Tired of ads? Enjoy an ad-free experience by signing up.
Leighton Cosseboom · · 3 min read

Hacker finds security bugs in Go-Jek app

Go-Jek is a popular app for hailing motorbike taxis.

Go-Jek is a popular app for hailing motorbike taxis.

Earlier this week, CNN Indonesia reported that an Indonesian programmer in Thailand named Yohanes Nugroho identified security flaws in on-demand motorcycle app Go-Jek.

Some of the bugs in question have already been resolved, but the hacker reportedly found bugs in the system that might have allowed people to manipulate the earnings of Go-Jek’s partners and drivers over the past several months. Those with the right knowledge could also access personal information about the company’s drivers and users, and change information like usernames, phone numbers, and emails if they so desired.

The alarming part, according to Nugroho, was that anyone motivated enough to hack Go-Jek wouldn’t need any special software or equipment, but instead would only need the right instructions and a normal web browser.

According to Nugroho’s personal blog, bugs of this nature have existed in Go-Jek’s system since at least August 2015 all the way until he published a post on the matter at the end of December – and possibly beyond. Nugroho claims the Go-Jek team asked him not to publish the information until January 10. In spite of this request, he ended up publishing the information on January 2.

Update 1/15/16: Yohanes Nugroho reached out to Tech in Asia to say that he notified Go-Jek on December 24 that the bugs he discovered in August were still there. He then wrote a blog post about it on January 2, which was password protected so that only he and the Go-Jek team could review it. Go-Jek read the post, then asked him to delay publication until January 5, then asked him to extend the deadline until January 10. On January 10, Nugroho waited until mid-day with no further reply from Go-Jek. He then published the article.

go-jek-bug

Image from Amazing Grace

See: If you work at Go-Jek, Nadiem Makarim is your ‘coach, sugar daddy, and friend’Nugroho believes there are still many bugs left to be revealed in the Go-Jek app. He told the media, “all [of] Go-Jek is HTTP-based API, so the browser capital alone could exploit its API if you already know the address. Finding out this address can be done by ‘reverse engineering’ or ‘sniffing.’”

In Nugroho’s blog post, he makes the following claims:

  • Anyone can search for a customer ID by phone number, name, or email
  • Anyone can change the credit (or “pulsa”) for a Go-Jek driver
  • Anyone can see the Go-Jek driver’s personal data, including photos, addresses, and even mother’s name
  • Anyone can get usernames, emails, and mobile phone numbers
  • Anyone could change the mobile phone number and the name of another user, without needing to know their password
  • Anyone can see other people’s order history

Following public scrutiny from local media portals Merdeka and CNN Indonesia, Go-Jek CEO Nadiem Markarim issued the following statement:

“In Go-Jek, we are always open and appreciate any constructive feedback to improve services [or] our technology. One thing is for sure, data security has always been one of our top priorities. We understand the existence of this problem and have made ​​improvements in almost all aspects and dimensions. We can affirm that the current credit belonging to the customers, partners, and riders is 100 percent safe. We have a dedicated team working to resolve this matter and [it] will be completed entirely in the next few days.”

Tech in Asia has reached out to Go-Jek for further comment, and will update this article if needed.

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Leighton Cosseboom

Leighton Cosseboom is an American media entrepreneur in Southeast Asia. He is the former English editor of Tech in Asia's Indonesia chapter, and recently co-founded Content Collision (C2), a media enabler and technology platform looking to help brands and publishers in the region.