A recently uncovered security flaw within Glow’s fertility tracking app’s online forum put sensitive data from its 25 million users at risk, as discovered by a cybersecurity expert.
A mistake in the app’s API configuration resulted in the personal information of users being exposed, including names, age ranges, self-reported locations, unique user IDs and any user-uploaded images like profile photos.
Ovi Liber, a security researcher, informed TechCrunch of the data leakage issue originating from the improperly secured developer API of Glow. The leak was reported to Glow in October and was rectified roughly a week later by the company.
APIs are pivotal for the communication between different services and applications on the internet. They should be securely restricted when dealing with confidential information to prevent unauthorized access to sensitive data.
Glow’s API, however, did not seem to have such security measures in place. Liber, who is not a professional developer, reported he could access it freely.
While Glow confirmed the problem has been fixed, they did not publicly comment on the issue or its repercussions. A Glow spokesperson did confirm the repair to TechCrunch but declined to elaborate on the situation further.
In a recent blog post, Liber elaborated on the vulnerability, which he claimed affected all Glow users, and described how he detected the security flaw – it was alarmingly straightforward to exploit.
Contact Us
If you have insights on similar vulnerabilities in fertility-tracking applications, we invite you to reach out. You can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, through platforms like Telegram, Keybase, and Wire @lorenzofb, or via email at lorenzo@techcrunch.com. TechCrunch also accepts tips via SecureDrop.
Liber’s discovery involved a type of security oversight known as Insecure Direct Object References (IDOR), which occurs when an application doesn’t perform proper authorization checks. According to Liber, the issue with Glow’s API was that it was effectively public and could be manipulated to reveal any user’s data.
While some may regard the compromised data as not intensely private, cybersecurity professionals argue that Glow’s users have a right to be aware of such a privacy issue.
Eva Galperin of the Electronic Frontier Foundation stated that this privacy breach should be taken seriously, stressing the significance of user awareness about their data security on such platforms.
Glow, available since 2013, boasts its capabilities to help users monitor various aspects of their reproductive health. However, this isn’t the first time Glow’s data protection mechanisms have been called into question. In the past, Consumer Reports and legal actions have pointed out security concerns.
FAQs About the Glow Data Exposure Incident
- What type of data was exposed due to the Glow app bug?
Names, age ranges, locations, user IDs, and uploaded images were among the data exposed.
- How was the Glow app bug discovered?
Security researcher Ovi Liber found the bug while examining the API calls on the Glow app’s forum using a network analysis tool.
- Has the issue been resolved?
Yes, Glow fixed the data leak approximately a week after being informed of the issue in October.
- What actions should Glow users take following this exposure?
Users should monitor their personal data, be cautious of phishing attempts, and consider reviewing the privacy settings on their Glow accounts.
- Was this the first time Glow has had security issues?
No, in the past Consumer Reports has highlighted potential privacy issues with Glow, and the company has faced legal action for inadequately protecting user data.
Conclusion
The exposure of personal information of 25 million users of the Glow fertility app due to a faulty API raises significant concerns about data security within connected health apps. It highlights the imperative need for stringent data protection measures and ongoing vigilance by both users and developers. Glow’s swift action to rectify the leak post-discovery must be acknowledged; however, it draws attention to the necessity of preemptive security checks to prevent data vulnerabilities from posing risks to users’ privacy.
[ad_2]








































