Hacker News new | ask | show | jobs
by mendez 3388 days ago
A London startup, Rentify, were trying to replace every photo returned by the Tinder API over their network with their CEO's face when they discovered a secret value showing the success rate of a user's photo. Full marks for fun office hack originality. 0 marks for Tinder for not using https for their photos.

A friend of mine also discovered Tinder was returning dates of birth to calculate age client side, so was able to predict other user's star signs: https://medium.com/haralds-notebook/tinder-should-probably-f... It proved fairly effective at getting a reply, as you might imagine. Thankfully he had the decency to explain how he guessed.

1 comments

This was us! Thanks for linking.

The terrifying bit is the sheer volume of data Tinder is leaking -- I would assume accidentally. The swipe % on the images for referrer and referee are pretty bad, but DOB and number of FB friends is enough data that you could trivially locate the person on Facebook.

Nice work! Agree, basic stuff as well - calculating an age from DateTime on the server is coding 101.