Plenty of Fish Hacked
plentyoffish.wordpress.com
Plenty of Fish Hacked
1–10 of 104 posts
Re: Plenty of Fish Hacked
#2The worst part is Markus stores his passwords in plaintext, or slightly better reversible encryption.
POF will mail a person their password. This is a security nightmare because basic precautions were not taken.
I just checked and POF is still able to reproduce and email me my password. I also checked the email I use for POF and there is no mention of this in any of their emails. If markus took this seriously at all he'd be resetting everyones password and have instructions to reset their email password.
"We have reset all users passwords and closed the security hole that allowed them to enter." This is a lie, I just logged in with my username and password. I wasn't even asked on login to change it.
Re: Plenty of Fish Hacked
#3Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS, hmm maybe?
Re: Plenty of Fish Hacked
#4Plenty of Fish? Might as well rename it plenty of passwords. The worst part is Markus stores his passwords in plaintext, or slightly better reversible encryption. POF will mail a person their password. This is a security nightmare because basic precautions were not taken. I just checked and POF is still able to reproduce and email me my password. I also checked the email I use for POF and there is no mention of this…
I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remembered to kill the account a few months back), but back then they would actually send you reminders every so often - I want to say once a week - that included your plain text password as a reminder.
I think this is just the kick in the ass I needed to go through all my accounts around the internet and make sure they all have unique, reasonably complex passwords. My email and banking passwords have always been unique, but I know I've been slack elsewhere. I won't let that happen again.
Re: Plenty of Fish Hacked
#5I'd tend to lean towards injection, given that it took Russo (apparently?) 2 days to produce a working exploit with what amounts to fiddling around, but if anyone knows where I can read a write-up on it I'd appreciate it.
(Professional curiosity, I'm a web dev and like to be apprised of what catches the more popular sites. Sometimes you get lucky and it's subtle/neat.)
Re: Plenty of Fish Hacked
#6Plenty of Fish? Might as well rename it plenty of passwords. The worst part is Markus stores his passwords in plaintext, or slightly better reversible encryption. POF will mail a person their password. This is a security nightmare because basic precautions were not taken. I just checked and POF is still able to reproduce and email me my password. I also checked the email I use for POF and there is no mention of this…
Re: Plenty of Fish Hacked
#7I managed to stumble through the first part of the article, but lost interest when Russo claimed that "he can see what the Russians are doing because they took over his computer." This sounds technologically implausible at best.
Maybe the official post in the morning will make more sense.
Re: Plenty of Fish Hacked
#8Re: Plenty of Fish Hacked
#9Plenty of Fish? Might as well rename it plenty of passwords. The worst part is Markus stores his passwords in plaintext, or slightly better reversible encryption. POF will mail a person their password. This is a security nightmare because basic precautions were not taken. I just checked and POF is still able to reproduce and email me my password. I also checked the email I use for POF and there is no mention of this…
It's actually worse than that. I don't know what it's like now, since I haven't used POF since 2008 or so when I met my current girlfriend (though I only remembered to kill the account a few months back), but back then they would actually send you reminders every so often - I want to say once a week - that included your plain text password as a reminder. I think this is just the kick in the ass I needed to go through…
Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep.
Every time I log on I have to use my chipcard in a little electronic device with an LCD display and a bunch of buttons on it, the chipcard generates a unique ID every time I log in. When I want to do an actual transaction I have to authorize it using 1, 2 or 3 challenges depending on the amount and destination of the transaction. It's less convenient than a password protected system but it's fairly secure.
It's also protected against the most common form of theft called 'skimming' because it uses the chip and not the magnetic stripe so a thief using the data on a skimmed card could only use that to use an ATM but not to access the internet banking section of the website of my bank.
Re: Plenty of Fish Hacked
#10It is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS,…