"CMF/Nothing's student referral program is not secure, and you can find user data of the referee through its API, including:
- first/last name,
- phone number,
- email,
- address and area
CMF's referral program allows you to make a code, which you can share to earn points. At the end of the program, the top 50 on the leaderboard will win CMF by Nothing products.
Besides the obvious security issue, referral programs have a problem, since people sharing links may not want you to purchase the best product, as they're incentivized with receiving products themselves.
Update: Nothing has silently taken the website down, but just like with their agency shenanigans, it's likely that we won't get any apologies or clarification, and the company will wait until this whole thing dies down.
https://x.com/cartidise/status/1809902007089512841"
- (https://t.me/nothingfuckups/311)
#Nothing #CMF #NothingCompany #SecurityIssue