Technical Issues

POF and eVow Down for for the Morning of March 27, 2014

Technical Issues
  • Friday, March 28 2014 @ 07:51 am
  • Contributed by:
  • Views: 2,260

It looks like yesterday morning Plenty of Fish and its sister site eVow was down for about 4 hours. POF.com went down sometime after 6am and was revived around 11:30am. Visitors at our forum and elsewhere on the internet reported receiving a "500 - Internal server error" when they visited the site. The dating app was also reported not working during this time period.

A 500 error code is a catch all error message that web servers reports when something has gone wrong and the server is not sure what it is. It is not a problem with the visitors browser or DNS but an issue with the web server where the web site is hosted.

POF has not reported why the outage has happened. From previous experiences we do not expect an answer.

The last major outage that spanned more than 2 hours in which we know of for Plenty of Fish was in Aug of 2010 (see Story). 2010 wasn't a very good year for POF.com in terms of uptime as they experienced 3 major outages.

Use Tinder? Your Exact Location May Have Been Exposed

Technical Issues
  • Friday, March 28 2014 @ 07:43 am
  • Contributed by:
  • Views: 1,766

Bad news for Tinder fans: all those creepy people you've been avoiding on the app may now know exactly where you are.

It turns out the dating app suffered from a bug for most of last year that would've allowed hackers to determine the exact location of its users. And Tinder chose to cover it up until just a few weeks ago. The information security firm Include Security exposed the security vulnerability in mid-February, saying that anyone with the right kind of knowledge could "get the exact latitude and longitude coordinates for any Tinder user" provided that the app was running.

Hello, major privacy violation!

The company confirmed that "anyone with rudimentary programming skills could query the Tinder API directly and pull down the coordinates of any user." From that API data, it is then possible to triangulate the exact location of the user with a very high degree of accuracy. We're talking within 100 feet. And remember that part where they said "rudimentary programming skills?" So not only can creeps get incredibly close to you, they don't even have to be smart creeps in order to do it.

So much for the fun of all that mindless swiping.

It’s a bad bug, for sure, but before you go cursing the day Tinder hit the app-mosphere, Include Security also noted in an FAQ on its disclosure blog post that these flaws can be "common place in the mobile app space" and will “continue to remain common if developers don't handle location information more sensitively." Is that more comforting or less comforting? I'm not actually sure…

What I am sure of is that Tinder should not have failed to disclose the vulnerability when it was privately reported. Users deserved to know that the security of their location data was potentially compromised, even though the bug was fixed sometime between December and January.

Your questions now are probably "Has anyone actually exploited this?” and “Can I tell if someone has tracked me using this privacy vulnerability?" According to Include Security’s post, “there is no simple way to determine if this attack was used against a specific Tinder user." In other words, nope – you have no way of knowing if that slightly unbalanced-looking person you just rejected is about to come knocking at your door.

Good luck sleeping (or swiping) with that on your mind.

See a demo of the Tinder vulnerability at work:

Hack of Cupid Media May Have Exposed Your Password

Technical Issues
  • Thursday, January 09 2014 @ 06:48 am
  • Contributed by:
  • Views: 1,892

Somewhere in the back of our heads, rattling around with all the other information we ignore like "You really shouldn't drink that last shot of tequila," we know that having an online account means accepting the risk that that account might be hacked. But no matter how many times we hear horror stories of it happening to someone else, we never quite believe it could happen to us.

Imagine the surprise, then, that Cupid Media users must have felt when the service was hacked early in 2013 and the names, e-mail addresses, and plaintext passwords for 42 million accounts were exposed. Ouch. That has gotta sting.

Ars Technica reports that "The cache of personal information was found on the same servers that housed tens of millions of records stolen in separate hacks on sites including Adobe, PR Newswire, and the National White Collar Crime Center." An official from Cupid Media explained that the hack appeared to be connected to "suspicious activity" that was detected on the site in January and officials say they believe they have notified all affected users, but those actions and explanations are likely to do little to appease users whose personal information has been compromised.

The Cupid Media hack will go down in history as one of the largest passcode breaches on record so far, a dubious distinction made even worse by the fact that the data was in plaintext, rather than a cryptographically protected format that requires significant effort to crack. Because many Internet users reuse the same passwords on multiple websites, a hack on this scale can give thieves instant access to tens of thousands of sensitive accounts tied to a user's e-mail address.

"Making matters worse," Ars Technica speculates, "many of the Cupid Media users are precisely the kinds of people who might be receptive to content frequently advertised in spam messages, including male enhancement products, services for singles, and diet pills."

And making matters even worse than that, a review of the Cupid Media user records that were exposed reveals that a significant portion of them were protected with weak passwords in the first place. More than 1.9 million accounts were protected with the password "123456." Another 1.2 million used "111111." How is it that, in this day and age, there are still people who think those are secure passwords? Have they never seen the Internet before?

Take note, online daters: the more random your password is, the safer it is. And please, please, never use the same password on multiple sites.

It’s Shockingly Easy To Hack Your OkCupid Account

Technical Issues
  • Friday, October 11 2013 @ 07:14 am
  • Contributed by:
  • Views: 20,582

In fact, it's so easy that I'm not sure it can be called hacking. It doesn't even have to be done intentionally - just one little oblivious click, and suddenly someone else is logged in under your username.

It works like this: when OkCupid sends you an email, any links included inside the email contain a unique identifier called a token. When you click the link, you are automatically logged into your OKCupid account without having to enter your password. The point is to make it as easy as possible to get into your account, but it also makes it worringly easy for someone else to do the same thing.

A writer at The Verge discovered the security hole after receiving a forwarded OkCupid email from a friend. After reading the funny message her friend had received from a prospective suitor, she clicked on the message to see the suitor in question.

"Suddenly," she writes, "I was in my friend's account, staring at all her read and unread messages. I could see her instant messages. I could edit her profile. Just because I had clicked on an email sent to her, OKCupid thought I was her."

Although your friends probably won't do anything unscrupulous if they land in that situation (you hope!), it might not be your friends who unexpectedly find themselves logged into your account. In another case, a woman blogged about an OKCupid user and included a link to his profile that she copied from her email. Unbeknownst to her, any reader who clicked on it would then be instantly logged in as her.

There may be a little karma involved here - because it doesn't seem very nice to publically blog about a user and include a link to their profile - but no one wants to give every stranger on the Internet access to their online dating profile. The token does expire eventually, but no one has yet determined how long it remains active.

Naturally, the OkCupid forums have exploded over this. In one discussion thread, a user writes "This totally defeats the purpose of having a password for the site. If anybody happens to be able to read my email, they are then able to see my full OkCupid account. Hello, what kind of account security is this?"

The thread has been active since 2009, so as incensed as OkCupid users may be, the site doesn't appear to be in a hurry to address the issue. Although "Login Instantly" is not a new feature, it is perhaps not the wisest choice for a social network, dating site, or other online destination that contains such personal information.

Think twice next time you're tempted to make fun of a fellow online dater by forwarding their hilarious message on to your friends. Stick to screencaps or - here's a really radical idea - just be nice and don't do it in the first place.

Plenty of fish Forums Gone.. Again!

Technical Issues
  • Friday, April 26 2013 @ 10:42 am
  • Contributed by:
  • Views: 6,096

A concerned visitor sent me an email the other day asking what has happened to the Plenty of fish forums? Did they shut down? I was like oh no not again, they have done something to the forums on POF. I still noticed the forums coming up in the search results so I visited forums.plentyoffish.com directly and was greeted with a nasty server run time error.

Now I know a bit about web servers and this is a Microsoft Internet Information Server (IIS) error. This is not good (see the full explanation below) because it indicates to me that the files for the Plenty of fish forum website has been removed. After further investigation it looks like this may have happened at least a week ago, since visitors have been searching our site about the Plenty of fish forums being removed for that long.

I am surprised that POF hasn’t addressed the problem. They must know about it as I am sure a large number of people have already complained about the issue as it has been a week now already. Also the POF forums are still very popular even though they are not directly linked to the main POF.com site anymore (I think POF wants to slowly kill the forums). What has me puzzled though is if they had plan to stop providing the forum, why not remove the website and domain record all together or at least display a nice message about the situation and the reason for the removal (which would take 2 minutes to do). Displaying a runtime error isn’t very professional. Heck even a redirect to the main POF dating site would have been better.

Update: After checking the POF forums off and on for the last hour it appears that this is an intermediate problem. About half the time I get a runtime error, about a quarter of the time I get some other one line text error and for the other quarter of the time the forums actually work. As I said before this has been happening for at least a week since others have reported on it.

I have a thought, let’s start a campaign to see if we can get Plenty of fish to fix the forums. I am going to tweet about this story on Twitter using the hashtag #FixForumsOnPOF. If you want POF to keep the forums alive like I do, then re-tweet my tweet or post your own using the hashtag. Maybe if POF is listening they will do something about it and fix the problem with the forums. 😊

In the meantime since you can’t use the POF forums all of the time you are more than welcome to post your relationship and online dating questions and observations in our dating forums. We have a number of forum categories you can post in about a whole pile of different topics.

So, what does the runtime IIS error mean that most people seem to be getting? It actually is 2 errors in one. The web server is complaining first about their not being a custom error file in the location specified to display to visitors when an error happens. The second error actually triggered the first error. The second error is harder to figure out since the current error message is all about the first error. The second error is some sort of application error which could be anything from the actual website files not being available to a coding error in the requested web file. Since an error message is displayed it does indicate that webserver is working properly and that there is nothing wrong with the domain record.

If you are looking for a popular free dating site to try and want some more information then you should read our Plenty of fish review.

Christian Mingle is Down - March 21, 2013

Technical Issues
  • Thursday, March 21 2013 @ 12:14 pm
  • Contributed by:
  • Views: 2,116

I just notice that my connection has timed out when I tried to visit ChristianMingle.com. I first notice the problem at 12:05pm today. I am not sure if the site is too busy or that Christian Mingle's web servers are offline due to a hardware or software problem.

We will update this post when we get more information.

Update #1: As of 12:23 pm EST a message comes up stating that the site is momentarily down and to try back again shortly. No reason is given for the outage though it obviously is not their internet connection since they can serve the problem page. The Christian Mingle customer service phone number is also given: 1-866-660-7924

Update #2: I just checked (1:33pm) Christian Mingle is back up and working fine. They were still down at 1:00pm so it looks like ChristianMingle.com was down just 1.5 hours or so.

Page navigation