
Please Don't Download "TeaOnHer"...
Source: YouTube · SomeOrdinaryGamers · published Aug 14, 2025 · 18:42
The video exposes severe security vulnerabilities in the Tea app and Tea on her, dating apps that collect users' personal identification but fail to protect it from hackers, resulting in massive data breaches 0:00-0:49.
Key Takeaways:
• Tea on her is the male version of the Tea app, requiring users to submit driver's licenses, passports, or other IDs along with selfies, just like its predecessor 1:58-2:25.
• Security researcher Zach Whitaker from TechCrunch discovered the app's API was completely unprotected, allowing anyone to access and download users' personal identification documents 5:09-6:28.
• The app's administrator used an extremely weak password "Password1=sorry!" demonstrating poor security practices throughout the application 9:03-9:12.
• The creator suggests the app may have been "vibe coded" (created with AI tools without proper security review), explaining the numerous vulnerabilities 15:57-16:11.
These apps exemplify the dangers of providing personal identification to unvetted applications, especially when developers lack basic security knowledge and platforms like Apple fail to properly review apps that handle sensitive data 16:15-17:04.
Sources:
- 0:00-0:49 Introduction to Tea app and Tea on her apps with security issues
- 1:58-2:25 Tea on her app requiring ID verification
- 5:09-6:28 Security researcher's findings on unprotected API
- 9:03-9:12 Administrator's weak password
- 15:57-16:11(https://www.youtube.com/wat
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Hello guys and gals. Me Mudahar and you know two weeks ago I looked at an application called the tea app. Now for anybody that doesn't remember the tea app was effectively this little dating check app that women were downloading so they could talk unfiltered stuff about any of the red flag men that they could find in the world. Now obviously I I talked about this application. I I looked into its terms of services and I want to be completely real with you ladies and gentlemen. I think that it is a landmine of of litigations that could happen. Obviously, the biggest thing that came out of it was in pretty much record time, the actual application seemed to be hacked and there was a lot of information that leaked out. 4chan had gigabytes upon gigabytes of people's uh, you know, driver's licens…