> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
https://infosec.exchange/@haveibeenpwned/117263977537458510
I'm assuming they're basing this on the no-passwords part.
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
Basically our data is free.
email? Is a user's email up for grabs just like that?
Is scraping wrong that, is the question.