Attack Vector

Snapchat

Review Date: 17/10/2022

Snapchat

TYPE

Launched on

App Developer - Snap Inc

Overall Ratings

Description
Snapchat is a fast and fun way to share the moment with your friends and family. Snapchat opens straight to the camera — just tap to take a photo or press and hold for video. Snapchat has an estimated 347 million daily users and children love all the filters they can use when they take and send pictures to their friends.
Login

Username Offensive and very offensive usernames can be generated in Snapchat without any problems.

Password Other than the password having to be 8 characters long there are no complexity requirements so you can enter a very weak password such as Pa55w0rd! and Snapchat will accept that as a password. This means that Snapchat accounts can be very susceptible to hacking especially if two factor authentication is not enabled on the account.

Multi Factor Authentication Snapchat supports two factor authentication however, as with most apps, it is not enabled by default when it absolutely should be. It can be enabled in the app and it should be turned on as soon as you setup your account.

Chat

There is no Chat feature on Snapchat, communication is through direct messages and these can only be sent to people who are in your contacts list. You cannot communicate with someone who isn’t in your contacts.

 

Access

On an iPhone Snapchat needs access to a microphone to record audio for Stories or video chats, Photos to save Snaps to a Camera Roll or send photos and videos in Chat, and the Clipboard to attach links. Apart from this, Snapchat might also need access to Notifications and Contacts. Finally, Location access is required for features like Geofilters and Snap Map, but users have the option to turn off Precise Location to maintain privacy.

On Android, the list of permissions is much higher. Apart from the permissions mentioned above, Snapchat needs access to receive text messages to autofill SMS verification codes. It also requires access to read contents of the phone’s storage, and modify and delete files in order to save Snaps and Stories or automatically load app settings. In addition, it needs almost complete access to network permissions to send and receive snaps and some battery permissions to use the flash, control vibration, or prevent the phone from sleeping. Users can choose to disable specific permissions, but doing so might result in some features being unavailable on Snapchat.

 

Location Service

Snapchat has a feature that broadcasts the user’s location on a map, which was released in June 2017. It was met with concerns over privacy and safety. The feature delivers a message via an opt-in asking if the user would like to show their position on the map but reportedly doesn’t explain the ramifications of doing so, including the application updates the user’s position on the map each time the app is opened and not just when actively capturing snaps, potentially assisting stalkers.

The map can be zoomed in to feature detailed geographical info like streets and addresses, which raise safety warnings from many famous media publications for children, teenagers, and even adults who are unaware of the feature’s actual behaviour.

In reply to this concern, Snapchat says that users can use the Ghost Mode of this program or select the friends that they wish to share their location.

Age Rating

The age limit stated by Snapchat to use the app is 13 years although no real checks to verify someone’s age are made when signing up.

The age rating on Google play to download the app is Teen, while iTunes it is 12+

Age Verification

Although the age limit of Snapchat is 13 years old in its terms of services and users need to provide their birth date to create a Snapchat account, there is no age verification. That is to say, users under 13, like 12, 11, 10, and even 9 years old, can still get access to Snapchat by providing a fake date of birth.

Security Breaches

The most recent Snapchat data breach occurred in May 2019, when it came to light that Snapchat employees were spying on users: viewing messages, location data, and more. Prior to that, a phishing attack in 2017 led to 55,000 stolen Snapchat login credentials.

As of July, there have been no reported Snapchat data breaches so far in 2022.

Anonymous

Although you need a phone number to sign up to Snapchat, it is possible to use a pay as you go sim which is not registered to anyone to sign up which would make it possible to be anonymous.

 

Review Summary

Snapchat is a fast and fun way to share the moment with your friends and family. Snapchat opens straight to the camera — just tap to take a photo or press and hold for video. Unfortunately, there are issues with Snapchat in terms of offensive user names, easy to guess passwords and not having two factor authentication enabled by default.

There can be inappropriate content discovered through Snapchats Discover feature and they have in the past introduced inappropriate content onto the platform such as the very short lived “Cosmo After Dark” Snapchat Introduces Cosmo After Dark (p*rn) – Protect Young Eyes Blog