Blog

HowAboutWe fix this security flaw?

I posted a HowAboutWe profile after my foodie friend Lee retweeted something about “Eater Dating.” Of course I wanted to get in on Eater Dating; I like Eater -> Girls who like Eater share a similar interest -> How About We go have some Lobster Bisque? -> Yadda Yadda Yadda

A few days after I posted some profile pictures and my first date suggestion. I get a few messages from different friends of mine saying that I was featured in their “Recommended Dates” email over the weekend. One of my friends actually forwarded me the email I was in:
.

.
I responded this morning, and clicked my profile to go back to the site:
.

.

I look up at the top right corner and it seems like I am logged in as my friend. The visitors/inbox numbers seem about the same, and apparently I can ask “him” out. I click visitors out of curiosity:

.
.

It’s confirmed, I’m officially logged in as my friend. Can I do everything a user is allowed to right now? Let’s find out.

How about we… check out her inbox?

.
.

How about we… post a new date?

.
.

How about we… change her privacy settings?

.
.

I’m sure they’ll fix this soon, but in the meantime, how about we not forward anyone our How About We Email?

Comments

comments

4 comments…

Leave a Comment