© 2025 Connecticut Public

FCC Public Inspection Files:
WEDH · WEDN · WEDW · WEDY
WEDW-FM · WNPR · WPKT · WRLI-FM
Public Files Contact · ATSC 3.0 FAQ
Play Live Radio
Next Up:
0:00
0:00
0:00 0:00
Available On Air Stations

Snapchat And Dropbox Breaches Are Really Third-Party-App Breaches

Snapchat's logo.
Carl Raether
/
Flickr
Snapchat's logo.

What can get lost in a flurry of news about Dropbox and Snapchat getting hacked is that the companies themselves deny they were hacked at all.

They're not lying. Technically speaking, Dropbox's servers did not get breached. Snapchat's didn't either. Photos and log-in credentials apparently leaked from third-party sites or apps that piggyback on these services.

What are third-party apps? They are services that exist outside a parent program, say, Snapchat. But these services rely on the code base of the parent and add functionality to the main service.

For instance, the third-party site that leaked the Snapchat photos was called Snapsaved.com, and it did what Snapchat did not — allow you to save photos sent through the service. In a Facebook post, Snapsaved said it itself was hacked and that it deleted its website as soon as it discovered the breach.

These third-party apps are everywhere. TweetDeck was originally a third-party app based on Twitter, until Twitter bought it. If you're a Flickr user, there are a number of "home-grown applications" based on that photo-sharing service.

But they can be easier targets for hackers than their parent software programs. So keep that in mind when you use third-party apps. Snapchat, for its part, reminded users that it discourages the use of third-party apps like Snapsaved and in a statement reiterated that such apps violate its terms of use.

In a blog post, Dropbox told its users that their data were safe. It urged them "not to reuse passwords across services" and recommended they enable two-step verification.

Some question whether Snapchat's API, which is an electronic manual of sorts that lets computer systems talk to each other, is just too easy to hack. If that's the case, then the blame for this breach can in some ways be put at the foot of Snapchat itself.

There are ways software companies lock down their systems to ensure greater security, but recent experiences with some third-party apps indicate that wasn't happening.

Update on Wednesday, Oct 12 at 5:31p.m. E.T.: A Dropbox spokesperson says the stolen logins were a result of users who use the same passwords and sign-in credentials across several sites — not a breach of any specific third-party apps.

Copyright 2021 NPR. To see more, visit https://www.npr.org.

Elise Hu is a host-at-large based at NPR West in Culver City, Calif. Previously, she explored the future with her video series, Future You with Elise Hu, and served as the founding bureau chief and International Correspondent for NPR's Seoul office. She was based in Seoul for nearly four years, responsible for the network's coverage of both Koreas and Japan, and filed from a dozen countries across Asia.

The independent journalism and non-commercial programming you rely on every day is in danger.

If you’re reading this, you believe in trusted journalism and in learning without paywalls. You value access to educational content kids love and enriching cultural programming.

Now all of that is at risk.

Federal funding for public media is under threat and if it goes, the impact to our communities will be devastating.

Together, we can defend it. It’s time to protect what matters.

Your voice has protected public media before. Now, it’s needed again. Learn how you can protect the news and programming you depend on.

SOMOS CONNECTICUT is an initiative from Connecticut Public, the state’s local NPR and PBS station, to elevate Latino stories and expand programming that uplifts and informs our Latino communities. Visit CTPublic.org/latino for more stories and resources. For updates, sign up for the SOMOS CONNECTICUT newsletter at ctpublic.org/newsletters.

SOMOS CONNECTICUT es una iniciativa de Connecticut Public, la emisora local de NPR y PBS del estado, que busca elevar nuestras historias latinas y expandir programación que alza y informa nuestras comunidades latinas locales. Visita CTPublic.org/latino para más reportajes y recursos. Para noticias, suscríbase a nuestro boletín informativo en ctpublic.org/newsletters.

The independent journalism and non-commercial programming you rely on every day is in danger.

If you’re reading this, you believe in trusted journalism and in learning without paywalls. You value access to educational content kids love and enriching cultural programming.

Now all of that is at risk.

Federal funding for public media is under threat and if it goes, the impact to our communities will be devastating.

Together, we can defend it. It’s time to protect what matters.

Your voice has protected public media before. Now, it’s needed again. Learn how you can protect the news and programming you depend on.

Related Content