Skip to main content

Color ‘hack’ allows users to spy on anyone from anywhere

color-photo-sharing-app
Image used with permission by copyright holder

The problems with the highly publicized new iOS and Android photo-sharing app Color continue to mount. According to Forbes, the app has an easily exploitable feature that makes it simple for tech-savvy users to view all the photos of anyone who uses the app.

That’s not to say Color is known for its tight privacy settings — in fact, the exact opposite is true. When a user takes a photo with Color, the photo is automatically uploaded to the Color servers. Then — and this is what makes the app so notable — anyone within a set perimeter of where that photo was taken can see that picture, along with the pictures of any other Color user who happens to be snapping off shots in that particular location.

Right now, that perimeter is set to 150 feet. But because of complaints by early adopters that the app is worthless unless used within the vicinity of other Color users, the company says it plans to implement a sliding scale to determine the range in which photo streams can be shared, based on population density.

The Color hack, first noted in a Twitter post by security researcher an Veracode chief technology officer Chris Wysopal last Thursday, can be carried out with “trivial geolocation spoofing.” In other words, you trick the app to think you’re actually somewhere else, and it will display the photos of users in that area.

Wysopal reportedly tried out his location spoof this past weekend using a jailbroken iPad and the (unauthorized) app FakeLocation. Sure enough, it worked exactly as he expected.

“This only took about five minutes to download the FakeLocation app and try a few locations where I figured there would be early adopters who like trying out the latest apps,” Wysopal told Forbes in a email. “No hacking involved.”

Color maintains that all pictures taken using the app are public, anyway, and so the vulnerability in its app is negligible. Still, the whole thing makes us feel a little bit out in the open.

Check out our hands-on review of Color here.

Andrew Couts
Former Digital Trends Contributor
Features Editor for Digital Trends, Andrew Couts covers a wide swath of consumer technology topics, with particular focus on…
I review phones for a living — here are the 10 apps I can’t live without
iPhone 14 Pro with custom home screen on Mickey Mouse phone holder next to flowers

For most of my life, I think I’ve had a pretty unique career path among my family and friends. Ever since I got the original iPhone, I’ve turned my love for writing into writing about technology, specifically mobile phones. Though I’ve pretty much been iPhone-only for most of my career, since I started at Digital Trends, I’ve been opening up to the world of Android.

Now that I’m checking out both iPhone and Android phones, the world of apps for me has expanded quite a bit. But regardless of what device I’m using, there are some apps that I need before anything else. Here are the first apps that I install when I get a new phone.
1Password (iOS and Android)

Read more
Sorry, but allowing third-party iPhone app stores is a bad idea
Apple Arcade page on the Apple Store as seen on the iPhone 14 Pro

Apple has always been known to have tight control over both its hardware and software, such as the iPhone and the iOS that powers it. However, it seems that the European Union continues to get more and more involved in regulating Apple’s most popular device, the iPhone.

So far, the EU has set a deadline for Apple to replace the Lightning port with USB-C by 2024, and more recently, it raised the possibility of opening up iOS to allow for sideloading and alternative app stores from third parties. Though this may seem like a good thing at first, I’m not so sure that’s entirely true. At the very least, it will cause some complications.
The App Store is a secure and trusted place

Read more
AT&T just made it a lot easier to upgrade your phone
AT&T Storefront with logo.

Do you want to upgrade your phone more than once a year? What about three times a year? Are you on AT&T? If you answered yes to those questions, then AT&T’s new “Next Up Anytime” early upgrade program is made for you. With this add-on, you’ll be able to upgrade your phone three times a year for just $10 extra every month. It will be available starting July 16.

Currently, AT&T has its “Next Up” add-on, which has been available for the past several years. This program costs $6 extra per month and lets you upgrade by trading in your existing phone after at least half of it is paid off. But the new Next Up Anytime option gives you some more flexibility.

Read more