By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Gulf PressGulf Press
  • Home
  • Gulf News
  • World
  • Business
  • Technology
  • Sports
  • Lifestyle
Search
Countries
More Topics
  • Health
  • Entertainment
Site Links
  • Customize Interests
  • Bookmarks
  • Newsletter
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Reading: Flaw in photo booth maker’s website exposes customers’ pictures
Share
Notification Show More
Latest News
Construction of Al Nama Hospital in North Al Sharqiyah almost halfway through
Gulf
Saudi Arabia slams attack on UN facility in Sudan
Gulf
Qatar performs strongly in global literacy ranking
Gulf
Talks in Berlin: Will Zelenskyy renounce NATO membership?
World
Jeddah Tower hits 80 floors: Burj Khalifa dethroned soon?
Business
Aa
Gulf PressGulf Press
Aa
  • Gulf News
  • World
  • Business
  • Entertainment
  • Lifestyle
  • Sports
Search
  • Home
  • Gulf
  • Business
  • More News
    • World
    • Technology
    • Lifestyle
    • Entertainment
    • Sports
Have an existing account? Sign In
Follow US
  • Terms
  • Press Release
  • Advertise
  • Contact
© 2023 Gulf Press. All Rights Reserved.
Gulf Press > Technology > Flaw in photo booth maker’s website exposes customers’ pictures
Technology

Flaw in photo booth maker’s website exposes customers’ pictures

News Room
Last updated: 2025/12/15 at 4:18 AM
News Room
Share
5 Min Read
SHARE

A security flaw in photo booth company Hama Film’s website is exposing customer photos and videos, according to security researcher Zeacer. The vulnerability allows unauthorized access to files uploaded from the company’s booths, raising concerns about data security and privacy. The issue was initially reported in October, but as of Friday, a full resolution hadn’t been implemented, prompting further scrutiny of the company’s practices.

Contents
Lack of Response from VibecastThe Importance of Rate LimitingPotential Legal and Reputational Ramifications

Hama Film operates franchise locations in Australia, the United Arab Emirates, and the United States. Unlike traditional photo booths, these booths upload customer images and videos to the company’s servers, offering a digital copy alongside the printed version. This convenience, however, has created a significant security risk.

The Hama Film Data Exposure Vulnerability

Zeacer discovered that the website lacked adequate security measures to protect these uploaded files. Initially, the researcher observed that photos remained accessible for two to three weeks before being deleted. While the retention period has since been reduced to approximately 24 hours, the core vulnerability persists.

This means a malicious actor could potentially exploit the flaw daily to download all photos and videos currently stored on the server. The researcher shared examples with TechCrunch showing images of groups, including young people, taken at Hama Film booths in Melbourne.

Lack of Response from Vibecast

Hama Film is owned by Vibecast, and Zeacer’s attempts to notify the company about the issue have been unsuccessful. Vibecast has not responded to multiple requests for comment from TechCrunch, nor to a message sent to co-founder Joel Park via LinkedIn. This lack of communication is raising further alarm about the company’s commitment to protecting customer information.

The absence of a response is particularly concerning given the sensitive nature of the exposed data. Photo booth pictures often contain personal information and depict individuals in potentially vulnerable situations. The potential for misuse, including identity theft or harassment, is significant.

The Importance of Rate Limiting

This incident highlights a common, yet critical, security oversight: the lack of rate limiting. Rate limiting is a security measure that restricts the number of requests a user can make to a server within a given timeframe. Without it, automated scripts can be used to rapidly access and download data, as demonstrated in this case.

This isn’t an isolated incident. Last month, TechCrunch reported a similar vulnerability affecting Tyler Technologies, a government contractor. Their websites, used for managing juror information, also lacked rate limiting, allowing attackers to potentially compromise juror profiles by brute-forcing personal details. This pattern suggests a broader need for improved cybersecurity practices across various industries.

Experts emphasize that implementing basic security protocols like rate limiting is a fundamental step in protecting user data. These measures are relatively inexpensive and straightforward to implement, yet they can significantly reduce the risk of data breaches and unauthorized access.

Potential Legal and Reputational Ramifications

The exposure of customer data could have serious legal consequences for Vibecast and Hama Film. Depending on the jurisdiction, the company may be in violation of data privacy regulations, such as GDPR or CCPA, which require organizations to protect personal information.

Beyond legal issues, the incident is likely to damage the company’s reputation. Customers may be hesitant to use Hama Film booths if they fear their photos and videos could be compromised. Restoring trust will require a transparent and proactive response from the company, including a thorough investigation and implementation of robust security measures.

The incident also underscores the growing importance of responsible data handling in the entertainment and leisure sectors. As more businesses collect and store customer data, they must prioritize security to protect against potential breaches and maintain customer confidence.

TechCrunch has chosen to withhold specific details of the vulnerability to prevent further exploitation while Vibecast addresses the issue. The researcher, Zeacer, continues to monitor the situation and has indicated that the problem is not fully resolved.

The next step will be to see if Vibecast responds to the continued reporting and takes concrete action to secure its servers. A reasonable deadline for a full resolution would be within the next week, but the company’s silence to date introduces significant uncertainty. Observers will be watching closely for any announcements regarding a security patch and a notification plan for affected customers.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
I have read and agree to the terms & conditions
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
News Room December 15, 2025
Share this Article
Facebook Twitter Copy Link Print
Previous Article Al Mudhaibi Health City inks MoU with UTAS in Ibra
Next Article Jeddah Tower hits 80 floors: Burj Khalifa dethroned soon?
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

235.3k Followers Like
69.1k Followers Follow
56.4k Followers Follow
136k Subscribers Subscribe
- Advertisement -
Ad imageAd image

Latest News

Construction of Al Nama Hospital in North Al Sharqiyah almost halfway through
Gulf December 15, 2025
Saudi Arabia slams attack on UN facility in Sudan
Gulf December 15, 2025
Qatar performs strongly in global literacy ranking
Gulf December 15, 2025
Talks in Berlin: Will Zelenskyy renounce NATO membership?
World December 15, 2025

You Might also Like

Technology

Home Depot exposed access to internal systems for a year, says researcher

December 15, 2025
Technology

Retro, a photo-sharing app for friends, lets you ‘time-travel’ through your camera roll

December 14, 2025
Technology

Google Translate now lets you hear real-time translations in your headphones

December 14, 2025
Technology

Trump’s AI executive order promises ‘one rulebook’ — startups may get legal limbo instead

December 14, 2025
Technology

Data breach at credit check giant 700Credit affects at least 5.6 million

December 14, 2025
Technology

Netflix growing up, data center jet engines, and the circular AI economy

December 14, 2025
Technology

Microsoft buys 3.6M metric tons of carbon removal from bioenergy plant

December 14, 2025
Technology

OK, what’s going on with LinkedIn’s algo?

December 14, 2025
//

Gulf Press is your one-stop website for the latest news and updates about Arabian Gulf and the world, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of ue
  • Advertise
  • Contact

How Topics

  • Gulf News
  • International
  • Business
  • Lifestyle

Sign Up for Our Newsletter

Subscribe to our newsletter to get our latest news instantly!

I have read and agree to the terms & conditions
Gulf PressGulf Press
Follow US

© 2023 Gulf Press. All Rights Reserved.

Join Us!

Subscribe to our newsletter and never miss our latest news, podcasts etc..

I have read and agree to the terms & conditions
Zero spam, Unsubscribe at any time.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?