Tired of ads? Enjoy an ad-free experience by signing up.
Leighton Cosseboom ยท ยท 4 min read

Warning: tech startups should take cyber security seriously, and hereโ€™s why

Hacker-1

Image from Cuneopost

Last week, Tech in Asia picked up a story about a hacker in Thailand who spotted gaping security holes in Indonesiaโ€™s on-demand motorcycle app Go-Jek. According to the programmer, the bugs could allow anyone with the right knowledge and a simple web browser to infiltrate the companyโ€™s system, and change around all sorts of things like email addresses, phone numbers, user names, and even the virtual credit of drivers and partnering vendors.

The bugs reportedly existed for several months before the hacker decided to make the information public. Local media had a field day with the discovery.

The incident generated some heat for Go-Jek but also raised larger questions about whether startups should be more careful about cyber security. Go-Jek is unquestionably one of Indonesiaโ€™s largest and most talked-about tech firms. It has seen incredible growth and taken on multiple large funding rounds. Many would argue that the company is no longer a โ€œstartupโ€ in the strictest sense of the word. Young tech firms are undoubtedly taking cues from the nationโ€™s โ€œUber for motorcycles.โ€

In the recent past, Indonesia has been cited as the capital of the world for cyber attacks. Back in 2013, US-based Akamai Technologies published a report saying the archipelago is now responsible for 38 percent of the worldโ€™s malicious traffic. Odds are, that number has grown.

After polling readers on the Tech in Asia Community Facebook page, I was able to dig up a couple of interesting cautionary tales of startups that didnโ€™t stay on top of their cyber security, sometimes sacrificing user data protection for agility in their competitive markets.

hacker

See: Confirmed: Sequoia Capital invested in Indonesiaโ€™s Go-Jek

A stalkerโ€™s delight

One of our users shared a news article about an app called Tantan. The startup, which is essentially a Tinder clone for China that raised a US$5 million series A funding round last year, had a basic security flaw. It sent passwords, phone numbers, location data, and more via plain text back and forth from the app in a userโ€™s pocket to the companyโ€™s server.

The problem, according to tech blog Motherboard, was that pretty much any communication between the app and the Tantan server in China was sent unencrypted. This meant that anyone sitting at a cafe with a wifi connection and a little bit of IT knowledge could pluck user data from the air if they felt like it.

In addition to knowing someoneโ€™s hometown, sexual preference, and other tidbits of personal information, hackers could triangulate (in a manner of speaking) the actual location of any user with the app. Tantan sent this data to the server sometimes several times per minute. The data could then easily be plugged into Google Maps to track someoneโ€™s whereabouts.

You may be wondering, โ€œWhy would anyone go through the trouble? Donโ€™t people have better things to do?โ€ The answer is: yes most people do. But not everyone. Consider the nature of an app like Tantan. This security flaw could allow users to stalk other users, regardless of whether theyโ€™ve already been blocked. Someone scorned by romantic rejection could decide to access sensitive data about the other person, then use it any way they please.

tantan

Bitcoin bank robbery

Stay ahead in Asiaโ€™s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

๐Ÿ„ For casual readers / ๐Ÿ‘ถ Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

โŒ›Sign up in 20s. No payment details needed.

๐Ÿ“– For learners / ๐Ÿ‘ Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.

Community Writer

Leighton Cosseboom

Leighton Cosseboom is an American media entrepreneur in Southeast Asia. He is the former English editor of Tech in Asia's Indonesia chapter, and recently co-founded Content Collision (C2), a media enabler and technology platform looking to help brands and publishers in the region.