Security

Dating app for Trump loners commits YUGE blunder: It leaks more than the West Wing

Donald Daters application more insecure than the president


A much-hyped dating site for Donald Trump supporters in the US is being blasted for shoddy security that may have exposed all of its users to eavesdropping and account theft.

Donald Daters pitches itself as "an American-based singles community connecting lovers, friends, and Trump supporters alike." The app, offered for both iOS and Android, was brought into the national spotlight on Monday when it was featured on Fox News.

Unfortunately, the media offensive appears to have come before the dating service was able to run a decent security assessment. So someone did that for them for free.

Shortly after the glowing profiles of the app went live, infosec researcher Baptiste Robert disclosed the application's makers had poorly secured an internet-facing cloud-hosted backend database containing information including all user names, private conversations via the app, and authentication tokens needed to log into their accounts.

Robert confirmed to El Reg that the data is stored on a backend database, and tweeted:

So, basically, everything short of credit card details is available from the mobile app's backend, if you know where and how to look. We'll give you a clue: the app includes the cryptographic keys needed to access the developers' cloud-hosted storage and accounts. These keys can be used to access the databases holding people's profiles. It seems someone bigly ignored some basic security measures.

According to the researcher, the dating app has about 1,607 users who have engaged in a total of 128 conversations, the longest being a discussion between two of the app's developers.

Robert was also able to extract information from the Android client:

The makers of Donald Daters did not return a request from El Reg for comment on the matter. SAD. And if you're using this app: don't. ®

Send us news
28 Comments

Enterprises are getting stuck in AI pilot hell, say Chatterbox Labs execs

Security, not model performance, is what's stalling adoption

Trump guts digital ID rules, claims they help 'illegal aliens' commit fraud

Also axes secure software mandates - optional is the new secure, apparently

AT&T not sure if new customer data dump is déjà vu

Re-selling info from an earlier breach? Probably. But which one?

Trump’s cyber czar pick grilled over CISA cuts: ‘If we have a cyber 9/11, you’re the guy’

Plus: Plankey's confirmation process 'temporarily delayed'

Dem senators pen stern letter urging Noem to reinstate cyber review board

Remember Salt Typhoon? Anyone?

ConnectWise customers get mysterious warning about 'sophisticated' nation-state hack

Pen tester on ScreenConnect bug: This one ‘terrifies’ me

Judge cites big OPM records leaks from 2015 in DOGE slapdown

Federal court blocks further data sharing, blasts lack of safeguards

US infrastructure could crumble under cyberattack, ex-NSA advisor warns

PLUS: Doxxers jailed; Botnets bounce back; CISA questioned over app-vetting program closure; And more

Dems demand audit of CVE program as Federal funding remains uncertain

PLUS: Discord invite links may not be safe; Miscreants find new way to hide malicious JavaScript; and more!

Schneier tries to rip the rose-colored AI glasses from the eyes of Congress

DOGE moves fast and breaks things, and now our data is at risk, security guru warns in hearing

Chinese spy crew appears to be preparing for conflict by backdooring 75+ critical orgs

SentinelOne discovered the campaign when they tried to hit the security vendor's own servers

CISO who helped unmask Badbox warns: Version 3 is coming

The botnet’s still alive and evolving