Distance to the Decimal — JavaScript Bug Hunt
Modelled on the Tinder location-privacy flaw reported by Include Security in 2014.
- Language: JavaScript
- Layer: Backend
- Difficulty: Easy
- Concepts: Security, Privacy
- Modelled on: Tinder · 2014
- Visible tests: the card names the right person; the distance is whole miles
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Tinder location-privacy flaw reported by Include Security in 2014. Tinder's API returned the distance to other users with very high precision, so by requesting it from three spoofed positions an attacker could trilaterate someone's location to within about 100 feet. Tinder fixed it after it was reported.
This project is a reconstruction: nearby.js builds the profile card one user sees of another. It returns the raw distance from the locked geo.js — and the other user's coordinates along with it.
Fix toPublicProfile so the card carries a coarse distance and nothing else about location.
Bug report
BUG-TINDER-LOC · Priority: High (privacy) · Reported by: external researcher
toPublicProfile(viewer, other) — users are { id, name, lat, lon, … }. Return EXACTLY { id, name, distanceMiles } (in that key order):
- distanceMiles = Math.round(geo.haversineMiles(viewer, other)), and never less than 1 (anything under a mile, including 0, is reported as 1)
- no coordinates and no other field of
othermay appear
listNearby(viewer, others) maps toPublicProfile over others, in order.
Observed: the card carries distanceMiles: 6.909… and the user's lat/lon.
Logs
GET /user/recs -> [{"id":"52b4…","distanceMiles":6.909390495,"lat":…,"lon":…}]The code as shipped
src/nearby/nearby.js (editable)
var geo = require("./geo");
exports.toPublicProfile = function (viewer, other) {
return {
id: other.id,
name: other.name,
distanceMiles: geo.haversineMiles(viewer, other),
lat: other.lat,
lon: other.lon
};
};
exports.listNearby = function (viewer, others) {
return others.map(function (o) { return exports.toPublicProfile(viewer, o); });
};
Read-only context: src/nearby/geo.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.