Zappl Ios Posting Pass Leak!

in zappl •  7 years ago  (edited)

Please discontinue your use of the Zappl IOS app.


zapplPostImage1519679866361.png


Encoded username and password are being sent to the server. Zappl IOS currently has an issue with the encoded passwords that are stored in your device being sent to the server. Normally its only supposed to send a session to the server.

Normally zappl works by storing your passwords in the browser or device and it sends a login session to the server. But instead its sending the username and password which it isn't supposed to being doing.

Our servers have not been breached and we have file shredded the node logs but just in case you feel the need please reset your posting keys.

We have taken the IOS app out the app store, but it will take some time to come down. So please let people you know for the time being to wait for the new update.

We are working as fast as possible to fix the issue. Any fixes we upload can take up to 8 days for the review process to go through. But on average it takes about 12hours - 2days.

To reset your posting private key password you can use https://steemit.com/@usernames/password
You can also use the trusted desktop wallet vessel https://github.com/aaroncox/vessel

This does not effect users of Android App and Website

Authors get paid when people like you upvote their post.
If you enjoyed what you read here, create your account today and start earning FREE STEEM!
Sort Order:  

thanks for the latest information, I really appreciate the hard effort of the zappl ,, and I will mention this information to people I know ..thanks

Thanks for spreading the information.

yes, equally .. so there are few complaints of people who use zappl application, they say directly to me ,, what they say is about the increasingly reduced Upvote ,, so what I want to ask on zappl is ,, can zappl provide Upvote a little more than usual.?

  ·  7 years ago (edited)

That's based on SBD value, With btc price crashing its going down more and more. The reason its not a 1% upvote anymore is because we have thousands of users and those were only the rates at the start of the app.

We allowed people to abuse the first two days. We figured out their tricks and learned abuse methods to not reward abusers. Average voting is now 0.5% upvotes but with the price getting lower and lower we will look into raising it for the difference.

Zappl will not be paying everyone on every posts.

Why is there a problem with the encoded password stored on the device?
Can this cause problems with user accounts ??
Please explain in detail so we can understand ..
Thank you

  ·  7 years ago (edited)

We added a more detailed explanation in the post what it means.

thanks for the latest information, I really appreciate the hard effort of the zappl ,, and I will mention this information to people I know ..thanks

I hope this change does not complicate the application users zappl ,.

It shouldn't have any effect people should just wait for the next update before use.

this may be a big problem. password issues. thanks for letting us know quickly, so we can stop it quickly

The issue was caught early so almost it would effect around 20-35 or so users who downloaded it. But just to be clear no passwords have been stolen.

Thank goodness if the password is secure. thank you once again for being so quickly told

Resteemed for visibility. Thanks for the alert

Thanks

Well received. Thanks for heads up.

Ok thanks sir

This seems to be a regular occurrence with your platform. I don't think I will be using it anymore.

These issues are different than the one before, the last issue was a possibility of the node storing encrypted passwords if a node was down in the error file. This issue is encoded passwords being sent, android and website don't do this. So this is likely a developers version that was uploaded to track on their side.

Zappl is in beta and the ios app just came out there hasn't been much testing of the application. More than one of the apps in the community have had security issues as well so. This isn't just a Zappl issue other applications that have had security issues or patches.

Good information,, l like your post @zappl

thanks to Zappl who has shared the latest information, one thing I want to ask Zappl ,, how to share post when zappl app slows down, can we make post in different app to get votes from Zappl.. ? thanks

Thank you for information
You're the best @zappl

This is happen to me when I’m posting last hour

Posting yang sangat bagus dan bermanfaat

I hope you will explain it to us.
Success is always for you, we are waiting for your latest information.

Thank you for the information....

We waiting from zapll the next information

I am happy to follow the development of zappl, hopefully this application can continue to grow for the better and can attract users.
Please prioritize your customer satisfaction zappl ..
Many zappl users who complain with the percentage of votes from zappl, can it be improved?

I hope zappl always protect zappl users, thanks for notification.

Wow, It is very nice

why is there a problem with the encoded password stored on the device???? #zappl

Master, with this issue no effect on user account lock?

Master how this is repeated with a broken password in the app. How do we create discord just to prevent this and we can publicly discord for post users at @zappl

Oke. Thanks for information

@zappl is not working for my apps store @ios. Help how i can to download.

I really appreciate this information, because with the latest information it can lead us to the goal that must be done.thanks zappl

ok @zappl i will do as you say...
Thanks you

Thank you for giving us the information ..
zappl should be growing not to lose with other applications ,,
Currently zappl application is very nice and easy for users, hopefully zappl application not to complicate the user .. that's it.

Thanks you for imformation and I hope you happy everyday @zappl

this may be a big problem the password problem thank you for notifying us.
this information is very important for us who are beginners in zappl. thank you

thAnk infoemation

Very nice your post.. Thank you @zappl

thanks for the info

Mr zappl. I am @muhammadabi. I have a zappl in my phone. But two my post in zappl. No respons why.. sorry lol

Mr zappl. I am @muhammadabi. I have a zappl in my phone. But two my post in zappl. No respons why.. sorry. Just kidding
Screenshot_2018-03-10-11-59-13.png

thank you on the information @zappl it has always been the best.

Looks like a few accounts below this comment are trying to say they're eligible for the blacklist.

thank you on the information @zappl it has always been the best.i like @zappl

thank you on the information @zappl it has always been the best.beautiful post @zappl

thank you on the information @zappl it has always been the best.

thank you on the information @zappl it has always been the best.

thank you on the information @zappl it has always been the best.

thank you on the information @zappl it has always been the best.i like post you @zappl

thank you on the information @zappl it has always been the best.

thank you on the information @zappl it has always been the best.

Thank informations

thanks for telling about it in time

thank you on the information @zappl it has always been the best.

Thanks for the heads up and also the honesty behind this. I had just referred the application to a couple of my Friends who are on iOS. I will ask them to discontinue using the application for the time being, as soon as you give the update, I'll ask them to reinstall.

PS: The Android App Works really great, keep it up.

thank you for the information, hopefully zappl better future.

Thanks for the information updated. That was a great responses. @zappl

i will not use it on ios now but keep us updated

This is crazy. I can't support Zappl if this is how it is going to be.

hopefully this bug is sorted out by now

Oh boy. 😕

FYI, most non-techies will not be able to understand Github. Github is a maze.

This issue wouldn't be reflected in the github, this is a developer build that was installed by mistake.

will try to use android one

Really disappointing that such an issue could happen. Surely this was extensively tested prior to release.

Yes it was but their are multiple builds, and the person in charge didn't check the build before uploading. What was installed is a developer build which has more tracking and reporting features in it than the normal builds. There was a lapse in review from the people who were in charge of uploading the IOS build.

Which will be corrected soon, it may take up to 8 days.

thanks for the latest information, I really appreciate the hard effort of the zappl ,, and I will mention this information to people I know ..thanks

zappl I really like your post great. I have joined in your zappl please accept me as your guest.

Zappl is really going far and their service rendered is also superb to be honest, keep the energy going.

Having said that, I am having issues with @zappl, because I hardly get benefit of upvote from zappl, neither I have I abused it before or used it the wrong way which is not fair. I introduced so many of my brought in users and they have more testimonies on zappl than I am. I don't really know why that they even get up-to $20 while all I get is nothing from you. Is there a better way of knowing how to use zappl than must of us really know or than I know?