Yik Yak, the anonymous social platform that was brought back from the dead in August 2021, has reportedly been revealing the precise locations and unique IDs associated with its users.
The exposed data was discovered(Opens in a new window) by David Teather, a computer science student at the University of Wisconsin-Madison, who disclosed the issue to Yik Yak on April 11.
The company addressed part of the problem on May 8; Teather publicly revealed the flaws on May 9. "I was able to access the precise GPS coordinates (accurate to within 10-15ft) of all posts and comments on the YikYak [sic] platform," Teather says, which "leaves at least 2 million users(Opens in a new window) at risk." (At least—Yik Yak hasn't publicly revealed how many users it has since November 2021.) Teather also discovered that every post and comment on Yik Yak is associated with a unique user ID.
The company released an update to address this problem on May 8, but according to Teather, someone could still de-anonymize users with "a few minutes of guessing." Teather's findings demonstrate the problem with taking any ostensibly private service at its word.Read more on pcmag.com