Rendered at 06:59:33 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
Shank 2 hours ago [-]
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
happosai 1 hours ago [-]
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
I'm assuming they're basing this on the no-passwords part.
sidrag22 2 hours ago [-]
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
samus 2 hours ago [-]
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
nilslindemann 56 minutes ago [-]
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
MiroslavPokorny 33 minutes ago [-]
Hack or scraping, both are equally bad.
m00x 28 minutes ago [-]
uh oh. If my ELO gets back to my friends I'm going to be very embarrassed.
TheSpacerr 2 hours ago [-]
Basically our data is free.
zx8080 25 minutes ago [-]
Peasants have no rights and shall be slaves.
ed_mercer 2 hours ago [-]
email? Is a user's email up for grabs just like that?
It sure seems like the evidence doesn't point to scraping to me.
https://infosec.exchange/@haveibeenpwned/117263977537458510
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.