複数のハッカーが反ポルノアプリ「Quittr」に数か月間セキュリティ問題を警告
複数のハッカーが、男性の自慰行為を止めることを目的としたアプリ「Quittr」に対し、数か月間にわたり重大なセキュリティ問題を警告したが、アプリ開発者はメディアからの問い合わせ後数週間経つまで問題を修正しなかった。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
image男性の自慰行為を止めさせることを目的とするアプリ「Quittr」について、少なくとも3人が数か月間にわたり重大なセキュリティ問題を警告していたが、アプリの開発者は、404 Mediaが複数回にわたってコメントを求めて連絡してから数週間後まで、それらを修正しなかった。
「私は創業者にメールで脆弱性を説明しました。開発者から返信があり、『セキュリティを向上させる方法を検討中』と述べ、どのようにして発見したかを尋ねられました。私はステップバイステップで手順を説明し、APIキーがクライアント側にあるのはFirebaseでは一般的であり、セキュリティルールを実装するだけで済むと説明しました」と、Kaedenと名乗る独立系セキュリティ研究者は自身のブログで述べている。「その後、何の音沙汰もありませんでした。フォローアップのメールを送りました。返信なし。もう一度フォローアップしました。それでも何もありませんでした。」
私は当初、別の独立系セキュリティ研究者からこのアプリのセキュリティ問題について聞き、1月にQuittrのセキュリティ脆弱性について最初の記事を書いた。当時、開発者に複数回連絡したにもかかわらずQuittrが問題を修正しなかったため、アプリ名は伏せた。その研究者が発見したのは、Quittrがモバイル開発プラットフォームであるGoogle Firebaseの利用において設定ミスがあり、デフォルトの状態では誰でも簡単に「認証済みユーザー」になり、ユーザーデータが保存されている場合の多いアプリのバックエンドストレージにアクセスできてしまうというものだった。
その研究者は当初、9月にQuittrにこの問題について連絡した。Quittrの創業者であるアレックス・スレイター氏は問題を認め、研究者に感謝の意を表明し、数時間以内に修正すると述べた。数か月後、研究者が問題が依然として修正されていないことを確認し、404 Mediaに連絡した。私はスレイター氏とQuittrに複数回連絡を取った。スレイター氏は当初、セキュリティ脆弱性の存在を否定したが、その後、3月10日より前に問題を修正した。これを確認した後、私はQuittrがようやく脆弱性を修正したことを受け、アプリ名を明記した別の記事を公開した。
スレイター氏は最近、『ニューヨーク・マガジン』で特集され、Quittrの成功がもたらした豪勢な生活様式——エキゾチックなスーパーカーを運転し、マイアミの豪邸に住むなど——が詳しく報じられた。スレイター氏は自身の生活様式に関する動画を個人のYouTubeチャンネルでも共有している。
研究者がアクセスできたデータの一部には、ユーザーの年齢、ポルノ視聴の頻度(自己申告)、ポルノ視聴習慣に関する懺悔的な記述などが含まれていた。データによれば、ユーザーの多くは自身を未成年であると申告していた。
3月、Kaedenは2025年7月3日に同じ脆弱性についてQuittrに連絡したことを示すメールを私に提供した。
「あなた方のFirebase(データベース)は設定が誤っており、あらゆるデータの読み書きが可能です。可能な操作の一例として、全ユーザーとその情報の一覧取得があり、この種のアプリにとっては非常に深刻な問題です」とKaedenはQuittrへのメールで述べている。Kaedenはまた、問題の修正方法を具体的に伝え、バグ報奨金があれば「大いにありがたい」と付け加えたが、一切受け取ることはなかった。
カイオと名乗るQuittrの開発者がKaedenにメールを送り、詳細情報を求めるとともに、問題を責任を持って開示してくれたことに謝意を示した。Kaedenは情報を提供したが、その後返答はなかった。
3月にQuittrについての私の記事を公開して以来、さらに別の匿名を希望する独立系セキュリティ研究者から連絡があり、彼も2025年8月に同様の脆弱性についてQuittrに通知していたという。結局のところ、合計3名の異なるセキュリティ研究者が、404 Mediaが修正されていない問題についてコメントを求めて同アプリに連絡するより前に、Quittrが機微なユーザーデータを危険にさらしていると警告していたのである。
原文を表示
imageAt least three people warned Quittr, an app that wants to help men stop masturbating, about serious security issues for months, but the creators of the app didn’t fix them until weeks after 404 Media reached out for comment multiple times.
“I emailed the founders and explained the vulnerability. A developer responded, said he was ‘looking into ways to make our security better,’ and asked how I found it. I walked him through it step by step, even explained that the API key being client-sided is normal for Firebase and that they just needed to implement security rules,” an independent researcher who goes by Kaeden, said on her personal blog. “Then nothing. I followed up. No response. I followed up again. Nothing.”
I first wrote about Quittr’s security vulnerability in January after hearing about the app’s security problems from a different independent security researcher. At the time, I did not name the app because Quittr did not fix the issue despite reaching out to the developers about it multiple times. That security researcher found that Quittr had a misconfiguration issue in its use of the mobile development platform Google Firebase, which by default makes it easy for anyone to make themselves an “authenticated” user who can access the app’s backend storage where in many instances user data is stored.
That researcher originally contacted Quittr about the issue in September. Quittr’s founder, Alex Slater, acknowledged the issue, thanked the researcher, and said he would fix it in a matter of hours. When the researcher saw the issue still wasn’t fixed months later, they contacted 404 Media. I reached out to Slater and Quittr multiple times. Slater initially denied there was a security vulnerability, but then fixed the issue sometime before March 10. After this, I saw Quittr finally fixed the vulnerability and published another story naming the app.
Slater was also recently profiled in New York Magazine, which detailed the opulent lifestyle the success of Quittr has afforded them, including driving exotic super cars and living in a Miami mansion. Slater shares videos about his lifestyle on his personal YouTube channel as well.
Some of the data the researcher could access included users’ age, how often they said they watched porn, and written confessions about their porn watching habits. Many of the users self-identified as minors, according to the data.
In March, Kaeden provided me with emails showing he contacted Quittr about the same vulnerability on July 3, 2025.
“Your firebase (Database) is misconfigured its possible to read/write to anything, one of the things its possible to do for example is list all users and their info, which is pretty bad for an app of this nature,” Kaeden said in her email to Quitter. Kaeden also told Quittr exactly how to fix the issue and said that a bug bounty “would be highly appreciated” but he never received one.
A Quittr developer who identified as Caio emailed Kaeden asking for more information and thanked her for responsibly disclosing the issue. Kaeden provided that information, but never heard back.
Since publishing my story about Quittr in March, yet another independent security researcher, who asked to remain anonymous, contacted me to say they also notified Quittr about a similar vulnerability in August 2025. Altogether, three different security researchers told Quittr it was jeopardizing sensitive user data before 404 Media reached out to the app for comment about the issue not being fixed.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み