Looking For Love; Finding Privacy Violations
itwbennett writes "When you sign up for online dating, there's a certain amount of information you expect to give up, like whether or not your weight is proportional to your height. But you probably don't expect that your profile will remain online long after you stop subscribing to the service. In some cases your photo can be found even after being deleted from the index, according to the electronic frontier foundation (EFF), which identified six major security weaknesses in online dating sites."
In a lot of systems, deleted simply means marked as deleted. What the system does with that information is another matter. Even in a file system, when a file is deleted, it is many times recoverable if it hasn't been overwritten with other data.
"Deleted from the index" does not mean the file was deleted. If I rip the table of contents and index out of a book you could still find each page by flipping through them.
I have several honeypot email accounts, and one kept getting emails that suggested it was somehow a member of a French on-line dating/introduction service.
The web site had no way to delete one's account, nor did the proprietors respond to emails.
My solution? I logged in and updated "my" personal information. I got nasty, every bit of the sickest crap I could think of.
They pulled my account within the hour. :-)
...laura