Tumblr Apple apps sent clear text passwords

By

Patch issued.

Tumblr has issued a patch for its iOS iPhone and iPad applications after a user discovered it sent passwords in clear text.

Tumblr Apple apps sent clear text passwords

The gaffe, first reported by The Register, was discovered by a security professional during an audit of iOS applications for an organisation.

He went public with the flaw after claiming Tumblr's support team failed to respond to his private disclosure.

Because the apps failed to make use of Secure Sockets Layer, users could for example have their accounts compromised when logging in over public wireless networks.

Tumblr product vice president Derek Gottfrid urged users to apply the "very important update" released today and change passwords if they had used the iOS apps.

"If you’ve been using these apps, you should also update your password on Tumblr and anywhere else you may have been using the same password," Gottfrid said in a statement.

"It’s also good practice to use different passwords across different services by using an app like 1Password or LastPass."

He said Tumblr was "tremendously sorry" for the flaw.

Got a news tip for our journalists? Share it with us anonymously here.

Copyright © SC Magazine, Australia

Tags:

Most Read Articles

Australia's super funds told to assess authentication controls

Australia's super funds told to assess authentication controls

Woolworths' CSO is Optus-bound

Woolworths' CSO is Optus-bound

CBA looks to GenAI to assist 1200 'security champions'

CBA looks to GenAI to assist 1200 'security champions'

Hackers abuse modified Salesforce app to steal data, extort companies

Hackers abuse modified Salesforce app to steal data, extort companies

Log In

  |  Forgot your password?