Skip to content

Women’s ‘red flag’ app Tea is a privacy nightmare

Technology
127 61 1.5k
  • off the top of my head, I don't know. i just feel the concept is intriguing and that the idea is a nice one.

    just the abuse potential is far too high I suppose. but it would be nice to know if someone had stalked someone else, may have spoken or behaved in a violent manner, etc.

    but I suppose at that point you might as well fingerprint and process any potential suitors lol. 😅

    the sentiment is great, however.

    I am going to say with even the downsides I think the idea is worth it.

    My friend sucks to her creeps and maybe she could have saved herself from at least two abused cases.

    Maybe like light system based around how often and how a users submits. This person submits a lot of negative responses red light.
    This person submits rarely green light?

    The problem is also how much data do we really want to keep? How little can we keep?

  • How would you implement the app in its current concept, without the possibility for abuse? It seems inherent to the very idea of it.

    Meowmeowbeans social pressure where people will refuse to meet or associate with people who have not been vetted and verified by meowmeowbeans members. So people who want to meet meowmeowbeans users would have to join to get screened otherwise they can get lost.

    Solves the issue of people who never signed up to the social media site having strangers uploading personal photos, videos, names, and stories to a profile page they never consented to. Which is reminiscent of doxing in its current state.

    So meowmeowbeans certification among consenting members would be the better route to go and socially making those not in meowmeowbeans outcasts. At least there is choice now for people to not be part of the community driven database of people.

  • Tea was storing its users’ sensitive information on Firebase, a Google-owned backend cloud storage and computing service.

    Every time. With startups, it's always an unsecured Firebase or S3 bucket.

    I'm certainly no web security expert, but shouldn't Tea's junior network/backend/security developers, let alone seniors, know how to secure said Firebase or S3 buckets with STARTTLS or SSL certificates? Shouldn't a company like this have some sort of compliance department?

  • Yeah, this app sucks for a variety of reasons, but holy shit the misogyny in this thread.

    Thanks for looking out for us. However, I, too, am a bit concerned. This is how Facebook started. The tech industry has zero ethics. I recommend women, AND men, have a trusted safety buddy when dating. When I met my spouse, I had two people who knew where I was, the person's name, photo, employer, and where we were meeting.Do some internet stalking. If I don't call you in an hour, come looking for me. If I call, I might ask for another hour, but you get the point.

  • I'm certainly no web security expert, but shouldn't Tea's junior network/backend/security developers, let alone seniors, know how to secure said Firebase or S3 buckets with STARTTLS or SSL certificates? Shouldn't a company like this have some sort of compliance department?

    I am not sure, but I read somewhere that the developer(s) used vibe coding to create the app so...

  • These alleged high standards women hold are largely imaginary. It's only kind of like that on dating apps, and that's because they're 80% male, so women HAVE to be picky.

    I agree. High standards and common ideas of "right" are generally present among people insecure and easily gaslighted.

    Such as those that would use this app. Point?

  • Honestly it seems like a weapon that can too easily be used for defamation

    How dare you!
    The misogyny!

  • Wow just two days ago I see a post about how Lemmy is dominated by men and how that could become a problem, and today I see a comment section where all the incels come out of the woodwork.

    "waaa somebody wants to solve a problem that has never affected me I'm the victim"

    "omg what if people talk behind my back they might find out I'm an asshole? literally 1984"

    "wadabout if this app was racist?!? checkmate"

    I'm not saying this app is good or bad (I can definitely see the problems) but if an article about cybersecurity gets posted and this is our first reaction, makes me lose hope in Lemmy.

    Edit: Responses have made very good points and I think I was off, thanks guys. I still think some of the early comments I encountered were rather reactionary

    “waaa somebody wants to solve a problem that has never affected me I’m the victim”

    Everyone has the problem that they'd want to discuss others behind their back. It's not accepted because it doesn't work to any good end.

    “omg what if people talk behind my back they might find out I’m an asshole? literally 1984”

    You won't find out anything from this. People sometimes lie, especially in such situations.

    but if an article about cybersecurity gets posted and this is our first reaction, makes me lose hope in Lemmy.

    Human adequacy is a big part of cybersecurity.

  • it seems its an app that helps women flag potential dating candidates as being dangerous or red flags.

    there is the potential for doxxing that comes with that, but I can absolutely understand its use and need when not abused in that manner.

    i wonder if there's the potential for a different app with more encryption and a way to prevent doxxing and abuse.

    i wonder if there’s the potential for a different app with more encryption and a way to prevent doxxing and abuse.

    Encryption, sure.
    Preventing doxxing? I highly doubt it. But hey, it's women doing it so it's ok and anyone who criticizes that is an incel.

  • Wow just two days ago I see a post about how Lemmy is dominated by men and how that could become a problem, and today I see a comment section where all the incels come out of the woodwork.

    "waaa somebody wants to solve a problem that has never affected me I'm the victim"

    "omg what if people talk behind my back they might find out I'm an asshole? literally 1984"

    "wadabout if this app was racist?!? checkmate"

    I'm not saying this app is good or bad (I can definitely see the problems) but if an article about cybersecurity gets posted and this is our first reaction, makes me lose hope in Lemmy.

    Edit: Responses have made very good points and I think I was off, thanks guys. I still think some of the early comments I encountered were rather reactionary

    i mean...an app directly copying a black mirror episode (but almost exclusively targeting a specific demographic) does ring some very, VERY loud alarm bells...

    like, this is literally the plot of nosedive.

    it's a social credit system.

    and none of the people even know they HAVE a score, so it's somehow even worse than the fictional scenario.

    this will, absolutely, hurt innocents and it will do so by design.

    "fuck them innocents!"...just because they happen to be men?

    how is that anything other than misandrist?

    how is that defensible?

    how is doxxing, mass libel, and targeted harassment a solution to sexism and rape culture?

    I'd be really interested in hearing anything about how this is supposed to help women, because i struggle to see how sowing massive, unearned distrust between men and women is going to make anyone any safer...

    I'm really, REALLY glad that the GDPR would nuke this sort of nonsense from orbit...uploading pictures of strangers, for the explicit purpose of gossiping about them behind their backs, spreading awful rumors?

    what. the. actual. fuck. is wrong with you people?

    and i don't mean women, or men: i mean americans and their total disregard for privacy and digital safety. what the hell...

  • There's definitely a use case, but there's an inherent power imbalance to these products that makes sure they will always be misused. The submitters are anonymous, and it's up to the person being reported on to prove the accusations are false.

    Or, they're supposed to be anonymous.

    it’s up to the person being reported on to prove the accusations are false.

    The person doesn't even know they're mentioned in the app.

  • Wow just two days ago I see a post about how Lemmy is dominated by men and how that could become a problem, and today I see a comment section where all the incels come out of the woodwork.

    "waaa somebody wants to solve a problem that has never affected me I'm the victim"

    "omg what if people talk behind my back they might find out I'm an asshole? literally 1984"

    "wadabout if this app was racist?!? checkmate"

    I'm not saying this app is good or bad (I can definitely see the problems) but if an article about cybersecurity gets posted and this is our first reaction, makes me lose hope in Lemmy.

    Edit: Responses have made very good points and I think I was off, thanks guys. I still think some of the early comments I encountered were rather reactionary

    You make a valid point, this platform absolutely shits on anyone without technical knowledge, just look at the hundred or so smug replies telling you what flavor of Linux they run if you mention a problem with Windows. So, no surprise everyone is focusing on that, and not the human aspect here.

    Having said that, there is a power imbalance to this that I really don't like, the accuser gets to hide behind a veil of anonymity, and the accused has their name published, and is forced to defend themselves.

  • it’s up to the person being reported on to prove the accusations are false.

    The person doesn't even know they're mentioned in the app.

    Which is even worse, because unless someone tells them, they're blissfully unaware.

    With most forms of Libel, at least the victim will see it in a timely manner.

  • You make a valid point, this platform absolutely shits on anyone without technical knowledge, just look at the hundred or so smug replies telling you what flavor of Linux they run if you mention a problem with Windows. So, no surprise everyone is focusing on that, and not the human aspect here.

    Having said that, there is a power imbalance to this that I really don't like, the accuser gets to hide behind a veil of anonymity, and the accused has their name published, and is forced to defend themselves.

    So, no surprise everyone is focusing on that, and not the human aspect here.

    This is a technology community and the article is specifically about a security breach that exposed massive amounts of sensitive user data.

  • Change the target to any other group and the outrage would be 100-10000 fold bigger.

    Try it out, instead of Women rating men, try subbing in various minority groups or races.

    Bonus points for the most offensive combinations.....

    e.g. Russians rating Ukrainians in your area....it can get pretty bad...I can think of many worse combos.

    I'm sorry but I'll just say it out right: new feminists are the absolute worst

    Don't get me wrong, I'm all for equality where possible. Where isn't equality possible? Well I'd like to conceive a child, but the plumbing isn't exactly useful for that. That sort of thing. Beyond that, were all the same, and IDGAF about your skin color, sexual preferences or whatever. I live by live and Let live, don't be an asshole, it's not that hard to be respectful

    New feminists though are the ones coming up with ideas like this website. On the surface, anyone could say that it's not a bad thing to have a place for women to talk about how to protect themselves. In reality though, it's a place where men, innocent or not, get doxxed and made to be rapists.

    There are some subs here on Lemmy as well that were very sad to see this shitshow of a website go, lamenting the fact that now they need a different place to dex people. Try not to tell them that doxxing is bad, it gets you banned.

  • This post did not contain any content.

    Lots of men in this thread real upset about this app pointing out how the majority men are shit

  • Lots of men in this thread real upset about this app pointing out how the majority men are shit

    Defaming people without giving them a chance to defend themselves, talk about shit people...

  • i wonder if there’s the potential for a different app with more encryption and a way to prevent doxxing and abuse.

    Encryption, sure.
    Preventing doxxing? I highly doubt it. But hey, it's women doing it so it's ok and anyone who criticizes that is an incel.

    wha? i didn't say anything about incels. or that doxxing is ok.

  • Hey Nima, I heard you like have to sex with dogs.

    Good luck proving you dont.

    uh hello! ok? not sure what your fetishes have to do with the conversation that was taking place. maybe you're from the UK and you're missing porn?

    But I wish you the best of luck in your search for whatever porn you like.

  • I'm certainly no web security expert, but shouldn't Tea's junior network/backend/security developers, let alone seniors, know how to secure said Firebase or S3 buckets with STARTTLS or SSL certificates? Shouldn't a company like this have some sort of compliance department?

    It's a little more complex than that. If you want the app on the user device to be able to dump data directly into your online database, you have to give it access in some way. Encrypting the transmission doesn't do much if every app installation contains access credentials that can be extracted or sniffed.

    Obviously there are ways around this too, but it's not just "use TLS".

  • 11 Stimmen
    20 Beiträge
    205 Aufrufe
    jimmydoreisalefty@lemmy.worldJ
    No, re-read. It is about technology.
  • 254 Stimmen
    42 Beiträge
    389 Aufrufe
    dojan@pawb.socialD
    Don’t assume evil when stupidity I didn't, though? I think that perhaps you missed the "I don’t think necessarily that people who perpetuate this problem are doing so out of malice" part. Scream racism all you want but you’re cheapening the meaning of the word and you’re not doing anyone a favor. I didn't invent this term. Darker patches on darker skin are harder to detect, just as facial features in the dark, on dark skin are garder to detect because there is literally less light to work with Computers don't see things the way we do. That's why steganography can be imperceptible to the human eye, and why adversarial examples work when the differences cannot be seen by humans. If a model is struggling at doing its job it's because the data is bad, be it the input data, or the training data. Historically one significant contributor has been that the datasets aren't particularly diverse, and white men end up as the default. It's why all the "AI" companies popped in "ethnically ambiguous" and other words into their prompts to coax their image generators into generating people that weren't white, and subsequently why these image generators gave us ethnically ambigaus memes and German nazi soldiers that were black.
  • Pornaroma Review a Detailed Comparison with Top Adult Sites

    Technology technology
    1
    2
    4 Stimmen
    1 Beiträge
    16 Aufrufe
    Niemand hat geantwortet
  • 1 Stimmen
    2 Beiträge
    27 Aufrufe
    A
    If you're a developer, a startup founder, or part of a small team, you've poured countless hours into building your web application. You've perfected the UI, optimized the database, and shipped features your users love. But in the rush to build and deploy, a critical question often gets deferred: is your application secure? For many, the answer is a nervous "I hope so." The reality is that without a proper defense, your application is exposed to a barrage of automated attacks hitting the web every second. Threats like SQL Injection, Cross-Site Scripting (XSS), and Remote Code Execution are not just reserved for large enterprises; they are constant dangers for any application with a public IP address. The Security Barrier: When Cost and Complexity Get in the Way The standard recommendation is to place a Web Application Firewall (WAF) in front of your application. A WAF acts as a protective shield, inspecting incoming traffic and filtering out malicious requests before they can do any damage. It’s a foundational piece of modern web security. So, why doesn't everyone have one? Historically, robust WAFs have been complex and expensive. They required significant budgets, specialized knowledge to configure, and ongoing maintenance, putting them out of reach for students, solo developers, non-profits, and early-stage startups. This has created a dangerous security divide, leaving the most innovative and resource-constrained projects the most vulnerable. But that is changing. Democratizing Security: The Power of a Community WAF Security should be a right, not a privilege. Recognizing this, the landscape is shifting towards more accessible, community-driven tools. The goal is to provide powerful, enterprise-grade protection to everyone, for free. This is the principle behind the HaltDos Community WAF. It's a no-cost, perpetually free Web Application Firewall designed specifically for the community that has been underserved for too long. It’s not a stripped-down trial version; it’s a powerful security tool designed to give you immediate and effective protection against the OWASP Top 10 and other critical web threats. What Can You Actually Do with It? With a community WAF, you can deploy a security layer in minutes that: Blocks Malicious Payloads: Get instant, out-of-the-box protection against common attack patterns like SQLi, XSS, RCE, and more. Stops Bad Bots: Prevent malicious bots from scraping your content, attempting credential stuffing, or spamming your forms. Gives You Visibility: A real-time dashboard shows you exactly who is trying to attack your application and what methods they are using, providing invaluable security intelligence. Allows Customization: You can add your own custom security rules to tailor the protection specifically to your application's logic and technology stack. The best part? It can be deployed virtually anywhere—on-premises, in a private cloud, or with any major cloud provider like AWS, Azure, or Google Cloud. Get Started in Minutes You don't need to be a security guru to use it. The setup is straightforward, and the value is immediate. Protecting the project, you've worked so hard on is no longer a question of budget. Download: Get the free Community WAF from the HaltDos site. Deploy: Follow the simple instructions to set it up with your web server (it’s compatible with Nginx, Apache, and others). Secure: Watch the dashboard as it begins to inspect your traffic and block threats in real-time. Security is a journey, but it must start somewhere. For developers, startups, and anyone running a web application on a tight budget, a community WAF is the perfect first step. It's powerful, it's easy, and it's completely free.
  • 85K – A Melhor Opção para Quem Busca Diversão e Recompensas

    Technology technology
    1
    1
    1 Stimmen
    1 Beiträge
    19 Aufrufe
    Niemand hat geantwortet
  • 88 Stimmen
    21 Beiträge
    288 Aufrufe
    J
    The self hosted model has hard coded censored content.
  • 0 Stimmen
    1 Beiträge
    16 Aufrufe
    Niemand hat geantwortet
  • 0 Stimmen
    1 Beiträge
    12 Aufrufe
    Niemand hat geantwortet