【】

Next time you make a payment on Venmo, beware: almost anyone can track it.
The popular mobile payments app is sharing users' personal data — including real names, comments sent with the payment, transaction dates, and recipients of the transaction — with the public by default. This information is being exposed through company’s public API, and it can be hidden by adjusting your privacy settings from "Public" to "Private."
Security researcher Hang Do Thi Duc recently discovered this "alarming amount" of information being leaked by examining the public API. The reason its happening, the researcher suggests, is because the Venmo app's default settings are set to "Public" for all users.
Using transaction data made available through the public API, Do Thi Duc downloaded 207,984,218 Venmo transactions, all the public transaction made on the app in 2017, and analyzed them. She has detailed her findings in an aptly named project called Public By Default.
SEE ALSO:Venmo fare-splitting is coming to the Uber appTo show just how much detail you can pull from the public Venmo transaction data, Do Thi Duc’s Public By Default project focuses on on five specific Venmo accounts. The five accounts, whose identities she’s chosen to keep private, include a Cannabis seller in California, a food truck vendor, a married man and woman, a junk food lover, and a fighting couple.
The amount of information Do Thi Duc is able to pull from the transaction data Venmo is sharing is pretty astonishing. For example, she was able to track the food truck vendor’s number one customer and find exactly when she’d go and what she was buying to eat. In the case of the married couple, Do Thi Duc was able to not only tell where they shop but also who was responsible for what bill.
In her report, Do Thi Duc was able to obtain even more information about the people behind these public transactions based on the profile picture they were using. If a Venmo user chose to link up their Facebook account so they can use the same profile picture as their Venmo avatar, Venmo’s public API shares the Facebook picture URL along with the rest of the transaction. This profile picture URL includes a user’s Facebook ID, which in turn will direct you straight to a person Facebook profile.
The fact that Venmo has enabled such easy access to this type of information in the form of a public API is problematic. In the hands of the right – or wrong – person this info is ripe for identity theft. Not only that, but the access to this information by say a stalker or domestic abuser is potentially dangerous.
In a statement, Venmo is quick to point out that while the “safety and privacy of Venmo users and their information is one of our highest priorities,” when it comes to protecting this information, it’s up to each Venmo user to change their default Venmo settings and make it private.
We recommend you do just that.
Featured Video For You
Would you throw $19,000 on this bathtub?
TopicsCybersecurityPrivacy
相关文章
These glasses hide a fitness tracker on your face
The last time a company tried popularizing wearable tech embedded in glasses, most notably with Goog2025-09-15- 羊毛地毯的清洗方法?1.羊毛地毯最好每周都清理一次,先使用吸塵器吸走地毯表麵的塵土和雜質,吸塵器最好使用不帶刷子的吸塵器,避免過多刷起毛的現象,如果不慎將水灑在地毯上,要將。羊毛地毯清洗方法?在清洗羊2025-09-15
- 女人吃聖女果有什麽好處和壞處女人吃聖女果有什麽好處問題分析:這個一般就是有大量的維生素,所以吃後可以達到補維生素的效果,對於皮膚這些當然是有好處的意見建議:所以這個適當的多吃是有好處不用擔心。經期吃聖2025-09-15
- 蒜長芽了還能吃嗎?會有營養嗎?大蒜長芽後不會含有任何有害物質或者毒素,不過唯一變化的是味道會不如以前,所以可以放心食用。而且隻要大蒜頭部沒有發生腐壞發黴,都是可以食用的。蒜頭發芽了還能吃嗎?那麽有個問2025-09-15
Teacher absolutely nails it with new homework policy
The war against homework has begun.。A massive pile of homework after a long day at school is enough2025-09-15- 蒜長芽了還能吃嗎?會有營養嗎 ?大蒜長芽後不會含有任何有害物質或者毒素,不過唯一變化的是味道會不如以前,所以可以放心食用。而且隻要大蒜頭部沒有發生腐壞發黴,都是可以食用的。蒜頭發芽了還能吃嗎?那麽有個問2025-09-15
最新评论