Connect with us

Hi, what are you looking for?

Technology

Lovense Faces Backlash Over Prolonged Email Leak Vulnerability

Lovense, the manufacturer of internet-connected sex toys, has come under scrutiny for failing to address a significant security vulnerability that exposed user email addresses for several months. Despite being informed about the issue by security researcher BobDaHacker in March 2023, the company reportedly delayed implementing a fix, leading to ongoing concerns about user privacy.

According to reports from TechCrunch and Bleeping Computer, BobDaHacker discovered that the app’s application programming interface (API) allowed anyone to convert a username into an email address. This vulnerability posed a serious risk, as it could enable an individual to take control of another user’s account. BobDaHacker noted that this flaw was particularly harmful for cam models who often share their usernames publicly but do not wish for their personal email addresses to be revealed.

In a blog post detailing the findings, BobDaHacker highlighted how the vulnerability could be exploited by sending a modified request to Lovense’s servers. This manipulation prompted the system to reveal the associated email address of the target user. The researcher even created a script capable of converting usernames into email addresses in under a second.

The timeline of Lovense’s response has raised eyebrows. BobDaHacker reported the vulnerabilities in partnership with the Internet of Dongs, a group dedicated to enhancing the security of internet-connected sex toys. Lovense initially claimed to have resolved the account takeover issue in April 2023, but BobDaHacker refuted this assertion, stating that the problem remained unaddressed.

In an effort to explain the delays, Lovense mentioned that while a rapid fix was considered, it would require all users to upgrade immediately, disrupting support for legacy versions of the app. The company estimated that a comprehensive solution to the email leak issue would take approximately 14 months to implement.

BobDaHacker pointed out that similar vulnerabilities had been reported to Lovense by security researchers earlier in 2023. However, it appears that these reports were closed without proper resolution, further highlighting the ongoing concerns surrounding the company’s commitment to user security.

In a statement to Bleeping Computer, Lovense asserted that an app update has been submitted to app stores, addressing the latest vulnerabilities. The company stated, “The full update is expected to be pushed to all users within the next week. Once all users have updated to the new version and we disable older versions, this issue will be completely resolved.”

As of now, Lovense has not provided a response to inquiries from The Verge regarding the ongoing situation. The delay in addressing such a critical security vulnerability raises important questions about user safety in the rapidly evolving market of connected devices.

You May Also Like

Top Stories

California has taken a stand against a federal directive from the Trump administration demanding the exclusion of transgender athletes from girls’ and women’s sports....

Entertainment

Olivia Munn, the acclaimed actress, recently shared an intimate revelation about her personal struggles with trichotillomania, a disorder that compels individuals to pull out...

Top Stories

Frontier, a coalition of technology leaders including Google and Meta, has announced a landmark investment in Arbor, a cutting-edge startup specializing in bioenergy with...

Top Stories

URGENT UPDATE: Affordable motorcycle helmets under ₹1000 are now available for safety-conscious riders across India. With road safety becoming a pressing issue, these helmets...

Entertainment

Fans of My Chemical Romance were taken aback after revelations emerged about guitarist Frank Iero‘s past encounter with the FBI. The incident traces back...

Health

Ng Kuo Pin, CEO of NCS, announced a significant investment of S$130 million in artificial intelligence (AI) over the next three years. This initiative...

Science

New observations from the James Webb Space Telescope (JWST) are transforming our understanding of Europa, one of Jupiter’s moons. These findings reveal that the...

Politics

Lawmakers in Pennsylvania are exploring potential changes to the state’s sales tax exemptions as the General Assembly grapples with a significant budget deficit. This...

Business

Political commentator Brilyn Hollyhand has voiced strong opposition to the prospect of Elon Musk launching a third political party in 2025. In his commentary,...

Politics

President Donald Trump is closely monitoring Republican senators as they navigate a controversial rescissions package that demands significant cuts to foreign aid and public...

Entertainment

Bleacher Report’s recent release of its ranking of the Top 100 NBA players of all time has sparked significant backlash, particularly regarding the placement...

Top Stories

UPDATE: Meta Platforms just announced a staggering $14.8 billion investment in AI, ramping up its efforts to dominate the tech landscape. This move comes...

Copyright © All rights reserved. This website provides general news and educational content for informational purposes only. While we strive for accuracy, we do not guarantee the completeness or reliability of the information presented. The content should not be considered professional advice of any kind. Readers are encouraged to verify facts and consult appropriate experts when needed. We are not responsible for any loss or inconvenience resulting from the use of information on this site.