I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…
Behind Grindr's Doomed Hookup in China
21–30 of 37 posts
Re: Behind Grindr's Doomed Hookup in China
#22Earlier quoted context omitted.
There’s so much throwaway data in there I’d be hard pressed to believe there’s much of value. They don’t even validate the users email beyond “contains @“.
I wouldn't be so sure. Grindr tracks users locations pretty precisely, and although many users hide their faces in profile pictures, many more demand a face be sent through direct messages, etc. If you have location and a face, and your target is even remotely popular, some internet sleuthing can put the rest together pretty easily. How much of this can be validated and proven to not be a masquerade (fake pictures /…
Re: Behind Grindr's Doomed Hookup in China
#23I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…
Whether or not a company has proper access control in place is mostly a function of whether they've had a scandal in the past that required them to lock things down. If it were widely known that Tencent employees are spying on WeChat users, they'd probably pretty quickly lose that access to stop the inevitable outrage.
[1] https://www.vice.com/en_us/article/xwnva7/snapchat-employees...
[2] https://www.nbcnews.com/tech/tech-news/uber-whistleblower-sa...
Re: Behind Grindr's Doomed Hookup in China
#24The Chinese hacked the entire OPM database and siphoned of the data of all government employees. Hacked Marriot. It’s anyone’s guess how will they mine and use this information.
They didn't exactly hack Marriott. They hacked Starwood, which had been bought by Marriott. I don't mean to nitpick but there are far more Marriott guests than Starwood guests.
https://www.reuters.com/article/us-marriott-intnl-cyber/marr...
Re: Behind Grindr's Doomed Hookup in China
#25The Chinese hacked the entire OPM database and siphoned of the data of all government employees. Hacked Marriot. It’s anyone’s guess how will they mine and use this information.
Their intentions are pretty obvious. Use that data to identify intelligence sources to blackmail, find potential double agents to recruit, and stop potential infiltration into their own intelligence agencies. It's easy to think of ways to combine all of these hack data streams into one database that can be cross referenced. You go to China on a visa, your entry to the country trips a flag in a system, and an intellig…
Re: Behind Grindr's Doomed Hookup in China
#26Earlier quoted context omitted.
The Marriott system is still riddled with vulnerabilities. Had someone transfer 200,000 points out of my account recently. No way they stole my session cookie, and the password was very complex, unique to Marriott and generated / stored by LastPass. There was no attempt to change my password. Now what's interesting is that the points to airline infrastructure likely is a SPG legacy backend that is still running.
Most people who have workstation malware are unaware of the fact that they have workstation malware.
Considering the large amount of points in OP's Marriott account, I highly doubt that was the highest-value target available. Considering it's already known that parts of their network were compromised, Occam's razor points to this being a vuln on the hotel's end.
Re: Behind Grindr's Doomed Hookup in China
#27This data set will be a blackmail goldmine. I'd be shocked if the Chinese government hasn't already mined it for "discreet" users.
Re: Behind Grindr's Doomed Hookup in China
#28Re: Behind Grindr's Doomed Hookup in China
#29I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…
Re: Behind Grindr's Doomed Hookup in China
#30Earlier quoted context omitted.
Most people who have workstation malware are unaware of the fact that they have workstation malware.
So assuming that his machine is compromised, the first method of attack was Marriott points? Sounds shockingly similar to the responses I got in a similar situation with my Bethesda.net account getting hacked. Again, complex PW from a manager. How likely is it that if someone gained access to that vault or my PC the first thing they would attack would be an account which only lets them gain access to a garbage fallou…