Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

71–80 of 104 posts

Re: Plenty of Fish Hacked

#71
post #55
post #3

It is mind boggling that the young 23yo Chris Russo was smart enough to hack PlentyOfFish but not make any sense with his crazy requests and compulsive lies. This morning Markus Frind CEO of PlentyOfFish plans to do and official statement about the events. Fun Fact: Markus Frind graduated the same year as I did from BCIT in Vancouver. I took Mechanical Design and Mark took Computer Science. Do I regret not taking CS,…

What does taking CS have to do with building a website like POF?...

A pure statistical reason since I am willing to bet there are way more CS students building websites than Mechanical Designers. But everything is possible, I have also built websites albeit a billion times less successful. To be honest I was just expressing my envy because although we went to the same school Mark build the largest dating site on the world and today is a millionaire and I am not, sniff.

Re: Plenty of Fish Hacked

#72

Earlier quoted context omitted.

In Denmark the currently-being-phased-in solution is a low-tech version of two-factor authentication. Instead of a hardware dongle, the centrally-administered "NemID" system issues you with a physical code card with some numerical codes on it. You enter your NemID password, your CPR number (Denmark's citizen-ID number), and the next unused code on the card. When there's fewer than 20 unused codes, the system notices…

The upside is that the NemID system gets the average citizen to a point where his/her family (and close friends) are the largest security problem. It is much more difficult for hackers in Argentina and Russia to get into your bank account when they need access to a piece of paper. If is impossible to protect against your own family: the have hardware access to your computer, they can intercept all your paper mail, th…

I think the NatWest system is pretty solid:

1. UserID is your date of birth and some random-ish number appended

2. It asks for three random characters from your password and your PIN

3. For any transaction you have the chip-card-plus-calculator-looking-device (and you need to know the pin for that.)

Personally I'm happy enough with the German system (username, password, random TAN from a piece of paper). At least I will be until my kids grow up :-).

Re: Plenty of Fish Hacked

#73

Earlier quoted context omitted.

My bank in Australia does this (for any transaction to an account I've never sent money to before). Works prettty well. I click a button, they SMS a 6 digit code, I enter it, money transferred (or bill paid).

Which bank?

That one. :)

http://www.commbank.com.au for those who don't get the joke.

Re: Plenty of Fish Hacked

#74
I'm on plentyoffish and they do weekly send you your password in plaintext (there are plenty of other sites that do this). Thankfully I change my passwords each month to a random string of 12 characters and don't really care. Perhaps if hackers get into my account, my account can finally get a date!

Re: Plenty of Fish Hacked

#75
Wouldn't surprise me one bit if this all came out as a sham and they were all just in it to get some attention...

I mean, who settles things through the blogosphere... come on folks, there is a judicial system!

Re: Plenty of Fish Hacked

#76

The fact that a well known site like POF was hacked is eclipsed by the fact that they both store unencrypted passwords, and the bizarre tone of this article. I managed to stumble through the first part of the article, but lost interest when Russo claimed that "he can see what the Russians are doing because they took over his computer." This sounds technologically implausible at best. Maybe the official post in the mo…

Is it implausible? Could you not set up some kind of honeypot machine and then monitor it's activity once it's been zombie'd? (Genuine question - I'm definitely no expert on the topic).

Certainly! That part alone is not only plausible, but also quite common. Antivirus companies, security researchers and various other interested parties have been known to use such tactics.

However, it doesn't make sense then those who hacked his supposed honeypot would be aware of his oversight ("they are trying to kill him"), while still using the honeypot to perform whatever illegal shenanigans they were up to ("they are currently downloading plentyoffish’s database").

Re: Plenty of Fish Hacked

#77

The fact that a well known site like POF was hacked is eclipsed by the fact that they both store unencrypted passwords, and the bizarre tone of this article. I managed to stumble through the first part of the article, but lost interest when Russo claimed that "he can see what the Russians are doing because they took over his computer." This sounds technologically implausible at best. Maybe the official post in the mo…

Is it implausible? Could you not set up some kind of honeypot machine and then monitor it's activity once it's been zombie'd? (Genuine question - I'm definitely no expert on the topic).

http://www.realvnc.com/

Re: Plenty of Fish Hacked

#78

This is why my pof passwords are always some variation of "zachary" (with some numbers appended).

You're just asking for a "disregard that, I suck cocks" now.

Apparently the above is unpopular - I was just trying to point out that posting your password (or enough of it that one could bruteforce the rest) has its downsides.

Re: Plenty of Fish Hacked

#79
post #30
post #15

Related, but slightly off-topic. When I read this post on my iPhone, I saw a match.com ad on the top of the page. match.com competes with Plenty Of Fish. POF is a multi-million dollar business. I'm surprised that they aren't paying Wordpress to provide an ad-free experience.

POF is entirely funded by ads from paid-for dating sites. It's a weird business model, but it seems lucrative.

No, it's not. They have a large(ish) self-serve advertising platform like FB with various levels of targeting.

Re: Plenty of Fish Hacked

#80
post #57
post #38

Just got in contact with Chris Russo who hacked PlentyOfFish His version of the events here -> http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp...

Mate, before you milk that 'interview' for eye-balls, just go back to the PoF article above and read the new comments. Chris Russo is there commenting, and it calls your ability to judge character into question. For starters, he has never denied the story about Russians holding his computer hostage and threatening to kill him. He just ignored it. Then he goes for the "race" card and says PoF are suspicious of his int…

Why haven't you denied the puppies kidnapping, mahmud? I can overlook the Yakuza. I have seen some movies about them and they look cool, but kidnapping puppies?

Really sounds suspicious.

Post reply on HN