We are at an age where data collection is technically easy for companies, and the users are willing to foolishly and unhesitantly give out their data, unaware of the The General Data Protection Regulation (GDPR) is coming on the 25th of May 2018.

When the regulation comes into place, you better not send any European’s profile on an insecure layer as you might be fined €20 million or 4% of your global turnover, whichever is higher. With GDPR, I am hoping that your awareness about the amount of data services collect about you will be greater.

Okay let’s do the simplest thing, filter by word “famous”.

Damn, “famous” also does not exist in the websocket. Looking at the JSON payload, it seems that there is a message object, and then the pre-defined message has an ID and we’re sending that.

Well that was a fail, I sent it to the same girl that I tested on. Shouldn’t have added the name, it’ll look super weird now… I was thinking, maybe if I have a paid account, then I can see how can I map the blurred images to the original images. In fact I did:curl 'https://com/publicapi/v2/matchprofile/12303942525/profile? ' -H 'authorization: Bearer 12339f23-2302-4e6f-b9ae-1f9c99a6e123' -H ' Accept-Encoding: gzip, deflate, br' -H ' Accept-Language: en-US,en;q=0.9,ar;q=0.8' -H ' User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_5) Apple Web Kit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.181 Safari/537.36' -H 'x-xyz-gdid: ' -H 'accept: application/json' -H ' Connection: keep-alive' -H 'content-type: application/json' -H 'x-xyz-platform: desktop' --compressed Alright, let’s change one number of the match ID, and see if we can get data.404 Not Found. Your privacy policy states that you have extensive security measures including the use of SSL, that you’ll exercise reasonable care in providing secure transmission of information, but you also state that you accept no liability of any unintentional disclosure of information.If I need to send a message, then the first thing I’d have to do is to see how does sending a message look like.So I switched to any other person there is on my match list, clicked on the button to send a pre-defined message, selected one of them “If you are famous, who would you be? Meanwhile I was preserving the log of Chrome Network Requests.The dating website does not even allow you to read the message.So I thought: Hmm, let’s see how smart these “smart” people are.

