mirror of
https://github.com/pxdg-afk/paxad.git
synced 2026-08-22 19:41:07 -04:00
Published 1 file
This commit is contained in:
@@ -3,16 +3,16 @@ publish: true
|
||||
aliases:
|
||||
- tailtag
|
||||
created: 2026-07-12T17:55:57.560-04:00
|
||||
modified: 2026-07-12T18:04:56.514-04:00
|
||||
modified: 2026-07-12T18:24:12.896-04:00
|
||||
tags:
|
||||
- furry
|
||||
- AI
|
||||
- vibe-coding
|
||||
---
|
||||
|
||||
several online sources have indicated that the recently popular Pokémon GO-like app "[TailTag](https://www.playtailtag.com)" has been breached and had user information leaked to the public internet.
|
||||
several online sources have indicated that the recently popular furry social app "[TailTag](https://www.playtailtag.com)" has been breached and had user information leaked to the public internet.
|
||||
|
||||
> props & excellent thread discussing this incident: https://bsky.app/profile/highlysuspect.agency/post/3mqhuc6bwds2r
|
||||
> super props & excellent thread discussing this incident: https://bsky.app/profile/highlysuspect.agency/post/3mqhuc6bwds2r
|
||||
|
||||
users were first made aware of the breach when they received a strange push notification from the app titled "IMPORTANT ANNOUNCEMENT" with the message body consisting primarily of "meows" and other cat noises.
|
||||
|
||||
@@ -24,13 +24,13 @@ Finn's response:
|
||||
|
||||

|
||||
|
||||
twitter user **@twnlink** did a lot of digging on this and discovered some rather alarming configuration errors:
|
||||
twitter user **@twnlink** did a lot of digging on this and discovered backend access was not entirely restricted to admins:
|
||||
|
||||

|
||||
|
||||
twitter user [**@Benaclejames**](https://x.com/Benaclejames) posted the following technical write-up of the vulnerabilities discovered on their Notion page: https://app.notion.com/p/TailTag-Vulnerabilities-39bd16d9d17180fa9279ec92bbe19549
|
||||
|
||||
[**@FloppyMinty**](https://x.com/FloppyMinty) was able to confirm the app's backend information was still publicly accessible as of 11AM EDT on June 12th.[^2][^6] While no user passwords were compromised, just about every other bit of personally identifiable information that users entered into the application is publicly accessible. With proper tools, a malicious actor could view information uploaded to the application in real-time and could theoretically then determine the physical location of specific users and/or the fursuiters they photograph.[^1]
|
||||
[**@FloppyMinty**](https://x.com/FloppyMinty) was able to confirm the app's backend information was still publicly accessible as of June 12th.[^2] Finn did later state in a separate post that the applied fix to the notifications issue should have fixed the access control issues as well.[^6] while no user passwords were compromised, just about every other bit of personally identifiable information that users entered into the application is publicly accessible, including email addresses and photos.[^1] as of writing, other than the publicly disclosed accesses of backend information already mentioned, there is no evidence any others have accessed or posted any data from the application.
|
||||
|
||||
on July 12, 2026, Finn posted the following response:
|
||||
|
||||
@@ -45,10 +45,14 @@ on July 12, 2026, Finn posted the following response:
|
||||
> \[in later tweets in reply to this original image post]:
|
||||
> If you would like to assist with future security, access control, or any other parts of the app, please reach out. I am happy to discuss how you can help.[^4]
|
||||
|
||||
In the interim, TailTag has been **taken offline** until further notice.[^5]
|
||||
in the interim, TailTag has been **taken offline** until further notice.[^5]
|
||||
|
||||
most of the comments in response to Finn's own statement were questions about the amount of AI assistance used in the creation of the app. Finn did say "LLMs were involved in the implementation of designs \[he] wrote in English."[^7]
|
||||
|
||||
TailTag's website is still online as of writing. Updates to both the site and application are likely, though no timetable has been announced.
|
||||
|
||||
change your passwords, folks, you'll be alright.
|
||||
|
||||
[^1]: @BenacleJames: _TailTag Vulnerabilities_ - https://app.notion.com/p/TailTag-Vulnerabilities-39bd16d9d17180fa9279ec92bbe19549
|
||||
|
||||
[^2]: @FloppyMinty: "PSA: If you used TailTag, your email among other metadata has been compromised." https://x.com/FloppyMinty/status/2076320147233493306
|
||||
|
||||
Reference in New Issue
Block a user