Privacy

Adult FriendFinder Hack Exposes 412 Million User Accounts

Privacy
  • Tuesday, December 06 2016 @ 10:25 am
  • Contributed by:
  • Views: 3,196

A hack against popular adult dating and entertainment company FriendFinder Networks has exposed personal data linked to more than 412 million user accounts. The breach is one of the largest in history, and marks the second such incident at the company in two years.

Nearly 340 million accounts from the company’s flagship site, Adult FriendFinder, were compromised according to a report from LeakedSource. The hack also targeted other sites owned by FriendFinder Network, including Cams.com, and records from Penthouse.com, which was sold in February.

The Adult FriendFinder data stretched back 20 years. Information such as usernames, emails, and join dates was stolen, along with account passwords (the majority of which featured unsecured protections or none at all) and membership data like VIP status and browser information. The cache also appears to include 15 million email addresses from deleted accounts.

Tinder Finally Setting Age Restrictions for its App

Privacy
  • Wednesday, July 27 2016 @ 07:26 am
  • Contributed by:
  • Views: 2,655
Tinder

Tinder, one of the world’s largest dating platforms, has been available to users as young as thirteen since the app launched almost four years ago. Tinder’s practice of letting teens use its app has been an anomaly in the industry, and one that hasn’t gotten as much attention as its reputation for quick hook-ups. But as of this month, the company has raised its minimum user age requirement up to eighteen.

This leaves many people asking: Tinder, what took you so long?

Online dating has been the subject of both opportunity and scorn in recent years. It's been a great way for people in different social circles to meet and expand their networks, but it has also posed a security risk, mostly due to a small percentage of users misleading other online daters by setting up fake profiles. Understandably, this has caused concern among parents whose teenagers have been using the popular dating app to find others to meet.

Tinder’s age verification is tied to Facebook, and the app has only let users who are younger than 18 see other users who are between the ages of 13-17. This would be fine in theory, but in practice it’s another story. This works only if the underage user has also set up a Facebook account with an accurate profile in which they reveal their real age. However, there is room for abuse if someone sets up a fake profile on Facebook, claiming to be eighteen or older, in order to continue using the app while underage.

Also understandably, this poses a problem for Tinder users who are reaching out to other users who they believe are age appropriate, only to find they are still teenagers. So while the restrictions are a move in a positive direction, it’s not a foolproof protection against fake profiles and catfishing.

All of the other popular online dating sites, including Match, eHarmony, and POF (Plenty of Fish) have had restrictions in place from the beginning when it comes to the ages of their users, and they all have a minimum requirement of eighteen. POF takes it one step further – if you are a female between 18-21, no guys over 30 years old can message or contact you over the service.

Tinder is attempting to make its platform a little more user-friendly, female-friendly, and age appropriate. It is also aiming to make daters of all sexual and gender identities feel more welcome. Recently, the company announced its plans to include transgender identification in profiles along with preferences.

So why did Tinder allow younger daters to use its app? Like all online dating services, it’s about the numbers. But since Tinder has a popular brand and large database of users now, it’s time they put the restrictions in place.

For more on this dating app, chck our our review of TInder.

Tinder Social Feature is Outing Tinder Users in Your Circles

Privacy
  • Wednesday, July 13 2016 @ 07:51 am
  • Contributed by:
  • Views: 1,665

Tinder is looking to be more social – or at least hook you up along with your group of friends to connect with other friend groups out in the real world. The problem? Tinder users are being opted in to this feature by default, so you don't have a choice. Which means Tinder Social automatically displays which of your Facebook friends are also using Tinder.

This can make for some awkward conversation, especially for those who would rather keep their dating practices private.

To make matters more uncomfortable, Tinder Social presents a list of your friends along with their dating app profiles so you can not only see they are using the app, but how they are presenting themselves on Tinder. (Sexy photos, anyone?)

And worse yet, some Tinder users think Tinder Social is a way to meet others for group sex (and considering the whole hook-up reputation, it’s not that far of a stretch).

The new feature is only in the testing stages in certain parts of Australia, so chances are you haven’t encountered the feature just yet. This will give Tinder some time to refine it. The company will need to make some changes to reassure people about their privacy on the app. Over the years, it has stressed to users that their social networks would not be compromised, and that anything they do on the app wouldn’t be seen on Facebook or in their other social networks.

While there’s currently a way to opt out of the friend-finding feature, Tinder users are automatically opted in, so you actively have to disengage. A good fix would be to make it an opt-in feature only, so Tinder doesn’t risk alienating users who didn’t realize their profiles were being put on display among their social media friends.

Finding circles of friends seems to be a new wave in the dating app space, and an untapped market for an already attentive dating app population. CEO of Bumble Whitney Wolfe announced the company would be unveiling a similar group friend-finding feature on their app, and Grouper, a dating app that’s been around for a few years, offers group dates for people who don’t want the pressure of one-on-one dating. There’s also MeetUp, a networking site that has been around for a while to help people find friends in their communities through activities and other interests.

Many other apps are jumping on this new friend-finding bandwagon, hoping to capitalize on the social networking market. We’ll see if Tinder or another app can get people excited about the friend-finding potential of apps.

 

Researchers Published (Then Deleted) Data From 70,000 OkCupid Users

Privacy
  • Tuesday, July 05 2016 @ 07:38 am
  • Contributed by:
  • Views: 2,265
Research on OkCupid

A team of Danish researchers caused an uproar last month by publishing data from the online profiles of nearly 70,000 OkCupid users. Information including usernames, political leanings, drug usage, and intimate sexual details were exposed, creating a massive privacy crisis.

The researchers, Emil Kirkegaard and Julius Daugbjerg Bjerrekær, used data scraping software developed by a third contributor, Oliver Nordbjerg, to collect the information. It was used for a study that analyzed members of OkCupid across a variety of factors. The database was posted along with a draft paper on Open Science Framework, a “scholarly commons” that supports open source research and collaboration.

Fling.com Hack Exposes Passwords (And More) Of 40 Million Users

Privacy
  • Wednesday, June 22 2016 @ 06:52 am
  • Contributed by:
  • Views: 6,474
Password Security

Fresh off the news that BeautifulPeople.com had been hacked comes another tale of privacy violation. This time, Fling.com is the victim of the breach.

International Business Times reports that tens of millions of credentials were stolen from the adult dating website and put up for sale on the dark web. The information allegedly includes usernames, plain text passwords, email addresses, IP addresses, gender, sexual preferences, and date of birth records. It appears that some of the accounts belong to Fling administrators.

According to the hacker responsible for the breach - who goes by the pseudonym ‘peace_of_mind’ - the data dump contains more than 40 million Fling.com records. It’s currently on sale for 0.8874 bitcoins, which is worth approximately $411 at the time of writing.

Vice Motherboard obtained a sample of the data from the hacker. The individual to whom the Fling.com domain is registered then confirmed its legitimacy.

“We take internet security very seriously,” he wrote in an email to Motherboard. “Our site is free to join and we do not store any credit card information. We've investigated the sample data and it is from a breach that happened in 2011.”

Motherboard also shared the sample data with security researcher Troy Hunt, proprietor of the breach notification website “Have I Been Pwned?” Using HIBP, Hunt discovered and contacted two victims of the Fling breach. One confirmed their full password in the sample. The second claimed they had no recollection of joining the site, but said the beginning of the password was something they have used in the past.

On the bright side, some of the email addresses in the sample did not appear to belong to any Fling accounts. Motherboard tested 101 addresses and found that only 61 were already in use.

Additionally, some of the accounts included in the data may have been disabled prior to the breach. “Accounts in the sample were also flagged with settings such as ‘admin_disabled,’ ‘user_disabled,’ or “active,’” writes Motherboard. “However, these flags seemed to have no bearing on whether an email address was already in use or not on Fling.”

Continued investigation provided further reason to believe that not all the accounts for sale are valid. Motherboard found that accounts can be created on Fling without clicking a verification link sent to an email address. They also found that Fling passwords are required to include numbers, though many passwords in the sample data only contained letters.

To be on the safe side, anyone who has used Fling.com should change their password - particularly if it has been used for more valuable services, like an email account or bank account.

BeautifulPeople.com Hacked & Personal Data Sold

Privacy
  • Friday, May 27 2016 @ 09:38 am
  • Contributed by:
  • Views: 1,406
BeautifulPeople.com was Hacked

BeautifulPeople.com boasts that it offers “online dating for beautiful people only,” but it’s currently making headlines for something far from pretty. The site was recently attacked by hackers who put the personal info of 1.1 million members for sale on the black market.

According to security expert Troy Hunt, the data belonged to members who joined before July 2015. Information like weight, height, job, and phone number was reportedly compromised, though no passwords or financial details were included.

"The breach involves data that was provided by members prior to mid-July 2015. No more recent user data or any data relating to users who joined from mid-July 2015 onward is affected," Beautiful People said in a statement. "As far as we were aware, at that time [in December 2015], only the two security researchers who informed us of the breach had access to this data."

Chris Vickery, who originally discovered breach, told the BBC the firm acted quickly after he notified them - but it was already too late. "They published it openly to the world with no protection whatsoever," he said.

Like the Ashley Madison hack – which exposed 39 million people hoping to cheat on their partners – there’s a sense of schadenfreude to the news. A part of us enjoys seeing “bad” people (or in this case, people who have an inflated sense of their own goodness) get knocked down a peg. We call it karma, but what it really is, is a warning.

Hacking is a scary phenomenon no matter what, and doubly so when it’s done with the intention to shame. Online dating is now so commonplace that many users have grown lax about how they do it. Theoretically we know we need to protect our personal information, but how much effort do we really put into it? Our data is bought and sold constantly, whether we know it or not, both legally and illegally. Let the Beautiful People hack be a reminder to prioritize your privacy.

The good news is, the company says the leak has since been patched. But there’s no way to reclaim the data that’s now circulating. Victims of the hack must now take precautions like changing passwords and monitoring for identity theft.

Beautiful People said all affected members are being notified about the breach. You can also use Troy Hunt’s HaveIBeenPwned.com to find out what, if any, personal information about you is publically available online.

Page navigation