There is an app called Tea which purports to be a tool to protect women’s safety — it allows women to share info about the men they’ve been dating.
Tea launched back in 2023 but this week skyrocketed to the top of the U.S. Apple App Store, Business Insider reported. The app lets women anonymously post photos of men, along with stories of their alleged experience with them, and ask others for input. It has some similarities to the ‘Are We Dating The Same Guy?’ Facebook groups that 404 Media previously covered.
“Are we dating the same guy? Ask our anonymous community of women to make sure your date is safe, not a catfish, and not in a relationship,” the app’s page on the both the Apple App Store and Google Play Store reads.
When creating an account, users are required to upload a selfie, which Tea says it uses to determine whether the user is a woman or not. In our own tests, after uploading a selfie the app may say a user is put into a waitlist for verification that can last 17 hours, suggesting many people are trying to sign up at the moment.
I’m already dubious — they use a photo of the applicant to determine their sex? That’s sloppy, and I can see many opportunities for false positives and false negatives.
But that’s not the big problem. The Tea database got hacked…by 4chan.
Yes, if you sent Tea App your face and drivers license, they doxxed you publicly! No authentication, no nothing. It’s a public bucket,a post on 4chan providing details of the vulnerability reads.DRIVERS LICENSES AND FACE PICS! GET THE FUCK IN HERE BEFORE THEY SHUT IT DOWN!
Congratulations. Your personal info has just been delivered to the worst collection of slimy sleazebags on the internet.
I’m just shocked that this app went live without the most rigorous evaluation of its security. You’re collecting scans of driver’s licenses with selfie photos, with only the most rudimentary precautions? What else? Social security numbers, bank accounts?










