Warning: Do not use Hive Social โš ๏ธ๐Ÿ

We found multiple critical security vulnerabilities in the App, leaking private messages, posts, images and user data like phone numbers, emails and birthdates.

https://zerforschung.org/posts/hive-en/

โš ๏ธ Warning: do not use Hive Social ๐Ÿ‘‰๐Ÿ๐Ÿ‘ˆ

Dieser Artikel ist auch auf deutsch erschienen. Update: The vulnerabilities are currently no longer exploitable because Hive deactivated their servers. More details Following the Twitter takeover, a number of services promising to be an alternative gained traction. One of those is โ€œHive Socialโ€, which reached more than a million users in the last weeks. Of course, we were interested and took a look at Hive from a security standpoint. We found a number of critical vulnerabilities, which we confidentially reported to the company. After multiple attempts to contact the company we finally reached them by phone and they acknowledged the report. After multiple days and multiple reminders by us, they claimed to fix them within the next two days. However after those two days, multiple vulnerabilities we reported were not fixed and still existed at the time of writing. โš ๏ธ We strongly advise against using Hive in any form in the current state.

People on Twitter wished for an edit button. One of Hive's security vulnerabilities allows even more: You can edit posts of other accounts.
To not endanger the privacy of the people currently using Hive even further, we are only publishing a short product warning. Once the issues are fixed, we will publish a more in depth analysis including technical details.
Update: The vulnerabilities are currently no longer exploitable because Hive deactivated their servers. More details: https://zerforschung.org/posts/hive-en/#update-1-poof-the-hive-is-gone
โš ๏ธ Warning: do not use Hive Social ๐Ÿ‘‰๐Ÿ๐Ÿ‘ˆ

Dieser Artikel ist auch auf deutsch erschienen. Update: The vulnerabilities are currently no longer exploitable because Hive deactivated their servers. More details Following the Twitter takeover, a number of services promising to be an alternative gained traction. One of those is โ€œHive Socialโ€, which reached more than a million users in the last weeks. Of course, we were interested and took a look at Hive from a security standpoint. We found a number of critical vulnerabilities, which we confidentially reported to the company. After multiple attempts to contact the company we finally reached them by phone and they acknowledged the report. After multiple days and multiple reminders by us, they claimed to fix them within the next two days. However after those two days, multiple vulnerabilities we reported were not fixed and still existed at the time of writing. โš ๏ธ We strongly advise against using Hive in any form in the current state.

@zerforschung > We had a longer call with their developer

wait, there is only one?! ๐Ÿ˜ฎ

@zerforschung Iโ€™m not sure why anybody would give an app their real birthdate anyway.
@zerforschung doing the lords work ๐Ÿ™Œ
@zerforschung Four hours later.

@katzentratschen
Oh Mann, really?! ๐Ÿคฃ
Chooo Chooo, here comes the fail train...

@zerforschung

@momo @zerforschung Take a look at their replies. And bring some popcorn.

@katzentratschen
Oh my god! Time to open the strategic popcorn reserves!! ๐Ÿฅฐ

@zerforschung

@momo @katzentratschen @zerforschung I'll prefer Nacho but I do not see them coming back up anytime soon
@zerforschung I just went on the site. Not only are there no posts appearing, I created a post AND THE POST DISAPPEARED!!!!! Massive fail. Delete the app ASAP.
@zerforschung we need this feature on pleroma.
@zerforschung it's a feature ๐ŸŒŒ๐Ÿง 
@zerforschung eyyyyyyy it's Old Tumblr xD
@zerforschung holy cow, thatโ€™s handy ๐Ÿ˜ฎ
Thanks for saving me/us some time..
@zerforschung Perfect! Elon and Stephen King could collaborate on a single...tweet or whatever they are over there. Cool.
@zerforschung Wow. That bug where you can edit other peoples posts is quite scary really. Thanks for the heads up.
@zerforschung best Feature. I know better what other people should write ๐Ÿคช
@zerforschung some insane vulnerability
also getting john green tumblr vibes lol
@zerforschung @fasterthanlime this is a sorely needed feature on birdsite
@zerforschung @fasterthanlime they just want to bring old tumblr back!
@zerforschung Nice one ๐Ÿซฃ๐Ÿคฆ๐Ÿป

@zerforschung To quote a review of New World's un-sanitized inputs:

"The PVP in this is insane"

@zerforschung we super duper promise to not abuse this if you tell us how it's done 
@zerforschung i gotta try this out??? ๐Ÿ˜‚
@zerforschung wow! They should add this to the fedi
@zerforschung Weia, that sounds devastatingโ€ฆ
@zerforschung holy hell in a handbasket ๐Ÿ‘€ glad I havenโ€™t made an account there
@zerforschung look at all the people who aren't the slightest bit surprised by this ๐Ÿ˜
@zerforschung Why I am not surprised? 
@zerforschung Never heard of Hive social until now. At the same time, I will not use it...
@zerforschung Thanks for the warning.
@zerforschung Pretty sure you'll also find something when you take a closer look at post.news. That seems to be the main one hyped up by mainstream journalists and some other blue checks. Their founder should know better, from past work experience, but I'm sure they cut some corners, too.
@JMCQ87 @zerforschung Accessibility seems to be one of those corners. ๐Ÿ˜•
@zerforschung but mastodon DMs arent encrypted, its insecure! /s
@zerforschung Woah yikes. I had heard about it, already wasnโ€™t too keen on using it thanks to its apparent lack of moderation, but this is also bad. Guess Iโ€™ll be sticking entirely with Mastodon for now!
@zerforschung I Am Not Surprised At All
What an absolute disaster of an app. I knew something bad was going to happen, but not that bad.
@zerforschung I may be wrong, but the name sounds familiar. Sure, I could google it. - But I believe this is not the first time Hive has been caught with plain text leaks.
@zerforschung What did you expect for an app run by two people?