The Star Malaysia - Star2

Data of 21 million Timehop users exposed

- By SHARMILA NAIR bytz@thestar.com.my

PERSONAL details, including names and e-mail addresses of over 21 million Timehop app users have been exposed due to a data breach. About 4.7 million of those accounts had phone numbers attached to them.

Timehop is an add-on app used by social media users to reminisce about the good ol’ days. It was popular before Facebook rolled out its Memories feature, and the app was also used by many Twitter and Instagram fans.

The startup admits that the breach occurred due to unauthoris­ed access to its Cloud computing service, which it says was not protected by a multi-factor authentica­tion.

The breach was detected two hours after it happened, and although Timehop managed to disrupt the data transfer, it did not manage to stop some of the data theft. On top of personal data, the attackers also reportedly took “access tokens” provided to Timehop by the social media platforms.

Timehop states that the tokens could allow attackers to view some of the social media posts uploaded by the affected users in the past. However, the startup claims that it has already taken measures to terminate the tokens and that they are no longer available for use.

“The damage was limited because of our long-standing commitment to only use the data we absolutely need to provide our service. Timehop has never stored your credit card or any financial data, location data or IP addresses; we don’t store copies of your social media profiles, we separate user informatio­n from social media content – and we delete our copies of your Memories after you’ve seen them,” states Timehop.

The case is still under investigat­ion and Timehop stresses that there has been no report of unauthoris­ed access of user data through the access token. It also states that the tokens do not provide anyone access to Facebook Messenger, or Direct Messages on Twitter or Instagram, or even the items posted by the users’ friends on their Facebook walls.

Alarmingly, Timehop – which only has access to users’ posts on their own profiles – admits that there was a short time window where it was “theoretica­lly” possible for the hackers to gain access to those said posts.

However, it stresses that there has been no evidence of such an occurrence. Timehop claims that it is working with a cybersecur­ity company to search the Internet and Dark Web to find out if any of the data have been leaked. So far, there is no evidence that such activity has happened, though Timehop believes that there is a high likelihood that the data will appear in forums and circulated on the Internet and the Dark Web.

As a result of this breach, Timehop claims that it has taken steps to include multi-factor authentica­tion to secure authorisat­ion and access control on all accounts.

As Timehop has invalidate­d all API credential­s, users have been automatica­lly logged out of the app, and users will be asked to log in again to Timehop and reauthenti­cate each service they wish to use with Timehop. This process, it says, will generate a new, secure token.

“We immediatel­y conducted a user audit and permission­s inventory, changed all passwords and keys, added multi-factor authentica­tion to all accounts in all Cloud-based services, revoked inappropri­ate permission, increased alarming and monitoring, and performed various other technical tasks related to authentica­tion and access management and more pervasive encryption throughout our environmen­t. We will employ the latest encryption techniques in our databases,” it states.

 ?? — AP ?? Timehop is an add-on app used by social media users to reminisce the good ol’ days.
— AP Timehop is an add-on app used by social media users to reminisce the good ol’ days.

Newspapers in English

Newspapers from Malaysia