I spent New Year's Day the way I spend most New Year's Days, which is not doing anything resolution-shaped and instead lying on the couch scrolling Twitter with a mild headache. And that's how I found out about the Snapchat thing, somewhere around 2pm, before I'd even had real food.
Quick recap for anyone who was smarter than me and stayed off their phone yesterday: back in August a security outfit called Gibson Security quietly told Snapchat about a flaw in the "Find Friends" feature, the one where the app can match up phone numbers to usernames. Snapchat didn't fix it. On December 25th, after months of nothing, Gibson Security got fed up and published the details publicly, basically saying "we told you, you didn't listen, here it is." Snapchat responded two days later with a blog post that used the word "theoretical" to describe the risk, which is one of those words that ages really badly. It aged about five days.
Yesterday, January 1st, a site calling itself SnapchatDB.info posted a searchable database of 4.6 million Snapchat usernames matched to partial phone numbers, apparently just to prove the vulnerability was real and not "theoretical" at all. Last two digits of each number were blanked out, supposedly as a courtesy, though I'm not sure how much courtesy is left once your username and area code are sitting in a downloadable file. By last night the site was struggling to load, probably because half of Twitter was trying to check if they were in it.
I checked. I don't think I am, and not because I'm careful, exactly, more because I never connected my contacts to Snapchat in the first place. This is less a security-conscious habit and more a leftover reflex from LinkedIn spamming my entire address book back around 2011 when I let it "find people I might know." I learned that lesson once and now I just say no to every single app that asks to read my contacts, on principle, forever. Instagram, fine, no contacts for you. Random flashlight app asking for my address book, absolutely not, and yes I know that's an old joke about app permissions but it was true then and it's true now.
What actually bugs me about this whole thing isn't even the leak itself, it's the timeline. Gibson Security didn't drop a zero-day out of nowhere. They gave Snapchat something like four months of warning before going public, and Snapchat's public answer was essentially a shrug dressed up in engineering language, something about existing measures already making large-scale scraping difficult. Well, 4.6 million rows says otherwise. I don't know if that number is the whole userbase they could reach or just what they bothered to scrape before getting bored, but either way it's not a small proof of concept.
I'll say this too: I don't think Snapchat is uniquely careless here, I think this is just what happens when a company grows from a dorm room app to tens of millions of users faster than its security team can grow with it. That's not an excuse, it's just how these things go, and it's going to keep happening to other apps in 2014 too, probably ones we haven't heard of yet.
If you've got Snapchat and you're the type to add your phone number or let it scan your contacts, might be worth going into settings and turning that off, assuming their servers aren't too busy to let you in today. I'd also gently suggest not being the person who signs up their little cousin for Snapchat this Christmas without at least glancing at what permissions get requested during setup, which, yes, is a very specific complaint, and yes, it's aimed at myself, because I did exactly that on the 26th and only afterward thought to check what "Find Friends" actually does.
Anyway. Happy new year. Off to a strong start, tech industry.