Cameo is a delicious app . you may pay up D - listing renown — the tier of folks you ’d watch on The Masked Singer or some other ridiculous reality show — to record personalise video for you and your friends . Prices per video bet on each celeb ’s rates , but bear a Real Housewife to send a surprise birthday greeting to a Bravo - obsessed have sex one is almost invaluable .
Except those private television salutation were n’t actually private at all . It turn out that Cameo is kind of a disaster when it comes to protection , according to aMotherboard report .
Motherboard discovered two separate issues , thanks to a tip - off from an anon. research worker .

You might want to change your Cameo password.Photo: Caitlin McGarry (Gizmodo
The first issue seems to be the effect of a strange but intentional decision . Cameo allows users to produce and share data link to video without requiring a password to view those video recording . That includes video that users mark as individual , which just means that they ’re not publicly listed on a fame ’s profile . Motherboard was capable to run a script to find private videos on Cameo — ones that , on the face of it , the user who requested them had no intention of being publicly viewable .
But Cameo also expose exploiter email addresses , telephone numbers , in - app messages , and salted and hashed passwords by storing the certification to its Amazon server in the Android interlingual rendition of the company ’s app codification .
“ Cameo recently learned of a vulnerability in one of our databases from a third party security data investigator potentially affect a limited amount of story holder data point , ” the caller sound out in a statement to Motherboard . “ Our squad promptly fixed the way out . After thoroughly investigating the matter , we are currently not cognizant of any evidence indicating that anyone else other than the security department investigator knew of or utilize the vulnerability . The trust of our community and information certificate are top priorities for Cameo . We are continuing to actively investigate the issue and unceasingly investing in data security . ”

The ship’s company say it has resolved the issue and is notifying affected users .
Motherboard let on a few other take with Cameo ’s operations . The companionship stores its privacy insurance policy in a Google doc , which is an interesting decision . The anon. investigator also cater Motherboard with Cameo ’s training video for participate celebrities , which details how they should upload their video to Telegram or else of directly to Cameo .
So if you require your fave world hotshot to record a birthday greeting for you , just mind that your personal information — and your telecasting — might be out there for the world to find .

Privacy
Daily Newsletter
Get the best technical school , science , and culture news program in your inbox day by day .
News from the future , deliver to your nowadays .
You May Also Like













![]()