Live data from Hacker News

Plenty of Fish Hacked

plentyoffish.wordpress.com

81–90 of 104 posts

Re: Plenty of Fish Hacked

#81

Earlier quoted context omitted.

From Markus' account, it sure looks like that; but note that a "chris russo" says, in the comments, that he's only given a proof of concept and that the web server logs will show that he didn't make a full dump. Of course, sending a PoC with an offer to fix the security does have a "nice website you have there, it'd be a shame if something happened to it" vibe to it; still, it's factually different from trying to ext…

That's a technicality in my opinion. If the website owner would ask you to fix it that would be one thing, to hack them and then to 'offer to fix it' (presumably for a fee) is across the line. It's a fine one but it's definitely there. Hacked a site? Send them a message about it, give them time to respond and time to fix. If they don't respond after a reasonable time has passed go public with it, don't try to transla…

Trying to turn a PoC into paid work is indeed sketchy; but I do understand that security researchers/whitehat hackers would like to get paid for their work.

It would be good if more companies set up bug bounties, and even better if they'd set the reward a bit closer to (reputed) black-market prices.

Re: Plenty of Fish Hacked

#82
From the TechCrunch article comments:

"Roberto Alsina Just a small clarification about this bit:

"They then start talking about money because they need to incorporate a company that can deal with companies outside of Argentina and that will cost $15,000. They also needed to know if they were going to make over $100k/year or 500k/year as that would require different registrations…"

I am from Argentina, and I own a company. Yes, in order to bill services to foreign customers, you need to register your company as an "exporter of services". And to do that you have to put money on escrow (but not $15000, only $7500), or your company has to demonstrate assets for over $12500.

If Russo has been working without an incorporated company (he could be a "monotributista", which is a way to bill as a physical person). A monotributista can export services, but... he's personally liable, so doing security consulting that way is insane.

That's probably why Russo could be asking for money up-front: if he didn't, he would have been doing business illegally."

Re: Plenty of Fish Hacked

#83
post #68

Why does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish? - http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp... 1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible. 2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor,…

A key point here is that he didn't use a proxy and doesn't seem to hide his identity during the sniffing around, which means he's either: a) stupid. b) not intending to do anything malicious.

I think a. is unlikely, because he did actually manage to break in, although, the hole itself might've been trivial and therefore this might not count. I don't think so, though. Which leaves b.

Re: Plenty of Fish Hacked

#84

Wouldn't surprise me one bit if this all came out as a sham and they were all just in it to get some attention... I mean, who settles things through the blogosphere... come on folks, there is a judicial system!

Things can get really stuck - as the protagonistss appear to be on different continents

Re: Plenty of Fish Hacked

#85

I'm on plentyoffish and they do weekly send you your password in plaintext (there are plenty of other sites that do this). Thankfully I change my passwords each month to a random string of 12 characters and don't really care. Perhaps if hackers get into my account, my account can finally get a date!

> Perhaps if hackers get into my account, my account can finally get a date!

No, you have to wait for OKCupid to get hacked for that to happen.

Re: Plenty of Fish Hacked

#86
post #41

Earlier quoted context omitted.

In Denmark the currently-being-phased-in solution is a low-tech version of two-factor authentication. Instead of a hardware dongle, the centrally-administered "NemID" system issues you with a physical code card with some numerical codes on it. You enter your NemID password, your CPR number (Denmark's citizen-ID number), and the next unused code on the card. When there's fewer than 20 unused codes, the system notices…

This resembles the most common way of authentication for online banking in Germany (a PIN and a list of transaction codes, so-called TANs). Do you always have to pick the next one-time code in the printed sequence? In Germany, you used to be free to pick any of the unused TANs, which made phishing really simple. Nowadays it's more common for a bank to challenge you to a randomly chosen TAN.

When I use NemID, it asks for code number NNNXXX, where NNN is the sequential number of the codes (to make it easy to find) and XXX is a "check" to prevent phishing.

Re: Plenty of Fish Hacked

#87
post #68

Why does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish? - http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp... 1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible. 2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor,…

The hacker's story certainly has less holes, however the style of writing out numbers as words is suspicious; I have only ever seen it in 419 scams: "28,000,000 (twenty eight million users)".

Re: Plenty of Fish Hacked

#88
post #68

Why does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish? - http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp... 1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible. 2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor,…

The hacker's story certainly has less holes, however the style of writing out numbers as words is suspicious; I have only ever seen it in 419 scams: "28,000,000 (twenty eight million users)".

Writing numbers as words is a legal norm in many countries.

Whilst Nigeria is one of such countries, it doesn't follow that all documents with alphabetised numbers are illegit.

Re: Plenty of Fish Hacked

#89
post #83
post #68

Why does the Hacker "Chris Russo" sound more credible than the guy from Plenty of Fish? - http://grumomedia.com/plenty-of-fish-hacked-chris-russos-exp... 1. He provides emails - I think Mark(Guy from Plenty of Fish), really needs to get those voice recordings of Chris threatening his wife online to be more credible. 2. Mark tells a complicated story - A story with mafia and all that, really? If we follow Occam razor,…

A key point here is that he didn't use a proxy and doesn't seem to hide his identity during the sniffing around, which means he's either: a) stupid. b) not intending to do anything malicious. I think a. is unlikely, because he did actually manage to break in, although, the hole itself might've been trivial and therefore this might not count. I don't think so, though. Which leaves b.

I think it's pretty obvious from both sides of the story that what Chris intended to do was (c) demonstrate the existence of a vulnerability in order to hard-sell his security consultancy.

Reading between the lines, it looks like his sales tactics were heavy on the FUD (he pointedly hasn't denied making any claims about Russian conspiracies), leaving Frind paranoid and angry. And probably also embarrassed if the security flaws were as basic as is being suggested.

Re: Plenty of Fish Hacked

#90
post #82

From the TechCrunch article comments: "Roberto Alsina Just a small clarification about this bit: "They then start talking about money because they need to incorporate a company that can deal with companies outside of Argentina and that will cost $15,000. They also needed to know if they were going to make over $100k/year or 500k/year as that would require different registrations…" I am from Argentina, and I own a com…

Many freelancers work as monotributistas or responsables inscriptos, exporting services that way. And it's perfectly legal. For a single person shop this would be the first case I hear of, of an incorporate company setup that way.
Post reply on HN