Distance to the Decimal — JavaScript Bug Hunt

Modelled on the Tinder location-privacy flaw reported by Include Security in 2014.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Easy
  • Concepts: Security, Privacy
  • Modelled on: Tinder · 2014
  • Visible tests: the card names the right person; the distance is whole miles
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Tinder location-privacy flaw reported by Include Security in 2014. Tinder's API returned the distance to other users with very high precision, so by requesting it from three spoofed positions an attacker could trilaterate someone's location to within about 100 feet. Tinder fixed it after it was reported.

This project is a reconstruction: nearby.js builds the profile card one user sees of another. It returns the raw distance from the locked geo.js — and the other user's coordinates along with it.

Fix toPublicProfile so the card carries a coarse distance and nothing else about location.

Bug report

BUG-TINDER-LOC · Priority: High (privacy) · Reported by: external researcher

toPublicProfile(viewer, other) — users are { id, name, lat, lon, … }. Return EXACTLY { id, name, distanceMiles } (in that key order):

  • distanceMiles = Math.round(geo.haversineMiles(viewer, other)), and never less than 1 (anything under a mile, including 0, is reported as 1)
  • no coordinates and no other field of other may appear

listNearby(viewer, others) maps toPublicProfile over others, in order.

Observed: the card carries distanceMiles: 6.909… and the user's lat/lon.

Logs

GET /user/recs -> [{"id":"52b4…","distanceMiles":6.909390495,"lat":…,"lon":…}]

The code as shipped

src/nearby/nearby.js (editable)

var geo = require("./geo");

exports.toPublicProfile = function (viewer, other) {
  return {
    id: other.id,
    name: other.name,
    distanceMiles: geo.haversineMiles(viewer, other),
    lat: other.lat,
    lon: other.lon
  };
};

exports.listNearby = function (viewer, others) {
  return others.map(function (o) { return exports.toPublicProfile(viewer, o); });
};

Read-only context: src/nearby/geo.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.