even more if their users are being targeted like this.
The reason that up until now an app like that hasn't existed is because it is an absolutely awful idea if you spend more than 10 seconds thinking about it.
It's ripe for abuse in fact I would be surprised if even half of the reports are legitimate. Isn't absolutely god awful system and whoever thought this up is an absolute prat, who seriously needs to get outside and actually experience real life and real people.
-
The drivers license thing is likely due to a law passed by the UK a few days ago requires all mature content to be behind an age check. And not a "Are you 18: Yes / No", more like "we will check using ID and photos of you".
It's the most hated piece of legislation in a while, with already 100 000 petition votes in 3 days to repeal it.
Oh, so they started requiring that in the last couple days?
-
Women aren't routinely abusing men with dating apps so yeah I would be weirded out lmao
Jesus you definitely need to get out more.
-
Indeed, and the kicker is that 4% is on turnover, not profit. That can really hurt.
Yeah it has to be that way otherwise all these venture capital funded businesses that never actually make a profit could just do whatever they want, and considering that's basically every startup it would essentially neuter to the law.
-
Remember the UK new safety law.
https://techcrunch.com/2025/07/15/reddit-rolls-out-age-verification-in-the-uk-to-comply-with-new-rules/Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan
“DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!” the thread read before being deleted.
404 Media (www.404media.co)
Whoopsie.
What goes around comes around. -
Oh aye, I am the #1 government truster, they should "not record" where I visit and should be trusted to ignore my internet history
If I had to choose between a government and a private entity to store my personal governmental records (e.g. age and name), I'd 100% choose the government first.
-
None of the driver licenses shown in the screenshot are UK style.
No idea why they were collecting identification then.
Even worse, since the hackers got a bunch of the data at once, the company must have held onto those pictures long after they registered people to their service, which they likely didn't need to do.
-
Uh... What's the tea app?
Edit: from what I can gather based on the last link attached to this post it seems to be some kind of app for women to talk about men they've dated. Why that needs drivers license uploads is a whole other question and definitely should have raised some massive red flags for anyone thinking about using it.
The app required ID uploads ostensibly to verify that you were a woman signing up, men were not allowed to join for obvious reasons
-
"talk"
They try to get a pass on this by saying it's about "safety" and reporting creeps. But it's filled with women posting dudes and gossip. It gives me the same vibes as those sites back in the day that were shut down because they were essentially revenge porn sites. Same shit different form.
Yes, trying to warn other women about a man you dated who abused you or gave off weird vibes is definitely the same as getting your nudes or porn video of yourself leaked against your will onto the public internet for everyone to see
-
What's the alternative to warning strangers about predators?
As usual on Lemmy, the answer is just for women to shut up and listen to what the men want
-
If I had to choose between a government and a private entity to store my personal governmental records (e.g. age and name), I'd 100% choose the government first.
easy to say, but that depends entirely on the government and company doesn't it?
-
Gives me no pleasure to add it to idcaboutprivacy
Free and open source—feel free to contribute.
Nice site you got there! Made from scratch or using some service/app?
-
Remember the UK new safety law.
https://techcrunch.com/2025/07/15/reddit-rolls-out-age-verification-in-the-uk-to-comply-with-new-rules/Women Dating Safety App 'Tea' Breached, Users' IDs Posted to 4chan
“DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!” the thread read before being deleted.
404 Media (www.404media.co)
Friendly reminder that some services do need your ID otherwise they cannot help you or at least they need to very you (accountants, notaries, etc)
edit: I can´t do your tax report if I 1 don´t identify you and 2 I don't have the social security for which I need to do the report
-
Found this article after a quick web search: https://www.forbes.com/sites/kateoflahertyuk/2025/07/24/what-is-tea-the-viral-women-only-app-with-1-million-downloads/
It's an app where women upload photos of men they're dating to get "the tea" on them (red flags, catfishing, etc.). I always wondered if something like this existed. Sucks that it has to, sucks even more if their users are being targeted like this.
The original incarnation on Facebook got sued for posting libel and shut down. There's no judge of truth on these apps it's all she said and no he said.
-
easy to say, but that depends entirely on the government and company doesn't it?
Any government already has all of that information, so, no.
By giving it to a company, you just increase the risks of info leakage.