Close Menu
UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    What's Hot

    Reaction from Gills boss Gareth Ainsworth after League 2 win

    February 28, 2026

    Anthropic’s Claude rises to No. 2 in the App Store following Pentagon dispute

    February 28, 2026

    Whitstable draw with Larkfield & New Hythe, Hythe Town win again, Division 1 Rochester beat AFC Greenwich Borough

    February 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Reaction from Gills boss Gareth Ainsworth after League 2 win
    • Anthropic’s Claude rises to No. 2 in the App Store following Pentagon dispute
    • Whitstable draw with Larkfield & New Hythe, Hythe Town win again, Division 1 Rochester beat AFC Greenwich Borough
    • Where to Stream SAG Awards Live – Hollywood Life
    • Is the U.S. at War With Iran? Updates After the Missile Attack – Hollywood Life
    • TradeTek 3.1 Industrial Strength Construction Estimating Solution
    • Senate Dems Push DOJ, Treasury To Probe Binance
    • A12 J29 northbound exit | Northbound | Accident
    • London
    • Kent
    • Glasgow
    • Cardiff
    • Belfast
    Facebook X (Twitter) Instagram YouTube
    UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    Subscribe
    Saturday, February 28
    • Home
    • News
      1. Kent
      2. London
      3. Belfast
      4. Birmingham
      5. Cardiff
      6. Edinburgh
      7. Glasgow
      8. Liverpool
      9. Manchester
      10. Newcastle
      11. Nottingham
      12. Sheffield
      13. West Yorkshire
      Featured

      ‘Miniature’ mountain creature with ‘squeaker’-like call discovered as new species

      Science November 9, 2023
      Recent

      Anthropic’s Claude rises to No. 2 in the App Store following Pentagon dispute

      February 28, 2026

      Senate Dems Push DOJ, Treasury To Probe Binance

      February 28, 2026

      A12 J29 northbound exit | Northbound | Accident

      February 28, 2026
    • Lifestyle
      1. Celebrity
      2. Fashion
      3. Food
      4. Leisure
      5. Social Good
      6. Trending
      7. Wellness
      8. Event
      Featured

      Where to Stream SAG Awards Live – Hollywood Life

      Celebrity February 28, 2026
      Recent

      Where to Stream SAG Awards Live – Hollywood Life

      February 28, 2026

      Is the U.S. at War With Iran? Updates After the Missile Attack – Hollywood Life

      February 28, 2026

      Pink & Carey Hart’s Relationship Timeline From Beginning to Now – Hollywood Life

      February 28, 2026
    • Science
    • Business
    • Sports

      Reaction from Gills boss Gareth Ainsworth after League 2 win

      February 28, 2026

      Whitstable draw with Larkfield & New Hythe, Hythe Town win again, Division 1 Rochester beat AFC Greenwich Borough

      February 28, 2026

      League 2 match report from the SO Legal Stadium, Holker Street

      February 28, 2026

      Live updates from Barrow v Gillingham, Ebbsfleet United v Farnborough, Salisbury v Maidstone United

      February 28, 2026

      Friday February 27 to Wednesday March 4

      February 27, 2026
    • Politics
    • Tech
    • Property
    • Press Release
    UK Daily: Tech, Science, Business & Lifestyle News UpdatesUK Daily: Tech, Science, Business & Lifestyle News Updates
    Home » Fertility tracker Glow fixes bug that exposed users’ personal data

    Fertility tracker Glow fixes bug that exposed users’ personal data

    bibhutiBy bibhutiFebruary 13, 2024 Tech No Comments3 Mins Read
    Facebook Twitter LinkedIn WhatsApp Telegram
    Share
    Facebook Twitter LinkedIn Telegram WhatsApp


    A bug in the online forum for the fertility tracking app Glow exposed the personal data of around 25 million users, according to a security researcher.

    The bug exposed users’ first and last names, self-reported age group (such as children aged 13-18 and adults aged 19-25, and aged 26 and older), the user’s self-described location, the app’s unique user identifier (within Glow’s software platform), and any user-uploaded images, such as profile photos.

    Security researcher Ovi Liber told TechCrunch that he found user data leaking from Glow’s developer API. Liber reported the bug to Glow in October, and said Glow fixed the leak about a week later.

    An API allows two or more internet-connected systems to communicate with each other, such as a user’s app and the app’s backend servers. APIs can be public, but companies with sensitive data typically restrict access to its own employees or trusted third-party developers.

    Liber, however, said that Glow’s API was accessible to anyone, as he is not a developer.

    An unnamed Glow representative confirmed to TechCrunch that the bug is fixed, but Glow declined to discuss the bug and its impact on the record or provide the representative’s name. As such, TechCrunch is not printing Glow’s response.

    In a blog post published on Monday, Liber wrote that the vulnerability he found affected all of Glow’s 25 million users. Liber told TechCrunch that accessing the data was relatively easy.

    Contact Us

    Do you have more information about similar flaws in fertility-tracking apps? We’d love to hear from you. From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram, Keybase and Wire @lorenzofb, or email lorenzo@techcrunch.com. You also can contact TechCrunch via SecureDrop.

    “I basically had my Android device hooked up with [network analysis tool] Burp and poked around on the forum and saw that API call returning the user data. That’s where I found the IDOR,” Liber said, referring to a type of vulnerability where a server lacks the proper checks to ensure access is only granted to authorized users or developers. “Where they say it should be available to devs only, [it’s] not true, it’s a public API endpoint that returns data for each user — simply attacker needs to know how the API call is made.”

    While the leaking data might not seem extremely sensitive, a digital security expert believes Glow users’ deserve to know that this information is accessible.

    “I think that is a pretty big deal,” Eva Galperin, the cybersecurity director at the digital rights non-profit Electronic Frontier Foundation, told TechCrunch, referring to Liber’s research. “Even without getting into the question of what is and is not [private identifiable information] under which legal regime, the people who use Glow might seriously reconsider their use if they knew that it leaked this data about them.”

    Glow, which launched in 2013, describes itself as “the most comprehensive period tracker and fertility app in the world,” which people can use to track their “menstrual cycle, ovulation, and fertility signs, all in one place.”

    In 2016, Consumer Reports found that it was possible to access Glow user’s data and comments about their sex lives, history of miscarriages, abortions and more, because of a privacy loophole related to the way the app allowed couples to link their accounts and share data. In 2020, Glow agreed to pay a fine of $250,000 after an investigation by California’s Attorney General, which accused the company of failing to “adequately safeguard [users’] health information,” and “allowed access to user’s information without the user’s consent.”



    Source link

    Featured Just In Top News
    Share. Facebook Twitter LinkedIn Email
    Previous ArticleTop 10 Dangers Of Social Media
    Next Article Taylor Swift Goes Clubbing With Parents, Travis Kelce After Super Bowl – Hollywood Life
    bibhuti
    • Website

    Keep Reading

    Reaction from Gills boss Gareth Ainsworth after League 2 win

    Anthropic’s Claude rises to No. 2 in the App Store following Pentagon dispute

    Whitstable draw with Larkfield & New Hythe, Hythe Town win again, Division 1 Rochester beat AFC Greenwich Borough

    Where to Stream SAG Awards Live – Hollywood Life

    Is the U.S. at War With Iran? Updates After the Missile Attack – Hollywood Life

    A12 J29 northbound exit | Northbound | Accident

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    89th Utkala Dibasa Celebration Brings Odisha’s Vibrant Culture to London

    April 8, 2024

    US and EU pledge to foster connections to enhance research on AI safety and risk.

    April 5, 2024

    Holi Celebrations Across Various Locations in Kent Attract a Diverse Range of Community Participation

    March 25, 2024

    Plans for new Bromley tower blocks up to 14-storeys tall refused

    December 4, 2023
    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement

    Recent Posts

    • Reaction from Gills boss Gareth Ainsworth after League 2 win
    • Anthropic’s Claude rises to No. 2 in the App Store following Pentagon dispute
    • Whitstable draw with Larkfield & New Hythe, Hythe Town win again, Division 1 Rochester beat AFC Greenwich Borough
    • Where to Stream SAG Awards Live – Hollywood Life
    • Is the U.S. at War With Iran? Updates After the Missile Attack – Hollywood Life

    Recent Comments

    1. Register on Anycubic users say their 3D printers were hacked to warn of a security flaw
    2. Pembuatan Akun Binance on Braiins Becomes First Mining Pool To Introduce Lightning Payouts
    3. tadalafil tablets sale on The market is forcing cloud vendors to relax data egress fees
    4. cerebrozen reviews on Kent director of cricket Simon Cook adapting to his new role during the close season
    5. Glycogen Review on The little-known town just 5 miles from Kent border with stunning beaches and only 600 residents
    The News Times Logo
    Facebook X (Twitter) Pinterest Vimeo WhatsApp TikTok Instagram

    News

    • UK News
    • US Politics
    • EU Politics
    • Business
    • Opinions
    • Connections
    • Science

    Company

    • Information
    • Advertising
    • Classified Ads
    • Contact Info
    • Do Not Sell Data
    • GDPR Policy
    • Media Kits

    Services

    • Subscriptions
    • Customer Support
    • Bulk Packages
    • Newsletters
    • Sponsored News
    • Work With Us

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2026 The News Times. Designed by The News Times.
    • Privacy Policy
    • Terms
    • Accessibility

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}