Live data from Hacker News

The Ashley Madison Database Was Leaked

krebsonsecurity.com

91–100 of 527 posts

Re: The Ashley Madison Database Was Leaked

#91

Earlier quoted context omitted.

IMO, you're getting downvoted because your judgment of people on AM assumes facts not in evidence (i.e., that users of AM are there to cheat on their unknowing spouses), and then judges those people based on those facts that only exist in your head. It's self-aggrandizing, and the tone doesn't come off as participation in a discourse about morality as much as a narcissistic statement about the identity you'd like peo…

you're getting downvoted because your judgment of people on AM assumes facts not in evidence (i.e., that users of AM are there to cheat on their unknowing spouses This is all text from the homepage of Ashley Madison: "Ashley Madison is the world's leading married dating service for discreet encounters" Their tagline, a registered trademark is, "Life is short. Have an affair.®" "Ashley Madison is the most famous name…

You are confusing marketing with actual use. Cf "to serve and protect".

Re: The Ashley Madison Database Was Leaked

#92
post #64

Earlier quoted context omitted.

It's been confirmed now by multiple sources.

The original article was specifically about the lack of concrete evidence, and didn't claim a definite answer until the update a couple of hours ago. The HN submission title had been changed before I posted, but Dang's explanation of the change posted about the same time as I did. I get it now, so by all means feel free to disagree with my original point about HN title etiquette, but please don't downvote me for fail…

I agree. Don't take it personally; a lot of civil, even insightful comments seem to be getting downvoted in this thread. No matter the forum, there will always be a grey area between "downvote for quality" and "downvote because I disagree."

Re: The Ashley Madison Database Was Leaked

#93
I'm not sure if people realize how significant this hack is.

We just might have seen the first public hack that will cause people to die or be physically hurt. Homosexuality is illegal in certain countries (like Saudi Arabia) and this hack might expose people to harm in these countries. Some reactions of spouses might also be violent.

It looks like the reaction of most commenters is very different compared to when Gawker exposed the Conde Naste executive. This hack might have done this very same thing to many people.

On one chat website (I'm not sure if it's a good idea to post links) people are already requesting emails/domain and others are providing them. This can be used for blackmail, revenge, or to contact spouses. There will certainly be divorces resulting from this. August 19 will be the day when many people's lives were overturned. I don't know of any other hack that had such an impact in the past.

Apparently, the emails listed in the leak did not require user's confirmation, so people are posting a mix of fake and real emails. I don't know if the email confirmation flag was included in the hack or not. This could easily result in people who were not involved in any way with the website to become falsely implicated.

I don't see how Ashley Madison can survive this. They will surely be sued by multiple parties. This hack also supposedly shows that fake female profiles were used. Hacker's message calls it a scam with 90%-95% of users being male. This is a company that just a few months ago was thinking of an IPO and of raising $200 million (http://www.bloomberg.com/news/articles/2015-04-15/adultery-w...).

Re: The Ashley Madison Database Was Leaked

#94

Earlier quoted context omitted.

Bcrypt includes a (large) random salt so is not subject to rainbow table attacks. I believe therefore that will protect against identifying passwords contained in a known list. If I'm wrong about this I'd love someone to explain why to me.

this is not about rainbow tables, just about brute forcing. The only theoretical protection would be a site salt, but that has to be stored somewhere as accessible as the database, so it's fruitless to assume somebody who can get their hands on your db can't get the site salt. "It’s important to note that salts are useless for preventing dictionary attacks or brute force attacks. You can use huge salts or many salts…

Adding the salt increases (albeit linearly) complexity of hashing w/ regard to brute forcing. So using a very long salt reduces hash speeds.

Re: The Ashley Madison Database Was Leaked

#95
I remember back in the day (2010) when I asked pandora in email to "NEVER PLAY ME AN ADD FROM THAT SCUZZY COMPANY AGAIN"... they replied that "we only play PG ads and we vet all adds so they are appropriate to all audiences. no apologies, just "you're wrong dude". I cancelled my account and I wasn't asked to cheat on my wife on a 30 minute basis after that.

Re: The Ashley Madison Database Was Leaked

#96
post #25

This is my first time to learn about Ashley Madison. The business model actually disgusts me. I get the whole open relationship, but people who are actually married or in a committed relationship are using this site is just ridiculous. Either you break off with your current relationship, or stay loyal. BTW, those "secure" logo are just so useless I see them as sign of weakness rather than confidence. Anyone can place…

I'm curious why so many are downvoting. Do you disagree that the business model is disgusting, or just think it's inappropriate to say so about a peer's startup? I'm very curious to know what HNers think about this.

Let's be real about what the business model actually is, though: scamming men who wish they were having more sex into paying a recurring fee, and then try to string them along to keep them paying, by having fake profiles of beautiful women 'wink at' or 'poke' them, chat, or whatever.

By now it has been documented that Ashley Madison customers are overwhelmingly male (duh...) and that they have fake women doing fake interactions (such as 'collect' messages the male users have to pay to read).

I don't find that business model disgusting, exactly, but it's pretty sad and sleazy and lame. (The facilitating affairs aspect of the business, if it were actually real, wouldn't offend me personally.)

Re: The Ashley Madison Database Was Leaked

#97
post #19

Krebs has since updated his post with confirmation from three independent Ashley Madison users confirming their data was in the leak. It looks like this was the real deal.

Interestingly, the three people say the last digits of their credit card numbers were included in the dump, while the Ashley Madison CTO says they don't keep credit card numbers, full stop.

Whereupon we find out that a developer had indeed added CC to the database, and the CTO didn't know...? :-\

Re: The Ashley Madison Database Was Leaked

#98
post #66

Earlier quoted context omitted.

Thank you for that answer, which helped me see some larger issues at play. Edit: although I also disagree that discussions of ethics and morality are off-topic for HN.

To be clear, I think discussions of ethics and morality in company purposes are (or at least, ought to be) very much on topic for the site as a whole. I just think that discussing the morality of this particular business on this particular comment thread is likely to risk being off-topic, because it's too easy to read it as "Yeah, but they deserved it," and maybe the company did but the story is primarily about the u…

Possibly the worst bit is the "you need to pay us money to be removed from our database" aspect of the business model, which gives the whole thing a decidedly protection-racket-ish air. And then, apparently, they didn't remove you from the database even if you paid the protection money!

Re: The Ashley Madison Database Was Leaked

#99
post #78

First online checker that I found: https://ashley.cynic.al/

I can confirm it tested negative for negatives, and positive for a positive.

barack.obama@whitehouse.gov is in there (and verified, whatever that means), as is tblair@labour.gov.uk (unverified), pointed out by zerohedge.

Re: The Ashley Madison Database Was Leaked

#100
post #93

I'm not sure if people realize how significant this hack is. We just might have seen the first public hack that will cause people to die or be physically hurt. Homosexuality is illegal in certain countries (like Saudi Arabia) and this hack might expose people to harm in these countries. Some reactions of spouses might also be violent. It looks like the reaction of most commenters is very different compared to when Ga…

> This is a company that just a few months ago was thinking of an IPO and of raising $200 million

"Life is short. Have a boom!"

Post reply on HN