Women’s ‘red flag’ app Tea is a privacy nightmare
-
Honestly it seems like a weapon that can too easily be used for defamation
I mean, yes, but does that take priority over women who are worried about their safety? There's been women doing this over local Facebook groups for a long time. Defamation of this sort is not a new issue.
-
It's a little more complex than that. If you want the app on the user device to be able to dump data directly into your online database, you have to give it access in some way. Encrypting the transmission doesn't do much if every app installation contains access credentials that can be extracted or sniffed.
Obviously there are ways around this too, but it's not just "use TLS".
Encrypting the transmission doesn't do much if every app installation contains access credentials that can be extracted or sniffed.
Encrypt the credentials then? Or OAUTH pipeline, perhaps? Automated temporary private key generation for each upload (that sounds unrealistic, to be fair)? Can credentialing be used for intermediary storage that encrypts the data on that server and then decrypted on the database host?
Clearly my utter "noobishness" is showing, but at least it's triggering a slight urge to casually peruse modern WebSec production workflows. I am a DNN researcher. Thus, I am far removed from customer-facing production environments, and it shows.
Any recommendations on literature or articles on how engineers solve these problems in a "best practices" way that you can recommend? I suppose I could just look it up, but I thought I'd ask.
Edit: I don't know why I'm down-voted. My questions were sincere.
-
Lots of men in this thread real upset about this app pointing out how the majority men are shit
It's an antisocial surveillance system for antisocial people, and creates a(n even more) antagonistic relationship between men and women.
Dating apps have been a disaster for dating, and this is perhaps the worst among them.
-
It's a little more complex than that. If you want the app on the user device to be able to dump data directly into your online database, you have to give it access in some way. Encrypting the transmission doesn't do much if every app installation contains access credentials that can be extracted or sniffed.
Obviously there are ways around this too, but it's not just "use TLS".
Wouldn't some sort of proxy in between the bucket and the client app solve this problem? I feel like you could even set up an endpoint on your backend that manages the upload. In other words, why is it necessary for the client app to connect directly with the bucket?
Maybe I'm not understanding the gist of the problem
-
Lots of men in this thread real upset about this app pointing out how the majority men are shit
Citation of course needed with that one.
The only people who will be listed on the app are people who are either deserving they've been on there or people who don't deserve to be on there but some woman in their lives has decided to inact some vengeance justified or otherwise.
-
Lots of men in this thread real upset about this app pointing out how the majority men are shit
What are you basing the majority of men are shit on? Confirmation bias?
-
I mean, yes, but does that take priority over women who are worried about their safety? There's been women doing this over local Facebook groups for a long time. Defamation of this sort is not a new issue.
It was defamation the entire time just because somebody made it an app rather than a Facebook group doesn't make any difference. It was always a crap thing to do.
Of course Tea took it to an entirely new level of stupid.
-
uh hello! ok? not sure what your fetishes have to do with the conversation that was taking place. maybe you're from the UK and you're missing porn?
But I wish you the best of luck in your search for whatever porn you like.
Weird, this app I have says its true that you like to have sex with dogs. It's encrypted and safe on my end, so it's totally fine!
-
it seems its an app that helps women flag potential dating candidates as being dangerous or red flags.
there is the potential for doxxing that comes with that, but I can absolutely understand its use and need when not abused in that manner.
i wonder if there's the potential for a different app with more encryption and a way to prevent doxxing and abuse.
i wonder if there's the potential for a different app with more encryption and a way to prevent doxxing and abuse.
You would have to have everyone take a polygraph or something (not that they actually work but a lot of people don't know that so maybe it would prevent them from lying in the first place). There's no way to prevent people from lying for whatever reason they have and there's no way to detect whether or not the thing they have posted is truthful.
The truth is as much benefit as the app may have when used properly the risk of abuse is far too high for it to ever be workable.
If you have a smoke alarm in your house that occasionally explodes and sets your house on fire, but the rest of the time actually works as a fire alarm, then it's not a useful product, as even if the chance of it exploding was less than 1% it would still eventually blow up your house, whereas if you never installed the alarm there was every possibility your house will never catch fire. So game theory suggests that you are better off without it.
Same with this app, sure it might prevent you experiencing a bad date but there's every possibility that it will also cause you not to date somebody who's actually a nice person. You are far better off just making that judgement yourself as you always did. And to be clear given human nature, the likelihood of the "fire alarm exploding" is probably a lot higher than 1%
-
It was defamation the entire time just because somebody made it an app rather than a Facebook group doesn't make any difference. It was always a crap thing to do.
Of course Tea took it to an entirely new level of stupid.
It was potentially defamation when it was just women...talking to one another, too. This seems like a pretty solid case of men looking at something women do to protect each other, and saying "...but what about the men who could be negatively affected in some cases?" I also think the tone in which this is being discussed is pretty revealing about Lemmy's demographics.
-
Weird, this app I have says its true that you like to have sex with dogs. It's encrypted and safe on my end, so it's totally fine!
mazel tov!
-
Defaming people without giving them a chance to defend themselves, talk about shit people...
But have you considered man bad?
-
Defaming people without giving them a chance to defend themselves, talk about shit people...
It's not defamation if it's true
-
What are you basing the majority of men are shit on? Confirmation bias?
Oh come on, you know how Those People are
-
I am not sure, but I read somewhere that the developer(s) used vibe coding to create the app so...
A lot of people have speculated that.
According to their statement their code was written in Feb/2024 and predates "vibe coding"
-
It's not defamation if it's true
And its legally actionable libel/slander if false.
-
It was potentially defamation when it was just women...talking to one another, too. This seems like a pretty solid case of men looking at something women do to protect each other, and saying "...but what about the men who could be negatively affected in some cases?" I also think the tone in which this is being discussed is pretty revealing about Lemmy's demographics.
Yeah, because only men are talking about this.
-
What are you basing the majority of men are shit on? Confirmation bias?
Well im a man. And most men i interact with are casually misandrist, ableist and homophobic. I can't imagine they behave any better when they're trying to fuck you
-
Lots of men in this thread real upset about this app pointing out how the majority men are shit
Lots of misandrists in this thread framing security failures as sexism against men
-
This post did not contain any content.
Lots of misandrists in this thread framing security failures as sexism against men
-
-
-
AI Utopia, AI Apocalypse, and AI Reality: If we can’t build an equitable, sustainable society on our own, it’s pointless to hope that a machine that can’t think straight will do it for us.
Technology1
-
Oculus founder Palmer Luckey leads group of tech billionaires launching new crypto-bank — aims to fill the void left by Silicon Valley Bank's 2023 collapse
Technology1
-
-
A fake Facebook event disguised as a math problem has been one of its top posts for 6 months
Technology1
-
-