7 ms·
Plenty of Fish Hacked
- fleitz 16y agoPlenty of Fish? Might as well rename it plenty of passwords. The worst part is Markus stores his passwords in plaintext, or slightly better reversible encryption. POF will mail a person their password. This is a security nightmare because basic precautions were not taken. I just checked and POF is still able to reproduce and email me my password. I also checked the email I use for POF and there is no mention of this in any of their emails. If markus took this seriously at all he'd be resetting everyones password and have instructions to reset their email password. "We have reset all users passwords and closed the security hole that allowed them to enter." This is a lie, I just logged in with my username and password. I wasn't even asked on login to change it.
- AgentConundrum 16y agoIt's actually worse than that. I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remembered to kill the account a few months back), but back then they would actually send you reminders every so often - I want to say once a week - that included your plain text password as a reminder. I think this is just the kick in the ass I needed to go through all my accounts around the internet and make sure they all have unique, reasonably complex passwords. My email and banking passwords have always been unique, but I know I've been slack elsewhere. I won't let that happen again.
- jacquesm 16y agoIf there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I have to use my chipcard in a little electronic device with an LCD display and a bunch of buttons on it, the chipcard generates a unique ID every time I log in. When I want to do an actual transaction I have to authorize it using 1, 2 or 3 challenges depending on the amount and destination of the transaction. It's less convenient than a password protected system but it's fairly secure. It's also protected against the most common form of theft called 'skimming' because it uses the chip and not the magnetic stripe so a thief using the data on a skimmed card could only use that to use an ATM but not to access the internet banking section of the website of my bank.
- AgentConundrum 16y agoAre you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me. I guess that's something, although I really don't know the exact circumstances that trigger the challenge.
- statictype 16y agoOdd. It seems like almost every big bank in Asia has them by now. I would have thought their use is widespread world over.
- jacquesm 16y ago> Are you European? Yes, working from NL at the moment. > Unfortunately, such a thing seems all but unheard of here in Canada. That sucks! > Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. Ok. > I have noticed that when I login from a new computer (for example, when I visit my parents), the site uses one of my challenge questions to ensure it's really me. So the bank likely either keeps a record of 'known' IP addresses for you or they keep a cookie on the computer that they use to identify a computer that you've used at least once. How annoying. It's interesting how we berate POF for not following 'best practices' but even institutions such as banks could do a whole lot better to protect their and their customers best interests. Are you liable for fraud committed with your account online? Or would the bank indemnify you if your password were used to clean out your accounts?
- AgentConundrum 16y agoAre you liable for fraud committed with your account online? Or would the bank indemnify you if your password were used to clean out your accounts? Honestly, I have no idea. I really should look into the fine print in the online TOS/Rules&Regs.
- healthyhippo 16y agoIts really ridiculous how many sites still store passwords that way. SurveyMonkey still sends forgot password requests in plaintext email. You'd think with $100M of funding they'd have sorted that out by now.
- grumo 16y agoIt is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS, hmm maybe?
- mahmud 16y agoWhat do you mean "young"? 12 year olds have broken into more sophisticated systems.
- grumo 16y agoYoung compared to me for sure
- fleitz 16y agoGrumo media looks pretty cool. Maybe you shouldn't regret it? I'm doing a startup in Vancouver as well. Your videos look awesome but are out of my current budget. :(
- domino 16y agoI just checked your profile, do you also do iPhone apps? We're a cool startup in Vancouver and we're looking for help with our iPhone development, maybe we can chat
- alnayyir 16y agoI'll ignore the issues with the plaintext/reversible passwords since that's a trope that has been bandied about enough lately and ask if anyone has technical details on the hack itself, I'm quite curious if it was a simple SQL injection or something more artful. I'd tend to lean towards injection, given that it took Russo (apparently?) 2 days to produce a working exploit with what amounts to fiddling around, but if anyone knows where I can read a write-up on it I'd appreciate it. (Professional curiosity, I'm a web dev and like to be apprised of what catches the more popular sites. Sometimes you get lucky and it's subtle/neat.)
- ivanstojic 16y agoThe fact that a well known site like POF was hacked is eclipsed by the fact that they both store unencrypted passwords, and the bizarre tone of this article. I managed to stumble through the first part of the article, but lost interest when Russo claimed that "he can see what the Russians are doing because they took over his computer." This sounds technologically implausible at best. Maybe the official post in the morning will make more sense.
- benohear 16y agoIs it implausible? Could you not set up some kind of honeypot machine and then monitor it's activity once it's been zombie'd? (Genuine question - I'm definitely no expert on the topic).
- ivanstojic 16y agoCertainly! That part alone is not only plausible, but also quite common. Antivirus companies, security researchers and various other interested parties have been known to use such tactics. However, it doesn't make sense then those who hacked his supposed honeypot would be aware of his oversight ("they are trying to kill him"), while still using the honeypot to perform whatever illegal shenanigans they were up to ("they are currently downloading plentyoffish’s database").
- palish 16y agohttp://www.realvnc.com/ http://www.realvnc.com/
- mahmud 16y agoThis is extortion, plain and simple.
- cubicle67 16y agoif you read grumo's comment http://news.ycombinator.com/item?id=2160916 http://news.ycombinator.com/item?id=2160916 you'll see it's not quite that simple [edited to fix name. sorry 'bout that, been a long day]
- grumo 16y agoThanks cubicle67, it is "grumo" instead, no worries.
- JoachimSchipper 16y agoFrom Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump. Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to extort money from a company by dangling a dump of their customer database.
- jacquesm 16y agoThat's a technicality in my opinion. If the website owner would ask you to fix it that would be one thing, to hack them and then to 'offer to fix it' (presumably for a fee) is across the line. It's a fine one but it's definitely there. Hacked a site? Send them a message about it, give them time to respond and time to fix. If they don't respond after a reasonable time has passed go public with it, don't try to translate it in to paid work.
- JoachimSchipper 16y agoTrying to turn a PoC into paid work is indeed sketchy; but I do understand that security researchers/whitehat hackers would like to get paid for their work. It would be good if more companies set up bug bounties, and even better if they'd set the reward a bit closer to (reputed) black-market prices.
- zackattack 16y agoThis is why my pof passwords are always some variation of "zachary" (with some numbers appended).
- JoachimSchipper 16y agoYou're just asking for a "disregard that, I suck cocks" now.
- JoachimSchipper 16y agoApparently the above is unpopular - I was just trying to point out that posting your password (or enough of it that one could bruteforce the rest) has its downsides.
- credo 16y agoRelated, but slightly off-topic. When I read this post on my iPhone, I saw a match.com ad on the top of the page. match.com competes with Plenty Of Fish. POF is a multi-million dollar business. I'm surprised that they aren't paying Wordpress to provide an ad-free experience.
- gaius 16y agoPOF is entirely funded by ads from paid-for dating sites. It's a weird business model, but it seems lucrative.
- StormN 16y agoNo, it's not. They have a large(ish) self-serve advertising platform like FB with various levels of targeting.
- mikecolella 16y agoA huge percentage of the ads served on the self serve platform are affiliates promoting other dating sites.
- nowarninglabel 16y agoI wonder if Markus realizes that e-mails have been going out non-stop to customers lately from spam profiles using their 'wants to meet you' "feature". On the one hand, I feel bad for PoF becoming the target of an attack and drama, but from the tone of the post, it wasn't handled right on their side either. PoF really needs to get its act together on the security side. It's sad to because it was a fairly well executed concept when it first arrived on the scene, and has since just turned into what amounts to a spam/ad farm.
- jarin 16y agoAs the lead developer on a dating site myself, I can say that it's ridiculously hard to keep out spam profiles. We block by country, Project Honeypot entries, and HTTP header profiling, use captchas, and use other bot-sniffing tricks, but in the end we still have to manually ban IP addresses every day. We don't store passwords in plaintext though, sheesh. Edit: I just upgraded the hashing algorithm on the site from SHA1 to Bcrypt. Paranoia for the win.
- leon_ 16y agoAnd then he posts it on HACKER news?
- dannyv 16y agoChris Russo says he didn't dump any data. http://plentyoffish.wordpress.com/2011/01/31/plentyoffish-hacked/#comment-119001 http://plentyoffish.wordpress.com/2011/01/31/plentyoffish-ha...
- Tichy 16y agoI read "closed the security hole", but I never read "reinstalled everything from scratch using clean data sources" - isn't that what he should have been doing? I still feel icky because of the sourceforge hack and wonder if I should reinstall everything. I probably should :-(
- grumo 16y agoJust got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-explains-how-he-did-it/ http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...
- anthonyb 16y agoWhile we were creating the legal documents in order to proceed, Markus Frind got progressively more aggressive and unresposive with us, and told us to speak with their employees, Kate and Jay, because there was a serial killer, murdering people from the website. If you ask me, both of them sound crazy and deluded. Marcus' story doesn't make much sense if you read the email on that site[1], but carrying on about serial killers doesn't help your case much either. And that freelancer link is just a red herring - I can't see what it's got to do with the case at hand. [1] Update: Or even if you read his own post: "I listened in the background and I closed the breach if indeed there was one while my wife was on the phone". Er, was there a breach or not? And why are you calling his mother and not the police?
- grumo 16y agoI just spoke directly with Chris Russo over Skype. He is extremely upset about the whole situation. I don't want to put any words on his mouth. He tells his own version of the events on the link above which he allowed me to post on his behalf.
- deleted 16y ago[deleted]
- mahmud 16y agoMate, before you milk that 'interview' for eye-balls, just go back to the PoF article above and read the new comments. Chris Russo is there commenting, and it calls your ability to judge character into question. For starters, he has never denied the story about Russians holding his computer hostage and threatening to kill him. He just ignored it. Then he goes for the "race" card and says PoF are suspicious of his intent just because he is in Argentina.
- 16y ago
- chegra 16y agoWhy does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish? -http://grumomedia.com/plenty-of-fish-hacked-chris-russos-explains-how-he-did-it/ http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp... 1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible. 2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor, Chris story sounds more realistic. He saw a flaw and reported it. Everything was going dandy until he saw ads for Plenty of Fish data. At this point Mark decides to try ruin Chris by fabricating a story, since he believe it is him trying to sell the data. It is a simpler story. 3. Why isn't Mark contacting the authorities? - A week and Chris is not in jail and responding freely on his blog? Mark does have some valid points though,he did hack pirate bay: http://torrentfreak.com/the-pirate-bay-hacked-users-exposed-100708/ http://torrentfreak.com/the-pirate-bay-hacked-users-exposed-... But Chris claimed again, proof of concept and he has no bad intentions.[What is the appropriate way to expose vulnerabilities?] In my opinion, he[Mark] should release the voice recording to add more credibility because right now he is sounding shaky.
- StormN 16y agoA key point here is that he didn't use a proxy and doesn't seem to hide his identity during the sniffing around, which means he's either: a) stupid. b) not intending to do anything malicious. I think a. is unlikely, because he did actually manage to break in, although, the hole itself might've been trivial and therefore this might not count. I don't think so, though. Which leaves b.
- notahacker 16y agoI think it's pretty obvious from both sides of the story that what Chris intended to do was (c) demonstrate the existence of a vulnerability in order to hard-sell his security consultancy. Reading between the lines, it looks like his sales tactics were heavy on the FUD (he pointedly hasn't denied making any claims about Russian conspiracies), leaving Frind paranoid and angry. And probably also embarrassed if the security flaws were as basic as is being suggested.
- TheBranca18 16y agoI'm on plentyoffish and they do weekly send you your password in plaintext (there are plenty of other sites that do this). Thankfully I change my passwords each month to a random string of 12 characters and don't really care. Perhaps if hackers get into my account, my account can finally get a date!
- ZoFreX 16y ago> Perhaps if hackers get into my account, my account can finally get a date! No, you have to wait for OKCupid to get hacked for that to happen.
- simonhamp 16y agoWouldn't surprise me one bit if this all came out as a sham and they were all just in it to get some attention... I mean, who settles things through the blogosphere... come on folks, there is a judicial system!
- enry_straker 16y agoThings can get really stuck - as the protagonistss appear to be on different continents
- jarin 16y agoFrom the TechCrunch article comments: "Roberto Alsina Just a small clarification about this bit: "They then start talking about money because they need to incorporate a company that can deal with companies outside of Argentina and that will cost $15,000. They also needed to know if they were going to make over $100k/year or 500k/year as that would require different registrations…" I am from Argentina, and I own a company. Yes, in order to bill services to foreign customers, you need to register your company as an "exporter of services". And to do that you have to put money on escrow (but not $15000, only $7500), or your company has to demonstrate assets for over $12500. If Russo has been working without an incorporated company (he could be a "monotributista", which is a way to bill as a physical person). A monotributista can export services, but... he's personally liable, so doing security consulting that way is insane. That's probably why Russo could be asking for money up-front: if he didn't, he would have been doing business illegally."
- loboman 16y agoMany freelancers work as monotributistas or responsables inscriptos, exporting services that way. And it's perfectly legal. For a single person shop this would be the first case I hear of, of an incorporate company setup that way.
- ralsina 16y agoYes, it's perfectly legal, but is incredibly stupid in this case because of the liability. If you work on security this way, you are going to get sued eventually. If you are a monotributista or responsable inscripto, you will lose everything. A SRL (like a LLC) is the logical way to handle this kind of work. What I meant by illegally is that it would be illegal if he was already incorporated as a SRL and exporting services (he needs to do the escrow to do that legally).
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- deleted 16y ago[deleted]
- njmanwhore 16y agoI don't understand why the victim of a crime is being given a hard time. Scenario: I own a safe with all my personal information locked inside of it; a Safe Cracker (let's call him...Chris) comes along a cracks me safe. Chris call me as says to me 'yeah, I cracked your safe if you don't hire my company to fix you safe's vulnerability maybe your personal information might get out.' Who is the bad guy in that situation the dope with the safe, with a 1-2-3-4 combination or the guy who takes the dopes information and attempts to use it for his own personal gain. NOTE: To anyone who still thinks the dope is more to blame; please send me your address i'll rob your apartment/house then sell your things back to you (don't worry I'll also sell you new locks).