Rendered at 05:55:20 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
Shank 1 hours ago [-]
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
happosai 11 minutes ago [-]
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
I'm assuming they're basing this on the no-passwords part.
sidrag22 1 hours ago [-]
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
samus 41 minutes ago [-]
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
TheSpacerr 39 minutes ago [-]
Basically our data is free.
ed_mercer 42 minutes ago [-]
email? Is a user's email up for grabs just like that?
It sure seems like the evidence doesn't point to scraping to me.
https://infosec.exchange/@haveibeenpwned/117263977537458510
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.