Brightkite API puts user information at risk
The Brightkite API allows 3rd party websites to access information of a logged-in Brightkite users via JavaScript, even without their a) consent b) knowledge. Of course, this information is submitted to Brightkite in the first place as "semi-public", but giving away your current (exact, the one meant for friends) location, sex, etc. to a 3rd party without knowing it does not make me very happy. This also includes direct messages sent to other users!
I will not disclose all the details here, so please contact trinta (at) gmail dot com for further details.
I will not disclose all the details here, so please contact trinta (at) gmail dot com for further details.
3
people have this problem
I have this problem, too!
Tell me when someone solves it.
The more people who report this problem, the more it gets noticed.
The more people who report this problem, the more it gets noticed.
The company has a solution in progress.
Create a customer community for your own organization
Plans starting at $19/month
-
Inappropriate?Hi Trinta, thank you for bringing this matter to our attention. We are investigating this now and working on a solution.
1 person says
this solves the problem
Loading Profile...



EMPLOYEE