Get the latest tech news

Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers


A security researcher went public after the sex toy maker asked for more than a year to fix the vulnerabilities, which leak users' private email addresses and allow for accounts to be hijacked.

The researcher, who goes by the handle BobDaHacker, published details of the bugs on Monday after Lovense claimed it would need 14 months to fix the flaws so as to not inconvenience users of some of its legacy products. “This was especially bad for cam models who share their usernames publicly but obviously don’t want their personal emails exposed,” BobDaHacker wrote in their blog post. The company told BobDaHacker in the same email that it decided against a “faster, one-month fix,” which would have required forcing customers using older products to upgrade their apps immediately.

Get the Android app

Or read this on TechCrunch

Read more on:

Photo of Accounts

Accounts

Photo of email addresses

email addresses

Photo of Lovense

Lovense

Related news:

News photo

Instagram adds new protections for accounts that primarily feature children

News photo

Google Chrome for iOS now lets you switch between personal and work accounts

News photo

iPhone Users Can Now Easily Swap Between Personal and Work Accounts in Chrome