Women dating safety app 'Tea' breached, users' IDs posted to 4chan

(404media.co)

Comments

bravetraveler 20 hours ago
http://archive.today/U5Tah

Freewalled

gaiagraphia 12 hours ago
Not sure, but think this may have been the original thread: https://archive.4plebs.org/pol/thread/511313558

>DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!

>Tea App uploads all user verification submissions to this public firebase storage bucket with the prefix "attachments/": [link, now offline]

>Yes, if you sent Tea App your face and drivers license, they doxxed you publicly! No authentication, no nothing. It's a public bucket. I have written a Python script which scrapes the bucket and downloads all the images, page by page, so you can see if you're in it: [pastebin link]

>The censoring in picrel was added by me. The images in the bucket are raw and uncensored. Nice "anonymous" app. This is what happens when you entrust your personal information to a bunch of vibe-coding DEI hires.

>I won't be replying to this or making any more threads about it. I did my part, God bless you all. Regards, anon

Being so careless with people's personal data should be a major crime, tbh. If I manipulated thousands of people to let me scan their passports and various other bits of personal info, then just left the copies around the city for people to find, I'd be prosecuted, and rightfully so.

batmaniam 20 hours ago
Isn't this basically Peeple except gender locked to women? Peeple failed because they couldn't eliminate bias and gossip against anyone. If someone was jealous of another, for example, that person could just write false slander and claim it was real with no evidence. That would have affected the victim for jobs, dates, etc. So it was laughed at by VCs and everyone online and it shut down.

How is Tea even legal? Isn't this just a legal libel timebomb waiting to happen?

ok123456 15 hours ago
We need to stop allowing companies that are not directly engaged in financial services to request government IDs.

Facebook shouldn't legally be allowed to demand an ID any more than this disaster of an "app."

Now tens of thousands of people will be subject to identity theft because someone thought this was a neat growth hacking pattern for their ethically dubious idea of a social networking site.

oc1 7 hours ago
Wait, the app does what?

> The app aims to provide a space for women to exchange information about men in order to stay safe, and verifies that new users are women by asking them to upload a selfie.

What exactly does this mean? Which information is exchanged without consent of these people? This seems to me more problematic than the actual topic of the data breach.

pavel_lishin 20 hours ago
Good lord, why would they store those drivers' license images for an instant longer than it took to verify their users?
tonymet 19 hours ago
Maybe this is a good time to think about what policy could help discourage these horrific practices (it sounds like their storage was unprotected)

* App Store review requires a lightweight security audit / checklist on the backend protections.

* App Store CTF Kill Switch. Publisher has to share a private CTF token with Apple with a public name (e.g. /etc/apple-ctf-token ). The app store can automatically kill the app if the token is ever breached.

* Publisher is required to include their own sensitive records ( access to a high-value bank account) within their backend . Apple audits that these secrets are in the same storage as the consumer records.

1970-01-01 17 hours ago
"Breached"

1st sentence: "exposed database"

We need a more nuanced headline here. They did nothing responsible. 404 should title this story with something that will blame them first and the 'hackers' 2nd.

anonzzzies 6 hours ago
Outsourcing job was it? Modern programmers are literally terrible at all basic stuff (who stores ID images in the db and then in the clear, do you have many other mental issues or what?) (I see startups like Resend making the same mistakes and still people use them, so there isn't much punishment even from people with half a brain) and AI is going to make it all so much worse. And a public bucket. I think it should be criminally liable to be that sloppy.
nis0s 21 hours ago
How is this user data even reliable or useful when someone can make fake personas and populate their activity with LLMs?

Drivers licenses can be faked. Moreover, someone can just pretend to be someone else on this app with real drivers licenses.

The whole premise, implementation and process of Tea as a social media app is flawed, and a legal liability for the devs.

kashnote 16 hours ago
I'm a firm believer that if you want to start a tech company, at least one of the founders has to have a technical background. Even if you outsource all the work, you need to be able to ask the right questions related to security.

It's not just that this database was accessible via the internet. It was all public data. Storing people's IDs in a public database is just... wow.

loeg 17 hours ago
"Safety" is doing a lot in this headline. It's a gossip app.
robotnikman 18 hours ago
With all the state/countries starting to do ID verification, this is a good lesson in what can go horribly wrong with these types of policies.
8f2ab37a-ed6c 19 hours ago
Sad that a common response to "we might not want this app to exist" is "well, if you weren't cheating, you wouldn't have a problem with it".

Why do people want to live in a panopticon of their own creation, with random anonymous strangers morally policing, judging each other with zero consequence to them?

Don't think we'll ever learn our lesson when it comes to privacy, it will be Eternal September forever.

bilekas 15 hours ago
So it wasn't "breached" ... It was just so badly made that the bucket was public. Vibe coding ?
dang 19 hours ago
Related ongoing thread; others?

Women are anonymously spilling tea about men in their cities on viral app - https://news.ycombinator.com/item?id=44682914 - July 2025 (17 comments)

EcommerceFlow 20 hours ago
How is an app that allows users to post unverified and doxxing information about random men allowed on the IOS app store?

Apple had no issue mass censoring Parlor and others, how is an app like this able to reach #1 under all?

irusensei 2 hours ago
It's almost poetic that this happens on the same day UK demands website to collect personal identification. I'm looking forward to the shitshow in the upcoming months.
throw838384 19 hours ago
Is there a way, to verify if potential partner uses this app? Or if they are in "are we dating the same guy" type of group?

I take doxing, stalking, revenge porn and cyber bullying very seriously! And I would pay good money for a background check, to stay away from such people.

energy123 1 hour ago
Repeal section 230 and end this Black Mirror dystopian madness.
duxup 21 hours ago
A flash in the pan gossip app that when it functions normally is not worried about anyone's privacy / accuracy ... also doesn't care about good policies or their user's privacy.

That seems about right.

DaSHacka 10 hours ago
They posted an official response:

https://www.teaforwomen.com/data-breach

jackdawipper 14 hours ago
In 2008 when the GFC every company we worked IT for on contract fired their IT staff first. Two weeks later, we had bonanza period right through into the next year. They realised the hard way that those lowly cheap IT staff were quietly keeping them afloat. We charged a lot to fix their problems they created because their CEO thought IT was a waste of money.

This will prove security in IT coding is necessary, so enjoy watching the drama unfold.

IT security bonanza time. It wont be long.

poemxo 5 hours ago
On X, one of the leaked pictures seemed to be a DoD ID card, and I wondered why Tea needed proof of someone's identity. Then I remembered Uber and Lime both want your drivers license. Facebook and Instagram supposedly request it too if your account gets locked. This is not a new normal I like.
throwpoaster 15 hours ago
Oh no, they doxxed the users of the doxxing app. Shocking (tiny violin emoji)!
cmxch 19 hours ago
A case for ironclad data privacy laws that allow people to pierce the veil and request deletion.
edm0nd 14 hours ago
Someone dropped a map from all of the photos metadata

RIP

https://x.com/vxunderground/status/1948850061493850598

ridiculous_leke 20 hours ago
You can get Apple Legal involved if your face is on the app and they should get the related posts removed.
motohagiography 18 hours ago
for someone who thought Tea was a good idea, what would be the objection be if this leaked contributor data were used to populate a similar app to warn men off?
ungreased0675 12 hours ago
I’d like to start seeing legal jeopardy for companies that are careless with customer information. Make developers scared to retain anything they don’t absolutely need.
realsolipsist 7 hours ago
Just wanted to add…I can’t sneed
nonhaver 8 hours ago
if im understanding correctly this was a public bucket? aside from the obvious leaking of data couldnt this also be subject to a DoW (denial of wallet) attack where a user could auto download all the images constantly on a VPS and cause a massive bill?
thekevan 13 hours ago
Just yesterday I saw tweets from someone popular in tech Twitter talking about how great it was that he helped the person who made this.
odiroot 3 hours ago
That "Tea" app seems like a real GDPR nightmare anyway.
honeybadger1 18 hours ago
it should have never been allowed to be published anyway. not trying to justify what is happening, but these kind of apps are historically abused and create more problems than they intentionally try to solve.
SomaticPirate 17 hours ago
"An app was created to help women stay safe on dates and avoid creeps, proceeds to be hacked by creeps"

Not a great look here.

However, Tea could have done a modicum of cybersecurity work (or hired an outside firm) to prevent this. If they are claiming to want to keep women safe (and not just running a gossip board) then this should be a red alert for them. No public acknowledgement is concerning...

amelius 17 hours ago
Isn't Apple supposed to protect these app users? I suspect a lawsuit is in the making.
jjangkke 19 hours ago
- The fact that this app exists solidifies the data that a small group of men/women do most of the dating on tinder etc while the vast majority land dates far less if none at all.

- This creates distorted market supply and demand where those small group of men/women become sought after and its only human nature in that they value their supply less than the rest.

- Toxic behavior is expected from that small group of highly attractive people that do all the dating.

- It was only a matter of time before such app would run into legal issues or attract angry individuals. Now the damage to the leaked identities will be prolonged. With the AI tech today, the extent to which a damage can be done is unknown (ex. deepfake, impersonations, further doxxing).

- Tea user's driver licenses as well as selfies, usernames, emails, posts about their dates will drastically increase the surface area for lawsuits, fraud and exploitation by malicious agents.

- The users of this site and those that have directly posted images, details have opened themselves up to significant legal and criminal liability. Given these apps were probably popular in large city centers like California, NY have heavy punishment for digital harassment and privacy violations on top of the damages that can be claimed against them by the men who's information and details were posted.

- Tea is largely insulated from what the users post which means that their biggest exposure might be just neglect and failure to secure data which comes with a slap on the wrist. Which will make it harder for Tea's userbase to claim large damages against it.

I read more details about this case and its beyond egregious. Unencrypted firebase and full public buckets. There is no hacking involved, the tokens were being used to pull data from roughly all 30,000 users of Tea and were only blocked short while ago.

Allegedly, 60GB of photos, user personal information, driver license, gps data being shared on torrent. A map of all 30,000 users tied to GPS data is being posted as well.

Given the extreme neglect to secure their data, I now believe Tea will be open to even bigger legal liability possibly criminal even.

indycliff 16 hours ago
My guess, hired the absolute lowest paid developers and got what they paid for.
Ancapistani 20 hours ago
I thought 4chan died a year or so ago?

Ugh. I’m clearly getting old. I don’t even remember the last time I went to 4chan.

calexanderaz 12 hours ago
What Tea Got Wrong (and how to avoid it) https://youtu.be/mMvfBUNNKIY
koakuma-chan 20 hours ago
Firebase again lol
noisy_boy 12 hours ago
At this rate what is even the point of dating for men? An angry ex can just ruin your reputation.
Beijinger 17 hours ago
LOL, well deserved. https://youtu.be/WjfpryoQ0Mk
technion 12 hours ago
Given it's now "fixed", here's the scraping code so you can verify how this went down:

https://pastebin.com/CPBiqd1E

anal_reactor 15 hours ago
This is legit funny
trallnag 18 hours ago
Damn, this app is going down quicker than coalfax

Edit: Nevermind, looks like Tea has been around for quite some time already. But it kinda flew under the radar with a fairly small user base.

smnthermes 20 hours ago
You can report it to Google Play. The category is Restricted Content -> User Generated Content, and the app ID is "com.tea.tea". https://support.google.com/googleplay/android-developer/cont...
fHr 14 hours ago
hahahhahaha
raverbashing 20 hours ago
"Security breach" more likely a vibe coded slop app

But yeah please tell me how "we care about your privacy"

bobsmooth 20 hours ago
With all this talk about age verification, I have to wonder if the complete lack of security was intentional.
aaaja 18 hours ago
This is such excruciating incompetence by the app developers I'm wondering if it was intentional. Done to punish the women who dared to speak up about vile men.

I just hope they can pursue legal action for this, whether it was a deliberate trap or not.

okokwhatever 1 hour ago
What a moment to be a woman dude...
hnpolicestate 12 hours ago
The trend has been for all things related to sex, dating and relationships to be aggressively male hostile. But I think it's certainly peaked. Off topic, any notice how anti -male bumble is? Trash app.
WrongOnInternet 14 hours ago
Not to get all conspiratorial, but if I was an incel, or other type of woman-hating-man, with an axe to grind, creating an app to "protect" women and their dirty secrets, then having their data "breached" would be a pretty diabolical revenge plan. Only women can join the app, but the only person running the app is a man? Nothing suspicious about that...
mandmandam 1 hour ago
For all the gloating in here about doxxers getting doxxed, there sure are a lot of HN accounts exposing themselves as utter creeps in here.
exiguus 18 hours ago
Kind of meta toxic behaviour to download the data from a App that has the goal to prevent woman from men toxic behaviour.
jjangkke 20 hours ago
Some observations:

- The fact that this app exists solidifies the data that a small group of men/women do most of the dating on tinder etc while the vast majority land dates far less if none at all.

- This creates distorted market supply and demand where those small group of men/women become sought after and its only human nature in that they value their supply less than the rest.

- Toxic behavior is expected from that small group of highly attractive people that do all the dating.

- It was only a matter of time before such app would run into legal issues or attract angry individuals. Now the damage to the leaked identities will be prolonged. With the AI tech today, the extent to which a damage can be doned with the information from the leaks is unknown.

- As for the company behind Tea, they are done. They face a monumental class action lawsuit as well as ongoing individual civil/criminal cases that will arise from the leaked identities, in particular the photo of driver licenses as well as selfies, usernames, emails drastically increase the surface area for damages.

- The users of this site and those that have directly posted images, details have opened themselves up to significant liability from not only the men they have targeted but from law enforcement.

- We'll see some new laws being formed from this case. Once again, we see the hidden dangers of blindly trusting large popular platforms with sensitive data but the twist with Tea here is the defamation activity that opens up its users to both civil and criminal liability.