Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping

(securityaffairs.com)

21 points | by kristianp 2 hours ago ago

7 comments

  • Shank an hour ago ago

    > Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.

    It sure seems like the evidence doesn't point to scraping to me.

    • emodendroket a minute ago ago

      I'm assuming they're basing this on the no-passwords part.

  • sidrag22 an hour ago ago

    > The data had been pulled by abusing the platform’s find-friends feature

    Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.

    • samus 21 minutes ago ago

      It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".

  • TheSpacerr 19 minutes ago ago

    Basically our data is free.

  • ed_mercer 22 minutes ago ago

    email? Is a user's email up for grabs just like that?

  • unixhero an hour ago ago

    Is scraping wrong that, is the question.