• AernaLingus [any]@hexbear.net
    link
    fedilink
    English
    arrow-up
    20
    ·
    1 month ago

    I first learned about the Quittr vulnerability from an independent researcher, who scanned the Google Play Store and Apple App Store for a common misconfiguration in apps that use Google Firebase, an app development platform. The researcher tested hundreds of the top apps on both stores after we published a story about the Tea app suffering a devastating hack due to the same issue. The researcher found dozens of apps had the same problem, including Quittr, but did not name Quittr in his public disclosure because the highly sensitive and personal data could put users at risk.

    So glad that Google is going to protect users by forcing even free open-source app developers outside of the Google Play ecosystem to pay a fee and register with them using government ID, which will lead many of them to stop development entirely. Users will be so safe now that they can only install Google-approved apps that must adhere to rigorous software engineering standards.