7 ms·
Fun with your friend's Facebook and Tinder sessions
- teen 12y agoIt's much easier to use the bottinder chrome extension (or whatever it's called now) than dealing with the proxy. Really it's as simple as exporting the cookies, importing them into chrome, and firing up botinder.
- thekingofspain 12y agoWonder if the match referenced at the end is true. Fun read.
- mseebach 12y agoMonica and Steve have two kids. As they weren't referred to as "twins", I'm going to assume that they're not. Assuming Monica got pregnant on the first date and again immediately after she gave birth (which is perfectly possible, but an unusual choice and very strenuous on the mother) that puts the episode 18 months ago, no later than July 2013. Considering that Tinder was launched around August 2012 and assuming Monica and Steve are modern and responsible people (ie. are careful not to rush into the big responsibility of parenthood), I'd say it's highly unlikely.
- crxgames 12y agoMaybe they were part of the YOLO crew of the era.
- btown 12y agoI'm trying to think about whether there's a way for Facebook and/or Tinder to mitigate this attack without degrading user experience. Because the auth token used is from the response to the last request ever made from Steve's computer, having a changing auth token on each request wouldn't help in this scenario. Restricting an auth token to an IP address wouldn't work since both users are presumably behind the same NAT (all devices on the same residential WiFi router) - not to mention that IP addresses change all the time. Restricting an auth token to a user agent string would stop the first attempt at this hack - but then someone would simply tell the proxy to mimic the UA of Steve's desktop - but then could Facebook refuse to honor mobile application authorization requests if the mobile device is mimicking a desktop browser's UA?
- Xcelerate 12y agoIf each computer had a unique hardware private key, that could stop it. But I'm not sure that they do? (Or even if some do, can HTML5 access that somehow?)
- ryansouza 12y agohttp://pilif.github.io/2008/05/why-is-nobody-using-ssl-client-certificates/ http://pilif.github.io/2008/05/why-is-nobody-using-ssl-clien...
- JetSpiegel 12y agoAnother reason: SSL certificates cost money. StartSSL has some free option, though.
- bri3d 12y agoThe costs-money kind of server SSL certificates and client SSL certificates are two very different things. Client certificates are generated by the user's machine and signed using your server's private key. The user's client presents them to your server to prove that the client is who they said they were when you signed their certificate. These certificates don't cost anything, besides some CPU cycles on both sides of the process. The kind of server SSL certificates that cost money are generated by you and signed by a CA that most users' browsers will trust. Your server presents them to the client to state to the client that the server belongs to the domain it says it belongs to. Most CAs will charge you money for the service of signing those certificates, but that process has nothing to do with the lack of adoption of client SSL certificates. The parent article does a good job describing why client certificates aren't used more often: the UX doesn't make sense to users and there's not a user-friendly way to protect them with a second factor (the way you can encrypt your SSH keys using a passphrase or authentication device).
- mFixman 12y agoCouldn't the author just copy Steve's private key to his computer then?
- cpfohl 12y agoTL;DR Lock your machine before leaving the room.
- Mahn 12y agoThat's not really the tl;dr version of the article.
- deleted 12y ago[deleted]
- calewis 12y agoHack aside, really wonderfully written. Very funny and well explained.
- nojvek 12y agoI made a tinder auto liker script a while back to help my non-nerdy friends out. That's where I learn't about the man in middle attack trick. Very well written I should say.
- miketuritzin 12y agoI really enjoyed the style in which this post was written. It was hilarious and really engaging. It was also interesting to read through all the details of the hack.
- holic 12y agoIn Chrome, you can view and manage cookies here: chrome://settings/cookies
- anonfunction 12y agoThanks for that! I always went through chrome's preferences which is like navigating a maze.
- joshma 12y agoYou can also get a nice tabular view for the domain you're on by going to "Resources" from dev tools and navigating to the "Cookies" subsection.
- evantahler 12y agoThe only hole I can see here is that chrome extensions can read HTTP-only cookies. What are your thoughts on this?
- beagle3 12y agoFirst, some chrome extensions might legitimately need this. But even if they were disallowed - The guy had physical access to a running chrome capable of sending those cookies, and the ability to install an extension. This basically means no software policy was going to stop him.
- huynq 12y agoRemind me this one http://vnhacker.blogspot.com/2011/09/beast.html http://vnhacker.blogspot.com/2011/09/beast.html
- driverdan 12y ago> you most likely have 2 minutes alone with his computer Install a RAT and do whatever you want later. You have have a lot more fun with a RAT than just grabbing FB cookies.
- Robadob 12y agoGrabbing cookies can be done easily as an offline attack though, assuming they don't clear cookies on every shutdown (which I'd bet 99% of users don't). You simply copy their cookies file/s from chrome and temporarily replace yours with it. I previously carried out a similar attack whereby I temporarily borrowed the hard-drive out of a housemates laptop when they had left it not locked in their room and gained access to many of their frequented accounts (after they had made a point of saying I wouldn't be able to gain access). I was able to maintain access for several months changing subtle things before someone else notified them and they cleared sessions. The cookies file is generally small enough to easily upload in the background if your passing around casual programming apps with friends. I don't condone this, but it's a very hard attack to mitigate without services breaking UX. Shopping websites do this by asking you to re-enter your password before changing account details/making a purchase, I'm not sure whether such a UX change would hurt social media. Note: This was all probably around 6+ months ago, chrome may have mitigated this exact attack since by encrypting the file with something Google account specific.
- sayemm 12y agoReally clever hack and entertaining blog post! Love this author's writing, esp this other post of his on Playing to Win - http://robertheaton.com/2014/11/03/why-you-should-read-playing-to-win-by-david-sirlin/ http://robertheaton.com/2014/11/03/why-you-should-read-playi... A hacker at heart.
- _nedR 12y agoThanks for the link. Although there were some points in the article where i was not sure he was being serious or sarcastic. Just began reading the actual book Playing to Win (Its available free for online reading: http://www.sirlin.net/ptw http://www.sirlin.net/ptw ). It has already struck me as very intelligently written and insightful when you view its lessons as applying to life (at least the competitive aspects of it) rather some video game.
- FunCaptcha_Jim 12y agoThis is extremely well written and engaging. Any other blogs like this one?
- robheaton 12y agoThanks :). To plug myself, I quite like http://robertheaton.com/2014/01/06/how-to-win-at-dinner-party-the-blue-eyed-islanders/ http://robertheaton.com/2014/01/06/how-to-win-at-dinner-part...
- danielweber 12y agoI really liked your article on how to take over Rails servers if they leak their secret. http://robertheaton.com/2013/07/22/how-to-hack-a-rails-app-using-its-secret-token/ http://robertheaton.com/2013/07/22/how-to-hack-a-rails-app-u...
- thret 12y agoShouldn't the brown-eyed people kill themselves on day 101? Or are they supposed to reason that they, and they alone might have some other coloured eyes.
- robheaton 12y agoThis is true - it depends on whether they know there are exactly 2 different eye colours on the island. I should clarify that!
- philbarr 12y agoAlso, since you're not allowed to talk about it, if you work out you have blue eyes you could just keep your mouth shut. They do seem to be going to an awful lot of effort to top themselves.
- mfkp 12y agoReminds me a lot of my experiences building Tinder++ : http://tinderplusplus.com http://tinderplusplus.com (Made as a desktop app so it has permissions to intercept the auth token, could have also been done as a chrome extension). Source: https://github.com/mfkp/tinderplusplus https://github.com/mfkp/tinderplusplus
- eyeareque 12y agoSomeone should automate this process. Very nice write up.
- dmritard96 12y agoAs I was recently doing some reading, it seems like the cookie stealing could be made more difficult by adding something harder to fake? I think for flask-login they add in the ip and user agent. https://flask-login.readthedocs.org/en/latest/#session-protection https://flask-login.readthedocs.org/en/latest/#session-prote... This probably wouldnt work given that I am assuming its the external IP and a user agent is pretty easy to copy/clone. Seems like there should be another value mixed in that might be hard to figure out for a third party behind the same NAT.
- apendleton 12y agoIP can cause weird behavior for mobile, since it changes all the time, especially if they hop onto/off of wifi. User agent is trivial to fake.
- beagle3 12y agoMeta: I was hesitant to click on this link, as the HN comments implied it was "enjoyable", which in my experience when applied to technical articles is usually codeword for "fluffy and un-informative". But this article has all the technical details, and just-enough-but-not-too-much humor and background story to make this entertaining. Highly recommended, even if you're a "the details, all the details and nothing but the details" technical reader like me.
- maaarghk 12y agoExcellent article aside I also enjoyed the reference to Darkplace in the header. :)
- robheaton 12y agoYou and he were...buddies, weren't you?