Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

51–60 of 104 posts

Re: Plenty of Fish Hacked

#51
post #3

It is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS,…

It is mind boggling that you contact Chris Russo, get his version of the events, publish it receiving page views and ad revenue and then immediately claim he "does not make any sense with his crazy requests and compulsive lies" without any demonstration of these claims. Now, you might be right, he might be a compulsive liar, but if he is why are you publishing his version of the events on your site then quietly labeling him crazy on HN without some measure of proof? You do realise such claims are libelous right?

Re: Plenty of Fish Hacked

#52
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

I just spoke directly with Chris Russo over Skype. He is extremely upset about the whole situation. I don't want to put any words on his mouth. He tells his own version of the events on the link above which he allowed me to post on his behalf.

Re: Plenty of Fish Hacked

#54
post #8

This is extortion, plain and simple.

Telling someone they should lock their door, and that you could do it for them (but not necessarily that noone else could, I mean what kind of developer can't fix a SQL injection attack in a couple of hours max?) doesn't seem like extortion to me. Now, if the claims about a stolen data dump held as collateral and threatening media reports are true, it borders on extortion.

Re: Plenty of Fish Hacked

#55
post #3

It is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS,…

What does taking CS have to do with building a website like POF?...

Re: Plenty of Fish Hacked

#56
post #8

This is extortion, plain and simple.

if you read grumo's comment http://news.ycombinator.com/item?id=2160916 you'll see it's not quite that simple [edited to fix name. sorry 'bout that, been a long day]

Thanks cubicle67, it is "grumo" instead, no worries.

Re: Plenty of Fish Hacked

#57
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

Mate, before you milk that 'interview' for eye-balls, just go back to the PoF article above and read the new comments.

Chris Russo is there commenting, and it calls your ability to judge character into question. For starters, he has never denied the story about Russians holding his computer hostage and threatening to kill him. He just ignored it. Then he goes for the "race" card and says PoF are suspicious of his intent just because he is in Argentina.

Re: Plenty of Fish Hacked

#58
post #8

This is extortion, plain and simple.

From Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump. Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to ext…

That's a technicality in my opinion. If the website owner would ask you to fix it that would be one thing, to hack them and then to 'offer to fix it' (presumably for a fee) is across the line. It's a fine one but it's definitely there.

Hacked a site?

Send them a message about it, give them time to respond and time to fix. If they don't respond after a reasonable time has passed go public with it, don't try to translate it in to paid work.

Re: Plenty of Fish Hacked

#59
post #8

This is extortion, plain and simple.

From Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump. Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to ext…

How come Russo was not shocked to hear the Russian threat story? It sure seems very suspicious NOT to refute that little nugget, no?

Re: Plenty of Fish Hacked

#60
post #37

Earlier quoted context omitted.

Paypal will. Don't quote me on this, but I think banks are starting to lean on "possession of a trusted mobile device" as their two-factor authentication. The basic theory is that I give them a number I can receive SMSes at, and then any time they want to verify that the person operating my web browser is really me, they say "We just sent you a one-time password via SMS. Enter it, resend it, or talk to customer servi…

My bank in Australia does this (for any transaction to an account I've never sent money to before). Works prettty well. I click a button, they SMS a 6 digit code, I enter it, money transferred (or bill paid).

Which bank?
Post reply on HN