Live data from Hacker News

How to boost your popularity on OkCupid using CSRF and a JSON type confusion

blog.azuki.vip

31–40 of 134 posts

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#32

Anecdote: OkCupid is the only website or app where I've had an account hijacked. I got it back with a password reset, but the profile and pics were filled with bogus content.

Any idea what the intent was?

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#33
post #19

Earlier quoted context omitted.

Lots of sites do this, it’s a feature for the majority of users who prefer convenience over security.

I find that passwordless links usually expire after 1 use or some amount of time; generating eternal alt-passwords for an OkCupid account in every message notification email seems pretty heinous.

Gmail now pretty much breaks single-use tokens in links because it consumes them itself after a user clicks on them, but before redirecting the user to the site.

It's an unfortunate change that has made single-use links a worse UX and less popular in the last couple of years.

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#34
post #4

Earlier quoted context omitted.

I learned recently that if someone forwards you the email that OKC sends them alerting them to a new message and you click on it you gain passwordless access to their account. I contacted OKC about this but they said that it was not an issue.

This isn't ideal, but why would anyone forward this kind of email?

The email itself could be intercepted, could it not?

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#35
post #27
post #21

Earlier quoted context omitted.

I guess when an adversary knows about the feature and uses some social engineering against the user?

In order to get access to their... OkCupid account? Not sure that I care.

Everyone's got something to hide somewhere.

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#37
post #8

Earlier quoted context omitted.

That's shocking! Really surprised that they don't see this as an issue, I would expect that it's trivial to social engineer someone into forwarding you one of those emails.

Maybe, but how much value is there in taking over people's OKCupid account?

The value is relative to motivation, I'd posit

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#38
post #27
post #21

Earlier quoted context omitted.

I guess when an adversary knows about the feature and uses some social engineering against the user?

In order to get access to their... OkCupid account? Not sure that I care.

Imagine https://www.wired.com/2017/01/grinder-lawsuit-spoofed-accoun..., without the spoofing.

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#39
post #4

Earlier quoted context omitted.

I learned recently that if someone forwards you the email that OKC sends them alerting them to a new message and you click on it you gain passwordless access to their account. I contacted OKC about this but they said that it was not an issue.

This isn't ideal, but why would anyone forward this kind of email?

I might forward it to a friend to ask if that's the girl he dated last week, without meaning to give him passwordless access to my account.

Re: How to boost your popularity on OkCupid using CSRF and a JSON type confusion

#40
post #8

Earlier quoted context omitted.

That's shocking! Really surprised that they don't see this as an issue, I would expect that it's trivial to social engineer someone into forwarding you one of those emails.

Maybe, but how much value is there in taking over people's OKCupid account?

If there's no value or downside to someone taking over my OKCupid account, why have a password on it in the first place?
Post reply on HN