Tumblr Apple apps sent clear text passwords

By
Follow google news

Patch issued.

Tumblr has issued a patch for its iOS iPhone and iPad applications after a user discovered it sent passwords in clear text.

Tumblr Apple apps sent clear text passwords

The gaffe, first reported by The Register, was discovered by a security professional during an audit of iOS applications for an organisation.

He went public with the flaw after claiming Tumblr's support team failed to respond to his private disclosure.

Because the apps failed to make use of Secure Sockets Layer, users could for example have their accounts compromised when logging in over public wireless networks.

Tumblr product vice president Derek Gottfrid urged users to apply the "very important update" released today and change passwords if they had used the iOS apps.

"If you’ve been using these apps, you should also update your password on Tumblr and anywhere else you may have been using the same password," Gottfrid said in a statement.

"It’s also good practice to use different passwords across different services by using an app like 1Password or LastPass."

He said Tumblr was "tremendously sorry" for the flaw.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Under malware threat, runaway AI agent project OpenClaw turns to Google's VirusTotal

Under malware threat, runaway AI agent project OpenClaw turns to Google's VirusTotal

Windows Secure Boot certificates expire in June, Microsoft warns

Windows Secure Boot certificates expire in June, Microsoft warns

Service NSW launches Digital ID pilot

Service NSW launches Digital ID pilot

Log In

  |  Forgot your password?