Live data from Hacker News

The Ashley Madison Database Was Leaked

krebsonsecurity.com

101–110 of 527 posts

Re: The Ashley Madison Database Was Leaked

#101
post #4

Earlier quoted context omitted.

This is a great comment, Thomas. I had an argument with my girlfriend about this. No matter what reasoning I used, no matter what I said, she could not agree that it was wrong that Ashley Madison (A.M.) was hacked. Her position was that marital infidelity is such a pubishable offense that the participants on A.M. deserve to be publicly outed. In her view, it was not even up for debate. She felt so powerfully about in…

Tell her that two wrongs never make a right.

Yep, Two wrongs never make a right. i agree with you.

Re: The Ashley Madison Database Was Leaked

#102

First online checker that I found: https://ashley.cynic.al/

this is legit checker. Some emails confirmed, others not. Probably indicator of time window of stolen data. Created mine approx 4 months ago and is not in list. e-mails I communicated with are on the list indicating their accounts were older?

Re: The Ashley Madison Database Was Leaked

#104
post #16

Earlier quoted context omitted.

We are never the infidels. Only "they" can be infidels.

Is there a word for things that only other people can be? The one that always comes to mind is "tourist".

Is there a word for things that only other people can be?

Kinda along similar lines: expats vs. immigrants.

"Oh no, Paul and Iza are expats. Not at all like those job-stealing immigrants who moved in next door..."

(aside: does wrong fit your original question?)

Re: The Ashley Madison Database Was Leaked

#105
post #99
post #78

Earlier quoted context omitted.

I can confirm it tested negative for negatives, and positive for a positive.

barack.obama@whitehouse.gov is in there (and verified, whatever that means), as is tblair@labour.gov.uk (unverified), pointed out by zerohedge.

I assume "verified" means that Ashley Madison's server sent a verification email to that address, and the user at that address clicked on the verification link included in that email.

Certainly, someone might enter in barack.obama@whitehouse.gov for fun. Presumably, emails to that address (and the official public email address, president@whitehouse.gov) get routed somewhere. But who is checking the emails sent to the president's public address? That likely requires a team of people, one of whom might have clicked on the link.

Re: The Ashley Madison Database Was Leaked

#106
post #62

Earlier quoted context omitted.

From a business point of view, and like any company, they're matching a need with a service at a profit. But everyone has their own preferences and boundaries. Society generally frowns upon affairs, but if your own morals allow you to create that sort of business, it's your choice.

> Society generally frowns upon affairs Than why is everyone doing it?

Ok, I think people are misunderstanding what I've said. I'm not taking any sides here. What I'm saying is that everyone has their own moral codes which can differ from what's dictated by society (morals aren't the same as ethics). There are going to be people who cheat but that doesn't mean everyone does. Look at laws. People break them. But not everyone.

As for AM as a business, I mentioned that everyone has their own preferences and boundaries. Some people won't create anything involving gambling, adult, etc. but others are okay with it. The same can be said for what the AM founder created. We don't have to like what he's made. We don't have to agree with the business model.

Re: The Ashley Madison Database Was Leaked

#107

Earlier quoted context omitted.

Bcrypt includes a (large) random salt so is not subject to rainbow table attacks. I believe therefore that will protect against identifying passwords contained in a known list. If I'm wrong about this I'd love someone to explain why to me.

It does prevent simple rainbow attacks, but it does not prevent a simple bruteforce of the common passwords. It can increase the cost a bit, but still in the realm of feasible. I am mainly trying to warn against the false sense of security. Salting does not magically make weak passwords secure. It makes certain types of attacks harder, but a bad password is still bad.

That being said the problem is less that we are not asking users to provide strong enough passwords. It is that the industry seems to be completely incapable of protecting their users data. This race to the least crackable hashing algorithm is only adding more lipstick on the pig.

Having seen a major leak pretty much every week if not every day the past 3 years, I am now of the opinion that I should provide zero personal information to anyone. Disposable email addresses, fake names and address will now be my norm.

Re: The Ashley Madison Database Was Leaked

#108

Heh. If I were Ashley Madison, and I wanted to create plausible deniability for people in the real dataset, you know what I'd do? I'd create and "leak" a bunch of other datasets with generated data, and data pilfered from other hacks, to muddy the waters. "Oh, my name's in there? That must be faked up data from the Playstation Network hack years ago. Of course I'd never sign up to Ashley Madison, Mr Journalist."

Agreed; it would be insane of them not to.

Re: The Ashley Madison Database Was Leaked

#110

There's something poetic about people who use an Internet based service to commit adultery being exposed by crackers. With luck the fallout will break Ashley Madison too.

Repost from a different, and now I think abandoned, thread: I'm curious - I keep getting downvoted whenever I criticise Ashley Madison on the grounds of morality. Why is this? This isn't a whinge about downvoting (if I didn't want to get downvoted I wouldn't keep posting about A-M), but a genuine inquiry into the reasons. Is it that people see discussions of morality as off-topic for HN? Do people disagree with my mo…

> I keep getting downvoted whenever I criticise Ashley Madison on the grounds of morality. Why is this?

Because although most people agree with you, your statements are not considered as interesting. Presumably because they're considered as trivially true. Votes aren't about whether what you wrote is true/false, but whether reading it provides some insights to readers.

If you commented "War in awful!" under a war-related post, you'd be downvoted too, not because people find war awesome, but because reading such a truism give no valuable information to anyone.

Post reply on HN