October 23, 2018

Digital Privacy: “PayPal’s Venmo App Exposes Most Transactions via its API”

UPDATED September 27, 2018 25,000 Americans Urge Venmo to Update its Privacy Settings (via  Mozilla)

From Bleeping Computer:

The vast majority of Venmo transactions are being logged in a public API accessible to anyone, according to the recent investigation of a privacy advocate.

The reason this happens is because the Venmo app’s default settings are set to “Public” for all users.

Unless users specifically change this value, all the transactions they make via the Venmo money-sending app are logged and made available to anyone via the Venmo public API.

Read the Complete Article, Access Resources

See Also: Venmo: How The Payment App Exposes Our Private Lives (via The Guardian)

This was the finding of a Berlin-based researcher, Hang Do Thi Duc, who analysed the more than 200 million public Venmo transactions made in 2017. Her aim was to highlight the privacy risk from using a seemingly innocuous peer-to-peer app.

Do Thi Duc showcases the level of personal data exposed through Venmo through her project website “Public by Default”, named because when anyone makes a payment through the app, it is public unless that person has locked down their privacy settings. Here she has honed in on five individual users, including a man who sells cannabis in Santa Barbara and a pair of lovers who pass money between each other accompanied by flirting, arguing, apologies and threats.

Read the Complete Article, View Charts

See Also: Changing Your Venmo Settings (via Public by Default)

Gary Price About Gary Price

Gary Price (gprice@mediasourceinc.com) is a librarian, writer, consultant, and frequent conference speaker based in the Washington D.C. metro area. Before launching INFOdocket, Price and Shirl Kennedy were the founders and senior editors at ResourceShelf and DocuTicker for 10 years. From 2006-2009 he was Director of Online Information Services at Ask.com, and is currently a contributing editor at Search Engine Land.

Share