11 ms·
How to boost your popularity on OkCupid using CSRF and a JSON type confusion
- ctoth 5y ago> It also occurred to me that if I redirected my website to the CSRF link that automatically sent a message to me, I could see the OkCupid profiles of my website visitors who were logged into okcupid.com, which would make for an intense web analytics tool. Ouch.
- llampx 5y agoThe Data Protection Agency loves this weird trick!
- Teever 5y agoI learned recently that if someone forwards you the email that OKC sends them alerting them to a new message and you click on it you gain passwordless access to their account. I contacted OKC about this but they said that it was not an issue.
- nicoburns 5y agoThis isn't ideal, but why would anyone forward this kind of email?
- thih9 5y agoI guess when an adversary knows about the feature and uses some social engineering against the user?
- EpicEng 5y agoIn order to get access to their... OkCupid account? Not sure that I care.
- kfrzcode 5y agoEveryone's got something to hide somewhere.
- wizzwizz4 5y agoImagine https://www.wired.com/2017/01/grinder-lawsuit-spoofed-accounts/ https://www.wired.com/2017/01/grinder-lawsuit-spoofed-accoun..., without the spoofing.
- Johnny555 5y agoYou might care if you were married and using OKCupid to find a girlfriend. You may say that getting exposed for trying to have an affair is a good thing, but that's a still a reason why someone may care how secure their OKCupid activity is.
- shakna 5y agoCertain sexual behaviours are outlawed in certain nations. And may result in death or long incarceration times. In other nations, it may not be strictly illegal, but is more than enough information that, if publicly released, would result in death threats and other social pressures.
- entropicdrifter 5y agoThe email itself could be intercepted, could it not?
- Johnny555 5y agoI might forward it to a friend to ask if that's the girl he dated last week, without meaning to give him passwordless access to my account.
- jmnicolas 5y agoA good way to know if he is really your friend ;)
- DJBunnies 5y agoLots of sites do this, it’s a feature for the majority of users who prefer convenience over security.
- cmckn 5y agoI find that passwordless links usually expire after 1 use or some amount of time; generating eternal alt-passwords for an OkCupid account in every message notification email seems pretty heinous.
- AlchemistCamp 5y agoGmail now pretty much breaks single-use tokens in links because it consumes them itself after a user clicks on them, but before redirecting the user to the site. It's an unfortunate change that has made single-use links a worse UX and less popular in the last couple of years.
- gbl08ma 5y agoThis sounds like it would break a bunch of email address verification systems, password recovery links and the like. I wonder if indeed it does break them, but since it only affects smaller websites nobody seems to care.
- AlchemistCamp 5y ago> "This sounds like it would break a bunch of email address verification systems, password recovery links and the like." This is exactly the pain I've experienced with my own site, https://alchemist.camp https://alchemist.camp I've manually tested it and seen the token consumed when clicking the link via gmail but had no issues when copying the link from the password reset email to a gmail account. A second manual tester confirmed the same, as have multiple support cases. Password recovery links sporadically fail for gmail users. I had to add extra instructions to copy and paste rather than click through the link and am in the process of moving away from single-use tokens because a lot of people still click before reading those instructions and email me for support. My increased customer support burden isn't something Gmail PMs worry about, but they may whitelist some larger service's emails.
- simonw 5y agoThat's shocking! Really surprised that they don't see this as an issue, I would expect that it's trivial to social engineer someone into forwarding you one of those emails.
- AnIdiotOnTheNet 5y agoMaybe, but how much value is there in taking over people's OKCupid account?
- rootsudo 5y agoYou'd be surprised, alot - but I'd wager it's easier to just save the photos and open up your own honeypot that way. But the messages could be interesting.
- rendall 5y agoSomeone I knew once sent me an urgent direct message over Twitter that they were stranded in the City of London and needed me to wire money. Phone gone, computer stolen, they could only communicate by Twitter. Of course it wasn't actually my friend, but a 2-bit hacker. But if they were to collect enough accounts and message enough people, someone might bite. Maybe someone would give up something truly valuable if they really thought it was someone they cared about, a long lost son, or a pined-for ex.
- kfrzcode 5y agoThe value is relative to motivation, I'd posit
- Johnny555 5y agoIf there's no value or downside to someone taking over my OKCupid account, why have a password on it in the first place?
- yunohn 5y agoThis is a horrible take, obviously there’s different levels of security and risk associated with everything.
- PicassoCTs 5y agoThey might be security wise rather weak, but their statistics blog is a brutal-beautiful view into what humans search for dating. https://theblog.okcupid.com/tagged/data https://theblog.okcupid.com/tagged/data
- monkeybutton 5y agoOne of the founders published an excellent book that is an extension of the blog: https://www.goodreads.com/book/show/21480734-dataclysm https://www.goodreads.com/book/show/21480734-dataclysm
- quacked 5y agoWhat people say they sort on: personality, values, morals, political views, friendships, etc. What people sort on when they don't think they're being observed: genes
- OminousWeapons 5y agoI'm pretty sure 99% of people would openly agree that physical attraction is a core element of partner selection.
- xiphias2 5y agoNot anymore, but before online dating people were hiding it much more
- OminousWeapons 5y agoPeople were trying to hide that they actually want to be sexually attracted to their partner?...
- xiphias2 5y agoTo me (a not attractive man) yes. But I'm from Eastern Europe, the culture is different there.
- the__alchemist 5y agoAnecdote: OkCupid is the only website or app where I've had an account hijacked. I got it back with a password reset, but the profile and pics were filled with bogus content.
- jacquesm 5y agoThat's what I would say too ;)
- spywaregorilla 5y agoAny idea what the intent was?
- Blankenface 5y agoNot the person you're replying to, but: probably to use the account to romance-scam other users with.
- m0rti 5y agoI had the same experience. My profile was transformed into a 50-year-old white male wearing a trucker hat without my knowledge. By the time I was able to access my account, it had a bunch of matches and messages from 50-60 year-old American women.
- ftio 5y agoSo how'd your dates go?
- IgorPartola 5y agoAs someone who used to be so want active on the site and even tried out their paid subscription, I had the features of the paid subscription for years after I canceled my membership. They finally caught it and disabled them but it was pretty clearly a bug.
- filoleg 5y agoIs it just me, or the images on the post are not loading? Initially I tried on the most recent FF, and about half the images were not loading. Refreshed the page, no images were loading after that at all. Then I tried on the most recent Chrome, images were not loading at all either. If someone has a workaround, please let me know. I have confirmed that adblocker and such were all disabled. Upon trying to access the images directly, I got this 403 error: > Your client does not have permission to get URL /u/0/d/<rest-of-the-URL> from this server. (Client IP address: <my-ip-address>) > Rate-limit exceeded. That’s all we know.
- darknavi 5y agoNot just you. On Edge Chromium and no images are loading.
- digitcatphd 5y agoThis is so HN lol
- matsemann 5y agoWould relying on CORS still work as long as the server checks that the type is actually application/json? Since those headers are impossible to set from a form, and doing it with fetch it would trigger a preflight request.
- amenghra 5y agoHistorically, it would have been weak since Java/Flash gave you more control over sockets than what’s available with js. In today’s world, it might be ok. I would personally build defense in depth and not just rely on one weak property.
- skohan 5y agoThis may be my favorite headline I have ever seen on Hacker News
- hmsimha 5y agoI believe this also requires that OKCupid has not set the 'SameSite=lax' attribute on their cookies, which is good practice as well; the browser won't send the user's cookies on cross-origin POST, PUT, PATCH, or DELETE requests when this attribute is set. So this exploit is really the confluence of failing to follow 2 standard security practices, as well as another unfortunate configuration quirk: - Failing to set SameSite=lax on their session cookie attribute - Not using a CSRF token to authenticate on unsafe HTTP actions - Not checking the content-type of API requests (though I'm not sure to what extent this is considered bad practice)
- simonw 5y agoI thought most modern browsers behave as if SameSite=Lax automatically these days. Were OkCupid deliberately setting SameSite=None on their cookies?
- k__ 5y agoWasn't lax just for static assets like images that are linked in external HTML?
- simonw 5y agoYes it was - "... are sent when a user is navigating to the origin site" https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Set-Cookie/SameSite#lax https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Se...
- nonameiguess 5y agoI have no idea if OkCupid still does this, but they used to segment their users based on attractiveness ratings. At first, I think it was solely just literally your attractiveness rating. They had a feature where you could rate people 1-5 stars and if you were in the top 50% of all rated users, you'd only see other people in the top 50% in your search results. If you were lower 50%, you'd only see people in the lower 50%. I think they eventually made this more sophisticated by augmenting the explicit average star rating with other measures of engagement like how often people saved your profile, how many messages you received, and the rate at which your own messages were answered. Something like this could have been valuable to get you into the upper tier.
- Decker87 5y ago> Something like this could have been valuable to get you into the upper tier. Only valuable until people view my profile picture.
- kbenson 5y agoOh, someone that knows what they're doing photographically can help quite a bit there. A good professional portrait photographer has probably forgotten more tips and tricks to do with posing and lighting than the average Instagram professional ever knew.
- OJFord 5y agoAnd then what? You score the date and rely on your awesome personality to make up not only for being physically disappointing, but having to some degree lied about it via a professional portrait photographer's tips and tricks? And if all that works, you found someone who liked the look of a fake/augmented version of yourself, but whom you persuaded to like the real self anyway... Congratulations?
- mastazi 5y agoI think sometimes having a foot in the door helps anyways. Of course grossly misrepresenting yourself is a bad idea but enhancing a bit, why not? Also, it is indeed possible that your potential partners may value other aspects besides your appearance, not everyone is obsessed with looks. But of course your mileage may vary depending who you met in your life, and also based on where you live / local customs etc. Then there is the issue of how you perceive yourself, when I was in my 20s and 30s I used to think of myself as not attractive, but now when I look back at my old photos from a more detached point of view, I think I was a fairly attractive young man. Excessive self criticism can be bad and artificially put you down. After entering a "serious" relationship and then getting married in my 30s I was able to look at myself in a more balanced way. I think my previous self-criticism was fuelled by some vague fear that I would never find a partner and I would live a lonely life. Probably it's a common thought among people of that age.
- bellyfullofbac 5y agoAh, more than a decade ago I found a similar issue on Friendster (anyone remember them?), I could embed an HTML image tag in my profile which loaded a PHP script (under my control) that would redirect the user to something like friendster.com/poke?id=[my user id], so if anyone visited my profile, their browser would GET that URL and I'd get a "poke" (I don't remember the Friendster term for it), notifying me who visited my profile. I didn't get many pokes, and I can't tell what part of this story is the saddest. Maybe the part that there probably weren't bounties back then (that I was aware of) and I didn't get any money for this discovery.
- mellosouls 5y agoReminder of the classic "Mathematician Hacks OkCupid" story from a few years back: https://www.wired.com/2014/01/how-to-hack-okcupid/ https://www.wired.com/2014/01/how-to-hack-okcupid/
- vmception 5y agoIntriguing! I have a friend that did a web scraper on OK Cupid several years before that article, perhaps 2009, based on the same idea: people can see when you looked at their profile or something. He didn't optimize much beyond that and wasn't meeting people he considered attractive, he just wanted to have an additional pool of meetings and volume of hookups, which was successful. Both he and the author of this story were able to warp the male experience in order to have many messages from women to sort though. I find this one interesting as the author here was actually looking to have a relationship, and eventually proposed and removed himself from the pool. I hadn't seen anyone do a data driven approach for that. 88 first dates though, a lot of effort. I'm somewhat familiar with LA, haha its sad he cut out the women from the east side due to distance because he's normally around UCLA. The east side women sounded pretty fun, younger, unencumbered but having suboptimal living environments. Which sounds about right for Los Angeles. Makes me kind of want to ponder if anyone has done two apartments in LA, westside and downtown.
- SahAssar 5y agoAs the author mentions, simply validating the content-type would have been enough. CSRF is generally not a problem if you validate content-types and/or use SameSite for cookies, both of which have been recommended for years.
- yonran 5y ago> Luckily the W3C deities gave us exactly such a gift in the form (pun intended) of the enctype attribute. Minor quibble: enctype="text/plain" didn’t come from W3C. HTML 4.0 forms only defines enctype="application/x-www-form-urlencoded" (which pct-encodes the json delimiters {"":}) and enctype="multipart/form-data" (which has a non-json Boundary prefix) so if those were the only enctypes that browsers used, then this exploit would not have worked. https://www.w3.org/TR/html401/interact/forms.html#h-17.13.4 https://www.w3.org/TR/html401/interact/forms.html#h-17.13.4 WHATWG HTML5 does define enctype="text/plain" behavior https://html.spec.whatwg.org/multipage/form-control-infrastructure.html#form-submission-2 https://html.spec.whatwg.org/multipage/form-control-infrastr.... According to the mozilla docs, it was “Introduced by HTML5 for debugging purposes.” https://developer.mozilla.org/en-US/docs/Web/HTML/Element/form#attr-enctype https://developer.mozilla.org/en-US/docs/Web/HTML/Element/fo... But I doubt it was created by WHATWG either; in 2004 the HTML5 editor Ian Hickson said “I agree it is brain-dead (it's IE-compatible)” https://lists.w3.org/Archives/Public/public-whatwg-archive/2004Jun/0395.html https://lists.w3.org/Archives/Public/public-whatwg-archive/2... Unfortunately I can’t see history of the spec before 2006 though https://github.com/whatwg/html https://github.com/whatwg/html
- runbathtime 5y agoIs this a type of inflation or a type of fraud or neither? Popularity is a made up category, or one that is ill defined while being manipulative. Popularity implies those most desired, but since this can be goosed by paying for attention, it is meaningless and hence let the hacking begin.
- vmception 5y ago> I found you could use essentially the same vulnerability to get other users to “like” your profile. Obviously you could abuse this in order to match with anyone you could trick into clicking a link, or you could spam the link to a bunch of people to increase your profile’s rankings in whatever mysterious algorithm OkCupid uses to suggest people. Ha! They should have used this to increase their evolutionary fitness! Assumptions about matchmaking app algorithms are the crux of my behavior on dating apps. Far far greater influence than other users independent impression of my profile or me trying to put a best foot forward.
- NewEntryHN 5y agoDo people use OkCupid on the browser?
- LAC-Tech 5y agoHaven't been single for a while - is OK cupid still a thing? I thought everyone used Tinder now.
- Blankenface 5y agoSort of. The thing is, a truly massive number of dating sites are owned by Match Group, which used to be part of IAC. Bumble and Coffee Meets Bagel are two examples of major non-Match-Group companies.
- Epenthesis 5y agoMy impression as a 30 year old het guy in SF is that the big 3 are Tinder/Bumble/Hinge, roughly sorted in order of "casual" to "serious relationship". According to friends, OkCupid seems to be baaarely limping along in queer/poly circles.
- nuker 5y agoBusiness model is not letting you find your person, because if you do they lose a paying customer. Thats my thinking and why I’m not using dating websites.
- polishdude20 5y agoI was talking about this exact thing with my girlfriend the other day. Tinder and other dating sites want you to stay as long as possible and spend as much money as possible with them. How do you do that? Number one: You give them hope. Give people hope that they will find the person they are looking for if they stay on longer. Give people hope by helping facilitate a match just as they start to lose interest in the website. Make them think they will find someone. Number two: Cultivate a culture of attractive people. Keep the attractive people staying. This gives hope for the unattractive people as they sometimes match with them. Keep the attractive people happy and help facilitate lots of meetings or them. Number three: Provide an easy way to skip the whole attractive/unattractive hierarchy by letting people spend money. Now you too can get in on the action (but not for too long) if you have the money. I realize this is a pessimistic view of dating sites. Heck, I met my current girlfriend of three years on OkCupid luckily. It's not all doom and gloom.
- nuker 5y ago> It's not all doom and gloom. Yep. They need it to work sometimes to stay competitive vs other websites. I guess it works as lottery draw, give only these 100 a proper match today
- joshfraser 5y agoGood to raise awareness as this issue has tripped up some of the biggest websites on the internet. I actually reported the exact same issue to amazon.com a few years ago. At one point it was possible to trick visitors into purchasing anything you wanted on amazon.com, including fake products you listed yourself or gift cards that you could send anywhere you wanted!
- SergeAx 5y agoThis would be unable if OkCupid stored its credentials in sessionStorage or localStorage instead of cookies, right?
- amenghra 5y agoWith modern browsers, there are almost a dozen ways to defend against csrf. You can use sessionStorage and force all requests to be XHR. Set the “new” flag on session cookies to not transmit cross origin. Check the origin header for all POST requests. Set a token in the forms (the “classic” way).