Live data from Hacker News

Behind Grindr's Doomed Hookup in China

reuters.com

21–30 of 37 posts

Re: Behind Grindr's Doomed Hookup in China

#21

I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…

Story sounds made up. Definitely not an acceptable cultural norm in China.

Re: Behind Grindr's Doomed Hookup in China

#22

Earlier quoted context omitted.

There’s so much throwaway data in there I’d be hard pressed to believe there’s much of value. They don’t even validate the users email beyond “contains @“.

I wouldn't be so sure. Grindr tracks users locations pretty precisely, and although many users hide their faces in profile pictures, many more demand a face be sent through direct messages, etc. If you have location and a face, and your target is even remotely popular, some internet sleuthing can put the rest together pretty easily. How much of this can be validated and proven to not be a masquerade (fake pictures /…

There's also the matter of device finger printing. If a malicious actor can get you to install a less illicit app that can personally identify you, they can finger print the device and then do the same in Grindr and compare prints to find targets.

Re: Behind Grindr's Doomed Hookup in China

#23

I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…

I don't think it's a difference in cultural norms. It's just what happens if you give people access to production databases without oversight. Snapchat [1], Uber [2] and police departments [3] have had employees abuse their database access, and there are probably many more cases that didn't turn up in a quick search.

Whether or not a company has proper access control in place is mostly a function of whether they've had a scandal in the past that required them to lock things down. If it were widely known that Tencent employees are spying on WeChat users, they'd probably pretty quickly lose that access to stop the inevitable outrage.

[1] https://www.vice.com/en_us/article/xwnva7/snapchat-employees...

[2] https://www.nbcnews.com/tech/tech-news/uber-whistleblower-sa...

[3] https://apnews.com/699236946e3140659fff8a2362e16f43

Re: Behind Grindr's Doomed Hookup in China

#24

The Chinese hacked the entire OPM database and siphoned of the data of all government employees. Hacked Marriot. It’s anyone’s guess how will they mine and use this information.

They didn't exactly hack Marriott. They hacked Starwood, which had been bought by Marriott. I don't mean to nitpick but there are far more Marriott guests than Starwood guests.

Far fewer is still: 343 million customer records, 25.55 million passport numbers (5.25 million in plaintext), 8.6 million encrypted payment cards.

https://www.reuters.com/article/us-marriott-intnl-cyber/marr...

Re: Behind Grindr's Doomed Hookup in China

#25

The Chinese hacked the entire OPM database and siphoned of the data of all government employees. Hacked Marriot. It’s anyone’s guess how will they mine and use this information.

Their intentions are pretty obvious. Use that data to identify intelligence sources to blackmail, find potential double agents to recruit, and stop potential infiltration into their own intelligence agencies. It's easy to think of ways to combine all of these hack data streams into one database that can be cross referenced. You go to China on a visa, your entry to the country trips a flag in a system, and an intellig…

i'm trying my absolute hardest to be constructive, but what in the hell are you smoking?

Re: Behind Grindr's Doomed Hookup in China

#26
post #19
post #4

Earlier quoted context omitted.

The Marriott system is still riddled with vulnerabilities. Had someone transfer 200,000 points out of my account recently. No way they stole my session cookie, and the password was very complex, unique to Marriott and generated / stored by LastPass. There was no attempt to change my password. Now what's interesting is that the points to airline infrastructure likely is a SPG legacy backend that is still running.

Most people who have workstation malware are unaware of the fact that they have workstation malware.

So assuming that his machine is compromised, the first method of attack was Marriott points? Sounds shockingly similar to the responses I got in a similar situation with my Bethesda.net account getting hacked. Again, complex PW from a manager. How likely is it that if someone gained access to that vault or my PC the first thing they would attack would be an account which only lets them gain access to a garbage fallout game and not my email/social media/bank account?

Considering the large amount of points in OP's Marriott account, I highly doubt that was the highest-value target available. Considering it's already known that parts of their network were compromised, Occam's razor points to this being a vuln on the hotel's end.

Re: Behind Grindr's Doomed Hookup in China

#29

I know a number of Tencent engineers through college and past tech job. There's this game among employees on certain teams - find compromising pics your ex has sent through WeChat messaging, and put them side by side with the screenshot of your ex breaking up with you (as in "who's laughing now"). I don't think this is a political / trade issue, but rather a difference in cultural norms. It strikes me when people out…

[flagged]

Re: Behind Grindr's Doomed Hookup in China

#30
post #19

Earlier quoted context omitted.

Most people who have workstation malware are unaware of the fact that they have workstation malware.

So assuming that his machine is compromised, the first method of attack was Marriott points? Sounds shockingly similar to the responses I got in a similar situation with my Bethesda.net account getting hacked. Again, complex PW from a manager. How likely is it that if someone gained access to that vault or my PC the first thing they would attack would be an account which only lets them gain access to a garbage fallou…

Sounds like they would be specifically targeted. It could be mailware that's delivered over the hotel's wifi or perhaps the maids dropping mailware on unattended laptops? If Marriott investigates this, they should look if similar incidents happened and correlate them with recent stays.
Post reply on HN