Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

61–70 of 104 posts

Re: Plenty of Fish Hacked

#61
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

I think that document raises a lot more questions than it answers, and some of those questions would have me 'extremely upset' too if I was on the receiving side of them.

There is more than meets the eye here imo.

Re: Plenty of Fish Hacked

#62

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

The weird thing is that Blizzard will cheerfully sell you a $7 hardware token to protect your imaginary WoW gold and equipment, but I don't know of any US banks that offer one to protect your actual money.

Bank of America and Paypal will.

Most banks use the "you only get to try three times before your account is locked" method of security. It's pretty hard to bruteforce a password with only three attempts before you have to call customer service. At that point, you might as well print out a fake driver's license, walk into a branch, and ask to close "your" account.

Re: Plenty of Fish Hacked

#63

I wonder if Markus realizes that e-mails have been going out non-stop to customers lately from spam profiles using their 'wants to meet you' "feature". On the one hand, I feel bad for PoF becoming the target of an attack and drama, but from the tone of the post, it wasn't handled right on their side either. PoF really needs to get its act together on the security side. It's sad to because it was a fairly well execute…

As the lead developer on a dating site myself, I can say that it's ridiculously hard to keep out spam profiles. We block by country, Project Honeypot entries, and HTTP header profiling, use captchas, and use other bot-sniffing tricks, but in the end we still have to manually ban IP addresses every day.

We don't store passwords in plaintext though, sheesh.

Edit: I just upgraded the hashing algorithm on the site from SHA1 to Bcrypt. Paranoia for the win.

Re: Plenty of Fish Hacked

#64
post #3

It is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS,…

It is mind boggling that you contact Chris Russo, get his version of the events, publish it receiving page views and ad revenue and then immediately claim he "does not make any sense with his crazy requests and compulsive lies" without any demonstration of these claims. Now, you might be right, he might be a compulsive liar, but if he is why are you publishing his version of the events on your site then quietly label…

My apologies. I got his version of the events after I read Marcus blog post. My opinion at that point was based only on the information I had a the moment. Then Chris Russo himself emailed me his version of the events which I posted on my blog with his permission. Lesson, don't take sides until you hear both sides of the story, understood.

Re: Plenty of Fish Hacked

#65

Earlier quoted context omitted.

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

The weird thing is that Blizzard will cheerfully sell you a $7 hardware token to protect your imaginary WoW gold and equipment, but I don't know of any US banks that offer one to protect your actual money.

E*TRADE offers this for free if you have a high enough balance ($5K?) between accounts. Unfortunately, our good friends at Mint.com have no way to deal with two-factor auth, so in my informal polls, all my friends who were using two factor switched back to password only so they could use Mint's reporting features.

Re: Plenty of Fish Hacked

#66

Earlier quoted context omitted.

My bank in Australia does this (for any transaction to an account I've never sent money to before). Works prettty well. I click a button, they SMS a 6 digit code, I enter it, money transferred (or bill paid).

Which bank?

AFAIK, CBA and Community CPS both do it.

Re: Plenty of Fish Hacked

#67
post #9

Earlier quoted context omitted.

If there is an option to use some kind of hardware token with your banking then I would strongly advise you to take that. Having just a password to protect your bank account sounds pretty scary to me. That's about as juicy as it gets. I'm paranoid enough about my servers having 'just' a password to protect them (oh, and an ACL), if my bank accounts would have only a password I wouldn't sleep. Every time I log on I ha…

Are you European? I only ask because my friend in London is the only person I've ever heard of using such a device. Unfortunately, such a thing seems all but unheard of here in Canada. Our debit and credit cards are being replaced with cards with chips embedded, which could be a sign that such devices are coming, but for now I'm afraid my password is my only real line of defense online. I have noticed that when I log…

Odd. It seems like almost every big bank in Asia has them by now. I would have thought their use is widespread world over.

Re: Plenty of Fish Hacked

#68
Why does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish?

-http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible.

2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor, Chris story sounds more realistic. He saw a flaw and reported it. Everything was going dandy until he saw ads for Plenty of Fish data. At this point Mark decides to try ruin Chris by fabricating a story, since he believe it is him trying to sell the data. It is a simpler story.

3. Why isn't Mark contacting the authorities? - A week and Chris is not in jail and responding freely on his blog?

Mark does have some valid points though,he did hack pirate bay: http://torrentfreak.com/the-pirate-bay-hacked-users-exposed-... But Chris claimed again, proof of concept and he has no bad intentions.[What is the appropriate way to expose vulnerabilities?]

In my opinion, he[Mark] should release the voice recording to add more credibility because right now he is sounding shaky.

Re: Plenty of Fish Hacked

#69
post #57
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

Mate, before you milk that 'interview' for eye-balls, just go back to the PoF article above and read the new comments. Chris Russo is there commenting, and it calls your ability to judge character into question. For starters, he has never denied the story about Russians holding his computer hostage and threatening to kill him. He just ignored it. Then he goes for the "race" card and says PoF are suspicious of his int…

Wait, so if I post here that mahmud is on the yakuza payroll and has kidnapped my puppies then people are supposed to believe it until you deny it?

Re: Plenty of Fish Hacked

#70

The fact that a well known site like POF was hacked is eclipsed by the fact that they both store unencrypted passwords, and the bizarre tone of this article. I managed to stumble through the first part of the article, but lost interest when Russo claimed that "he can see what the Russians are doing because they took over his computer." This sounds technologically implausible at best. Maybe the official post in the mo…

Is it implausible? Could you not set up some kind of honeypot machine and then monitor it's activity once it's been zombie'd? (Genuine question - I'm definitely no expert on the topic).
Post reply on HN