Hackers Publish Cheating Site's Stolen Data
pdclarry notes that many news outlets are reporting that 9.7 GB of data stolen from cheating website AshleyMadison.com has been published online. "The dump contains files with titles including 'aminno_member_dump.gz,' 'aminno_member_email.dump.gz,' 'CreditCardTransactions7z,' and 'member_details.dump.gz,' an indication that the download could contain highly personal details." Brian Krebs questioned the way this has been reported without confirmation, but added that he's been contacted by several people who found their own accurate details within the data dump. Many of the reports note this detail: "Assuming the download turns out to be authentic, people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals."
Usually all sites will send a confirmation email and only enable the account if a confirmation link or code from that email is used.
So i guess it's a bit hard to "create an account using the ... e-mail address of other individuals"
Faithful is one of life's top priorities. Without trust, you are a decoration at best.
Assuming the download turns out to be authentic, people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals.
...And supplying other people's credit card details as well, no doubt.
FWIW, I believe that people's sex lives are their own business, married or not. But I find it difficult to drum up any sympathy for marrieds who are foolish enough to go looking for something on the side via a big flashy commercial website dedicated to that purpose.
Internet privacy was over at least a decade ago. There's been plenty of time for you to figure this out.
Il n'y a pas de Planet B.
Humans can live however they want. These humans did. They just couldn't admit it.
That list is extremely salted.. or filled with fakes... it is definitely not a list of only paying customers
"Information wants to be free".
The idea that AshleyMadison (or any other entity) would keep registration information private forever was laughable. My rule of thumb is that if I don't want what I do to be published all over the internet, then don't do it.
You are all cows. Cows say Mooo. Mooo Cows Mooo! Mooo say the cows. YOU COWS!!!
I just felt a strange disturbance in The Force, as if a million divorce lawyers suddenly yelled out "CHA-CHING!" and then... yelled out "CHA-CHING!" again!
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Ashley Madison rebrands itself as "Cheating Liar" dot com, reality show on the way.
Except AM specifically did NOT so as to help avoid leaving a trail.
One of my friends is on this list because I created his account for him as a prank.
I am lothario donchuno. Me with Soulskill now for all to cheer.
Onion: http://yuc3i3hat65rpl7t.onion/stuff/impact-team-ashley-release.html
"...people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals.
Says the journalist who spends an inordinate amount of time doing "research" on the Ashley Madison site.
The point of the hackers is not to point out the moral decay of society, but to point out that AM are really scammer, with the number of real males on the website greatly outnumbering the number of real women.
It's not a prank, it's identity theft, either a felony or a misdemeanor.
Ashley Madison hack: hackers claim cheaters' details dumped online
I have an account on AM with a phony identity, though, I never gave them any CC information. Let me finish to download the leak and I'll check if I'm in the leak :-)
Anyone detect a massive case of projection here? "Freethinking people"? As in, people who think freely and disagree with Ashley Madison's position? Why is it always "freethinkers" are on the despicable side of things? You'd think that actual free thinking would mean that you were free to think whatever you wanted instead of being required to arrive at a pre-arranged conclusion - one that Ashley Madison arrived at. "Forcing their ideology"? WTF is that all about? Sounds to me like they can't handle the fact that the world is a big place and there might be people out there who disagree with them. Shocking, eh?
Sanctimonious: making a show of being morally superior to other people.
Shutting down free speech with violence isn't fighting fascism. It IS fascism!
very useful website, however you can find more resources on http://foundation4knowledge.blogspot.com/ and http://foundation4knowledge.blogspot.com/p/home.html for learning more
In what way is this a prank if your "friend" doesn't ever get notified he even has an account there?
Slashdot social media options: AIM, ICQ, Yahoo, Jabber and Mobile Text. Why no MySpace?
This is a Doctorow quote, he is a fucking idiot, world class.
well the second part of the prank was obviously to hack and publish the user database.
a pretty elaborate prank I must say, I salute!
world was created 5 seconds before this post as it is.
Now let me see the transactions of the other 2000 guys that use my credit card. Gonna be back in a while!
Somebody creates accounts using or linking my email address (and which I have not confirmed) all the time.
And this happens even with big companies who should know better. Microsoft, Skype, Twitter, Banks, etc.
If you don't want to get caught cheating, then don't fucking cheat.
These morons deserve to have their details posted.
"Nine times out of ten, starting a fire is not the best way to solve the problem." - my wife
If you download this list is it considered possession of stolen property?
Also can anyone check if the name Ed Danner is on there? Asking for a friend.
Cheaters really should just suck it up. I mean, yeah it is their own stupid fault in cheating.
Next lets go for the bot boxers, their servers should get hacked next, bring down all forms of gaming cheating!
Wait, what do you mean this has nothing to do with computer games? Da fuq?
...
Wow...what a dick move. You're sure he's your friend?
That's a sociopathic action for sure. You need to have a brain scan to confirm it. Do you do this sort of thing often?
Shutting down free speech with violence isn't fighting fascism. It IS fascism!
Cheaters play in the shadows because the thrill of "outsmarting" their partners breathes excitement in to their lives. It's a selfish form of thrill-seeking.
It's nothing more than a particularly cruel expression of kleptomania.
Speaking as a former thief: don't waste your tears on people who lose a game they initiated. "Might makes right" follows the same ethos/morality. It's equally satisfying watching karma catch up with cheaters as it is to watch a thug start a fight with the wrong victim.
These victims deserve privacy like shoplifters deserve a merciful store owner.
I'm afraid most of the "available women" I met were barely concealed hookers. The site's a scam.
Usually all sites will send a confirmation email and only enable the account if a confirmation link or code from that email is used.
So i guess it's a bit hard to "create an account using the ... e-mail address of other individuals"
Yeah but we need to state it anyway because we don't want report of men beating their cheating wife going up over night. Help the poor women justify their actions, it for equality after all.
Everyone knows nobody remained married in the US after F*ckfacebook came out and everyone who ever had a peg in a hole of your significant other or visa cersa suddenly had method and means to chat them up for a sympathetic ear (booty call, every time) the minute you were out of the house for more than 8 hours. /sarc
I call BS because CC Transactions are _never_ stored in a .7z file.
It's just common sense.
He's taking the fall for his buddy. Friends don't come much better than that.
Marry girl children.
Not "Ashley Madison"s
Can't believe cunts decide anything they do is wonderfun, including adultery.
Hans Reiser did nothing wrong.
He did the correct thing under the Law of the God of Deuteronomy.
I'm happy he killed Nina Reiser. She looked to cuck him, he wasn't having that. She is dead. I pray the cunts that support her meet a similar fate.
So was this site free? No CC info?
I love Jesus, except for his foreign policy.
However legit accounts may have other identifying info. CC numbers, profile pics and text with personal info. I think for many there will be enough data points to ID if not in a court of law then in a court of spouse.
Silence is a state of mime.
well the second part of the prank was obviously to hack and publish the user database.
a pretty elaborate prank I must say, I salute!
This hacker/prankster should be easy to find, he probably reads Slashdot uses an Android phone and had a girlfriend (that last fact should shorten the suspect list considerably). Oh, and he probably only got angry enough to hack AshleyMadison.com because she cheated on him with an Apple iPhone using hipster.
"...people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals."
People should also remember it is very difficult to randomly generate a VALID credit card number.
Sites like this use credit card numbers to "confirm" the age of the individual signing up (I know, I know, having access to Daddies' CC isn't proof of age, etc.).
Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
Only it's done in a country which has felonies and misdemeanors. The post didn't specify.
sociopath is a term deprecated back in 1968 (when it was coined as part of the Bell defence which FAILED because it was BULLSHIT), no legitimate psychologist or psychiatrist uses the term.
Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
Nah, evidence is not required for a court of spouse. You get accused of something outrageous you couldn't possibly have done and you're guilty anyway.
I do wonder though how many people are going to be on those lists who never signed up for the site, whether because of 'pranks' like someone else said or just because the thief may have put fake data in the files our just made up the files. Anything is possible but that won't matter in the court of spouse.
To me, just another reason to never use social media, dating sites, or anything else like that. It's one thing, and also inexcusable, for any company to lose a customer list ever, but sites that are actually supposed to make your info available to others are just extra risk waiting to happen.
My gmail address gets used as a throwaway rather a lot, and you'd be surprised at the number of sites that don't bother at all.
This message was sent to you ($foo@gmail.com) because you are a valued NBA fan registered with us and we wanted to wish you a happy birthday!
Hi meleonaz,
www.skype.com
Registered email successfully updated
Your email address for the account meleonaz has been successfully updated to $foo@gmail.com
Hi @notme345,
We got a request to reset your Instagram password.
Thanks so much for joining Pandora! We're very happy to have you on board, and we look forward to providing you with endless hours of great music listening and discovery.
Many more sites will still create the account and let you use it without me validating the email, and many more provide no means of saying this *isn't* their email.
I guess these Ph.Ds need to stop using the term then.
https://www.psychologytoday.co...
http://psychcentral.com/blog/a...
http://www.webmd.com/mental-he...
Oh, and they need to remove it from the DSM
http://dsm.psychiatryonline.or...
Just another day in Paradise
For what it's worth, more than 15,000 of the e-mail addresses are hosted by US government and military servers using the .gov and .mil top-level domains.
I wonder how many federal employees will be losing security clearances as a result of this?
Exactly this. I get crap mail from Best Buy, Enterprise Rental Car, and several others, because they're too damn lazy to do their jobs.
Just another day in Paradise
This is a piss poor attempt to give the significant other a lame excuse...
"But darling... it was possible for anyone to create an account using the name and e-mail address of other individuals.".
Yeah right :)
I said legitimate.
Thanks for proving my point.
Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
That for starters depends on the laws of your locality.
Secondly, person registering the account can very well argue they used a pseudonym. Many a pseudonym is a realistic name, and as such can very well happen to match the name of someone else. People that happen to have identical names are a similar case.
It would definitely be identity theft if the person not only uses another person's name, but tries to completely impersonate another individual. Just registering using a name that's not your own is not identity theft, imho.
No, you just proved that you're an idiot. If you don't know what the DSM is, you shouldn't be commenting on this.
Just another day in Paradise
Using someone else's email for it pretty much shoots down the argument that it was a pseudonym.
This dump has already been called out as fake
http://krebsonsecurity.com/201...
I know what the DSM is, it's that volume which claims that simply disagreeing with authority is a mental illness and that anger is something that can be drugged out.
Bring legitimate examples to the table and leave the ad hominems at the fucking door.
Political debates have me rolling my eyes so much I think I got optical whiplash. I should sue. - Foamy The Squirrel
I hope you never get upset at stories like "school replacing wood chips with bubble wrap", because you are the reason everything escalates legally so much in this country.
Yeah, me too. AT&T, some casual labour placement place in Phoenix, I even get alarm armed/disarmed/etc. notifications from some woman's house in the NE US. Not to mention the elementary school class parents' mailing list that sent me name, phone number, address, parents' names for all the kids, plus schedules for upcoming events.
People and companies should be more careful.
I find it absolutely hilarious when slashdot plays lawyer. Stick to tech brother
Please provide examples of legitimate psychologists or psychiatrists or organizations. I'm genuinely curious.
Agreed, if you would indeed (have to) use that other person's e-mail, and supposedly gained access to that person's inbox, it'd clearly be identity theft.
However in this case, that's not necessary to register an account.
If they are Civilian GS, SES, etc., probably few or none; if they are contractors, they are screwed. Whoever has the AM list and the stolen SF-86 list has a gold mine for extortion.
Thanks.
I'm totally using this excuse when my wife finds my name on that list.
Ah the "everything's a felony" crowd has shown up.
Pull your head out asshole.
You seem to confuse legitimate with "agreeing with me".
DSM may not be a perfect tool. But if something is in there it will be considered legit untill there is a campaign to show that it is controversial.
Hi, I'm just a random person on the internet, I was reading this and I couldn't help notice you we're being a massive douchebag, and I decided to just drop by and give you some notice of your inane fuckery. So that happened.
(and way to be an asshole "oh no legitimate way *get's pointed to a fuckton of legitimate uses* "oh no I mean 'legitimate' use" provides no idea what his idea of "legitimate" could possibly be"
P.S.:Also, those of us who took criminal psychology courses were still taught the term psychopath and sociopath and their very specific meanings you massive tool.
how many people are going to be on those lists who never signed up for the site
All of them.
So the authoritative text of a field is not legitimate? Are you next going to tell me the Oxford English Dictionary is not a legitimate source of definitions of words in the English language?
No legitimate climate scientist believes in climate change.
Support my political activism on Patreon.
No one in the medical community uses this term. It has no real meaning and testing. Calling some a sociopath is akin to saying nanny nanny bo bo
Thanks. I'm going to use that as my excuse. I just have to convince a friend to say so.
No, it's a prank. Now that this hack has happened it's also hilarious. Don't be an old stick in the mud.
people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals
See honey, even Slashdot acknowledges it! It was a hack. It could have been anyone using my email and credit card. They probably just got lucky on the penis length thing.
SJW's don't eliminate discrimination. They just expropriate it for themselves.
I created an account yesterday just to see what it was all about...
I literally smacked my hand off the keyboard to create a username and password (it never even asked me to confirm the password), and the username and domain of an email address. Randomly selected items from drop-downs (managed to set myself up as a 90lb Indian male - couldn't be much more wrong).
Once everything was filled in, the account was instantly created and it was asking me to upload a picture of myself (naturally, I tossed in a dickbutt picture) and added a fun mask to it (compliments of the site's software for "masking" your face).
Then it let me straight into the site, no more questions asked. No verification needed. Nothing.
"Assuming the download turns out to be authentic, people should remember that it was possible for anyone to create an account using the name and e-mail address of other individuals."
Yeah, honey, see some other guy with my name and email address made the account on AshleyMadison, it wasn't me!!
I'm sure that'll work, it sounds so plausible.
Just cruising through this digital world at 33 1/3 rpm...
My ex-wife signed me up to this site and tried to use it as evidence of me cheating in an attempt to try to extract alimony out of me. What a bitch.
And all I wanted to do was order some snack cakes. I thought it was odd that they asked for so much personal information. Then I realized I was on the Ashley Madison web site and not the Dolly Madison web site.
Where is the link to the db?
Funny how many guys there are named Ron Mexico.
"Contrarily the lookaside buffer might not be the panacea... "
But not all sites. And supposedly not this site.
Except for the rare super-cryptographic sites, nearly every sit is vulnerable.
This goes for activity in public too, with a billion smartphone video cams out there.
At least according to the search tool someone released, there's a flag in there as to whether the email was verified or not.
No TRUE Scotsman would use that term!
RTFA.. They did NOT validate email addresses.
I wanna hear about who succeeded in getting this thing to import nicely into a database, and how they did it. How did you manage the parsing? I wanna run some nice search functions on it, say by zip code of the credit card addresses, or by various university .edu domains. I wanna see the creepy messages that my creepy professors send when they're horny. I have a feeling that this is going to be a lot of fun! Also, I'm quite sure that sociologists could find some very interesting patterns in this data, which will teach us a lot about human nature. Weee! (Sorry about my apparent glee - I know that many lives will be ruined by this hack.)
Someone did that with my email too.
I deleted their accounts, they were fraudulent anyways.
The guy or girl posting this information better pray their identity is never discovered. There will be a line a mile long of people looking to kill them in the most brutal ways possible.
Usually all sites will send a confirmation email and only enable the account if a confirmation link or code from that email is used.
HA, No they don't. Someone started using my gmail address years ago (thinking it was theirs) to create accounts. I have access to so many accounts it's borderline wrong. This person even let their kid sign-up to EA's origin.com and bought a game. I did an account password reset seeing as the email address is mine and now the game belongs to me and they can't play it anymore.
Once I even got digital plane ticket's emailed to me from an Australian airline. I was able to do a password reset and get into the account and do whatever I wanted.
Companies seem to be relying on the "type your email 2 times" method and not the ending an email to verify. It's pretty sad.
To a Scientologist, none are legitimate ...
So, my wife cheated on me awhile back, and we are in counselling and trying to patch things up after I unceremoniously threw her out of the house.
Do I download this data and search it for identifying info that could lead to my wife? I'm not sure I trust her enough not to be in that data, but I'm not sure I'd really want to know.
Thoughts?
Is that you, Tom Cruise?
HA HA HA HA... ahhhhhh HAAAAA HA HAAAA HEE HEE hee haa hee hee whew... ahh that felt good.
Sociopath is not a disorder listed in the DSM. Even a cursory glance at Wikipedia will inform you of this.
"First they came for the slanderers and i said nothing."
Good for them,
Dislike all this "Attack on Morals, God is Dead, Government Give me Checks" crap.
"So the authoritative text of a field is not legitimate?"
Given how illegitimate and unreproducible most psychology 'experiments' are, they have zero scientific credibility and thus the entire field is illegitimate.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
But they did allow you to verify and encouraged it. There's an account verification field with Y/N in it. Most of the accounts are verified. Nice try though!
Most of the accounts were verified. People are already going through the data. You didn't HAVE to verify the email, but most people did anyway.
You can say that about physics, medicine, or climate science as well.
Support my political activism on Patreon.
That depends on your intentions and what you do with it. If you meet sleep with women and then get them to demand child support from him, certainly. If you jut post a joke picture not so much. If you tell his wife that you did it for him as a joke, and that helps him cover up his real account, it may even count as a service.
My apologies, you are technically correct, though the link I provided shows over 1700 relevant articles.
Just another day in Paradise
That is true too lol. There is no official diagnosis of sociopath, so the term is deprecated; though clearly psychologists still use it (and sometimes base their entire practice on it)
"First they came for the slanderers and i said nothing."
I brought legitimate examples, which you've summarily dismissed. But, then you're smarter than all of the actual Ph.Ds in the field.
Have a nice day jackass.
Just another day in Paradise
So, what indicates that it has "depreciated". If it's not decreasing in usage among professionals, that seems to indicate an incorrect usage to me.
Just another day in Paradise
Medicine has plenty of verifiable experimental results. Climate science has verifiable geological records. Physics has plenty of proof that the Laws of Thermodynamics are inviolable.
Almost every psychology experiment with results simply cannot be reproduced at all.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
Wife: Mr. Johnson, you have an account on Ashley Madison
Mr. Johnson: Ashley Madison? I'm not a cheater....
Wife: Sure you are not a cheater
Agreed. I get GCHQ stuff and emails with photos from dudes at various locations because some random project manager over there has the same name as me and can't figure out gmail. Ps hope little Finn liked his Christmas present.
Well, good. That should kill that little segment of 'reality tv' and clean up our airwaves a little bit.
Still waiting on Serviscope_minor to wake up to fucking reality and realize that Jessica Price isn't going to fuck him.
1) I have a secret e-mail account I use for slutting around, and it's in there.
2) my ex-girlfriend (who cheated on me quite a lot) her secret slut e-mail is in there too.
3) one of my good friends who is known to be a bit of a sex freak, his is in there too
4) the "normals" from my life are not in there.
my favourite reaction to this incident is:
"2 years of paying $19 a month... Now I'm finally getting f**ked"
Me too. Worst yet, they're usually websites that are so shit that they ignore their own "unsubscribe" processes.
I had this problem just last week. This bunch of clowns ignored my request to unsubscribe. So I went in, reset the password, and logged in. No option to delete account or opt out, so I changed my email address to the website's own enquiries inbox. Made no difference, still got a daily spam. So clearly their email spam-me list is separate from their account list and don't sync. Sigh. Just another address to add to my spam filter for the next 50 years.
Too many morons designing email subscription services.
I haven't seen much commentary on the question of how many of the exposed records are real identities and how many are pseudonyms. Leaving aside the (lack of) ethics of betraying your life partner, let's take a moment to note how easy it is to make separate Gmail and Google Voice accounts, and pay cash for a Visa debit card. If you're using your real identity and your main email address -- especially if it's a work address (and especially a dot-gov or dot-mil one), then, sure, you're a bastard, but more to the point, you're a moron.
It would be difficult, if not impossible, to hide your actions from Google, let alone the NSA. But you wouldn't be outed by this hack.
Yet psychology is a valuable field that underscores medicine, economics, business, stock prediction, poker, and so forth.
Reproducible results in psychology show that 4 months of cognitive therapy for the severely depressed produce results of 0 relapses in 24 months in 47% of cases, while continuous drug therapy for 24 months produces 0 relapses in 23% of patients, and a placebo for 24 months produces 8% success rate. The targeting of specific distorted thinking and the guided improvement of executive functions actually works twice as well as Xanax or Zoloft, which themselves only work about 3 times as well as simply suggesting to a patient that he has undergone treatment.
That indicates the psychological strategies have a large (5x) impact beyond the placebo effect--a conclusion we can reproduce simply enough by putting an experiment group on sugar pills and putting another on therapy, while keeping an untreated control group to monitor.
I'm sure you would argue that seeing the effect repeatedly, but not understanding the cause invoked by the specific experimental action, means no reproducible experimental results exist, since we can't say that each experimental action invokes the same physical responses and thus produces the same effect by the same cause. We can say that about chemistry by invoking quantum mechanics, too.
Support my political activism on Patreon.