Slashdot Mirror


Hack Exposes 412 Million Accounts on AdultFriendFinder Sites (zdnet.com)

"Almost every account password was cracked, thanks to the company's poor security practices," reports ZDNet -- even for "deleted" accounts. An anonymous reader quotes their article: The hack includes 339 million accounts from AdultFriendFinder.com, which the company describes as the "world's largest sex and swinger community [and] also includes over 15 million "deleted" accounts that weren't purged from the databases. On top of that, 62 million accounts from Cams.com, and 7 million from Penthouse.com were stolen, as well as a few million from other smaller properties owned by the company. The data accounts for two decades' worth of data from the company's largest sites, according to breach notification LeakedSource, which obtained the data... The three largest site's SQL databases included usernames, email addresses, and the date of the last visit, and passwords, which were either stored in plaintext or scrambled with the SHA-1 hash function, which by modern standards isn't cryptographically as secure as newer algorithms.
The attack apparently coincides with the discovery of "a local file inclusion flaw on the AdultFriendFinder site, which if successfully exploited could allow an attacker to remotely run malicious code on the web server. " Ironically, Friend Finder Networks doesn't even own Penthouse.com anymore. They sold the site to a new owner last February.

78 comments

  1. pleaaaaaseeee... by Anonymous Coward · · Score: 0

    Tell me the typo in the title is intentional.

    1. Re:pleaaaaaseeee... by ChodaBoyUSA · · Score: 1

      YIKES!

    2. Re: pleaaaaaseeee... by Anonymous Coward · · Score: 1

      Hehe looks like all it took was a c bomb in the title to get the editors to finally do the jobs.

  2. Oh gee by buss_error · · Score: 5, Insightful

    I am so sick and tired of databases not being properly protected. One thing you can do is to monitor outbound traffic. If you suddenly see a huge stream from the DB server to somewhere it doesn't normally go, a banshee cry should come from your monitoring system.

    You can also include "trap" data in the DB and have pattern matching set up (on the system, in the network, on the routers). See the pattern, alarms and cell phones should start ringing.

    --
    Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves.
    1. Re:Oh gee by BarbaraHudson · · Score: 4, Funny

      What is your problem? It's AdultFriendFinder. Someone just found 412 million friends. NOT_A_BUG WORKS_AS_DESCRIBED :-)

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    2. Re:Oh gee by doug141 · · Score: 2

      But wouldn't the development costs of a monitoring system come out of this quarter's profits, and therefore this quarter's executive bonuses? What's the executive downside to data loss... still nothing?

    3. Re:Oh gee by Dutch+Gun · · Score: 4, Interesting

      Yes, but you're arguing "if they were only competent, they could do x and y..." Obviously, they're not competent enough to even properly hash and salt usernames/passwords properly. So, of course they're not going to do anything else sensible, like what you're describing.

      --
      Irony: Agile development has too much intertia to be abandoned now.
    4. Re:Oh gee by sg_oneill · · Score: 2

      I once worked at a company that had lost 3.5 million in the previous year to hackers against half a million profit. From day one at that job I had identified the flaw and had been telling anyone who I could that it was serious and we needed to fix it. And constantly was told "We need to focus on new features". And you know what, even after the figures came out I *still* could not convince them to let me fix the security hole because they could claim it all back as "R&D tax credits". I quit the company in disgust.

      --
      Excuse the Unicode crap in my posts. That's an apostrophe, and slashdot is busted.
    5. Re:Oh gee by Anonymous Coward · · Score: 0

      I'm actually surprised to hear that AFF is a real site, I always thought it's just some malware trap that porn sites spam.

    6. Re: Oh gee by LostMyBeaver · · Score: 1

      What a crap IT solution. Don't get me wrong, if I can't get a good solution, a crap IT solution will have to do.

      IT people seem to think that something like this is called "proper protection". It's not. A less crap IT solution would be to place a firewall in between the web server and the SQL server and enforce specific queries.

      A slightly better solution would be to limit all database access to specific stored procedures. This would destroy business agility because it would require the programmers to stop using tools like LINQ.

      There are many small solutions that when combined would work, but a dumb ass "behavioral" filter is like saying "I know our code and network security sucks, instead of fixing it, let's hack the shit out of it"

    7. Re:Oh gee by AmiMoJo · · Score: 1

      Executives need to start seeing jail time for stuff like this. If they can't show that they took reasonable steps to prevent it, like getting the system audited externally by an accredited company on a regular basis and enforcing security standards (ISO etc.) they should be held liable.

      You make big bucks off people's private data, you accept the risks.

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    8. Re:Oh gee by Anonymous Coward · · Score: 0

      You make big bucks off people's private data, you accept the risks.

      Your mistake is in thinking this is people's private data, it isn't. In the United States the data belongs to the person who collects it, in this case AdultFriendFinder.

    9. Re:Oh gee by The+Raven · · Score: 1

      Like Ashley Madison, I bet 99% of the users are male, and 90% of the women are fake accounts.

      --
      "I will trust Google to 'do no evil' until the founders no longer run it." Hello Alphabet.
    10. Re:Oh gee by DerpQuake · · Score: 1

      It's an interesting consumer lesson. You can sign up with a fake name and email and you can even delete your account, but the moment you supply your real name to run your credit card there is exposure. Until the simple theft of personal information carries liability for the company holding the data, not just liability for the provable harm, nothing will change. Until then we'll all just keep getting free credit monitoring, as if that solves everything.

    11. Re:Oh gee by Anonymous Coward · · Score: 0

      That's pretty much the totality of the site. Loads of fake "profiles", and many more pure duplicates. Do real people actually use the site? Maybe. But the entire purpose is an ad revenue "scam". It's all to common for "dating" sites to never delete anything, given the marketing gold of "number of profiles".

  3. haha by Anonymous Coward · · Score: 0

    i smell scandals happening. i can already hear neighbors yelling and slammed doors.

  4. A Brilliant Plan: by Anonymous Coward · · Score: 1

    1. Sign up for sites like these using your enemies' information.

    2. Wait for said sites to get hacked (because they inevitably will), spewing your enemies information across the Interwebs and filling their lives with unexpected shame and scandal.

    3.Profit!

    1. Re:A Brilliant Plan: by John.Banister · · Score: 1

      If you're going to commit identity theft, wouldn't you prefer a more tangible reward?

    2. Re:A Brilliant Plan: by Anonymous Coward · · Score: 0

      If you're going to commit identity theft, wouldn't you prefer a more tangible reward?

      Look; do you have no respect? He's president now. What do you want from him???

  5. Re:Don't worry by NotInHere · · Score: 4, Funny

    SHA has the best rounds, believe me. bcrypt and scrypt are so slow, they are all computation and no results.

  6. So what's the password... by Anonymous Coward · · Score: 0

    For Trump's account?

    1. Re:So what's the password... by Anonymous Coward · · Score: 1

      As funny as that would be, trump doesn't use computers or the internet. He doesn't even use email. He hand writes everything.

      Yes, he's that old school.

      In any case, he has no need for adult hooking up sites. He can pretty much walk up to any hot chick and just grab her by the pussy.

    2. Re: So what's the password... by Anonymous Coward · · Score: 0

      So he has many things in common with Bill Clinton then.

      I wonder if he's also going to use law enforcement officers to pick up girls, rent motel rooms and lie to his wife while he's cheating on her multiple times a week like Clinton did.

    3. Re: So what's the password... by Anonymous Coward · · Score: 1

      And yet somehow Trump's predicted, presumed philandering be fine with the Conservitards. Peachy keen in fact.
      They'll brag about his conquests while they vote for his reelection.
      Go figure.

    4. Re: So what's the password... by BarbaraHudson · · Score: 0

      And yet somehow Trump's predicted, presumed philandering be fine with the Conservitards. Peachy keen in fact. They'll brag about his conquests while they vote for his reelection. Go figure.

      Maybe it's because he wasn't a hypocrite liar trying to hide it like the Clintons?

      Me, I would have voted for Hitler before voting for Hillary. At least Hitler did something good - he killed Hitler. Mayby the Clintons can learn something from him :-)

      (it's a joke, stupid libtard lizard people. Go riot somewhere or smash a few windows. Hopefully you'll be arrested and committed to Bellevue because there's something wrong with people who lose an election and then lose their shit)

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    5. Re:So what's the password... by Anonymous Coward · · Score: 0

      I_Want_to_Date_My-Daughter

      He said it himself.

    6. Re: So what's the password... by Anonymous Coward · · Score: 2, Insightful

      It is really funny that you should mention that. Many people who lived through the Hitler years say that Trump strongly reminds them of Hitler.

      So in a way, you really did vote for Hitler this time around.

    7. Re: So what's the password... by Anonymous Coward · · Score: 0

      That's because when someone has no logical arguments left, they demonstrate Godwin's Law. Then, they break stuff.

    8. Re: So what's the password... by Anonymous Coward · · Score: 1

      (it's a joke, stupid libtard lizard people. Go riot somewhere or smash a few windows. Hopefully you'll be arrested and committed to Bellevue because there's something wrong with people who lose an election and then lose their shit)

      You mean like you were planning on doing if Trump had lost?

    9. Re: So what's the password... by pnutjam · · Score: 1

      Barbera, aren't you a Canadian transgender?

      I am a Trump protester. I want him to clearly reject his "deplorable" base.
      I'd also love for him to say he knows his campaign was too divisive and has made it impossible for all American's to accept his leadership; so he is committed to a single term, which will ensure he can clean up Washington without being beholden to anyone.

    10. Re: So what's the password... by Anonymous Coward · · Score: 0

      Not a Clinton fan but....
      I always said that Bill was a fool for lying to congress. He should have just said "Yeah I stooped her, so what?"
      It probably would have got him cheers in half the bars of America. His wife obviously knew of his philandering ways (after all she helped him cover it up.) It's not illegal to cheat on your wife in most parts of the country. I'd say he might have had problems with work place fraternization laws, but expect that Congress probably wrote exemptions for high level executive department officials as well as themselves in the law. But in any case marital infidelity is not a "High crime or misdemeanor" in the sense used by the constitution, like perjury is. So he couldn't have been prosecuted until the end of his second term.
      So basically he was a fool for lying.

    11. Re: So what's the password... by BarbaraHudson · · Score: 1

      Not me. Negative campaigns have always caused me to vote "weirdly." Like last election, when I voted Green.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
    12. Re: So what's the password... by BarbaraHudson · · Score: 1

      Barbera, aren't you a Canadian transgender?

      Last time I looked, since my birth cert didn't always say female, so I guess so :-)

      Clearly the whole transgender hate thing can be fixed by the individual states issuing properly corrected birth certificates. There is NO way that federal legislation can do that, nor offer the same protections. All those stupid bathroom bills disappear when you have a new (not amended) birth certificate with your new sex.

      We've had laws in this province protecting us from discrimination based on sex, which has been interpreted to include birth sex, for decades. Other provinces have been slower catching up, but it's getting there.

      Same thing with birth certificates. Some provinces destroy your old birth certificate, any marriage or divorce records, and your kids birth certificates and issue new ones with the new name and sex; these are recognized by all levels of government as the only ones with legal standing. Makes my marriage 40 years ago the world's first government-recognized same sex marriage, since I only got to finish all the paperwork after the newest laws kicked in (long story) . Gotta love retroactivity.

      How is a school going to bar a trans girl using the same bathroom as other girls if she's legally a girl, and the old records, even if produced, have no legal standing? Simple answer - they can't. So while I agree with Obama that Title IX "should" apply to such cases, there's no way to get the states to accept it without the cooperation of the two houses. Trying to impose it by executive writ wouldn't be a lasting protection anyway, so nothing of value was lost. Just that EVERY F*ING TRANS IN THE US IS FREAKING OUT FOR NO REASON.

      Bunch of bloody drama queens, reposting every rumour and speculation. No wonder 35% are dysfunctional according to their own doctors. It's the same with both sides on pretty much all the issues, because nobody knows yet how it's going to unfurl.

      As one example, non-NATO-member allies Japan and South Korea have been reassured that the US has their back, while at the same time saying that they really do need to kick in more for their defense. That's a far cry from the isolationism rhetoric of the election. It's something both parties would have liked to be able to do.

      Not going to like a lot of things he does, but it's worth the risk to see if he can get some sort of rapprochement with Putin so that there's less risk of everyone glowing in the dark or turning into radioactive zombies. Same as Nixon, being so anti-communist, was the only politician who could have credibly gotten better relations with them and made it stick.

      --
      "Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.
  7. Congrats by nospam007 · · Score: 2

    I guess, some divorce-lawyer's wet dream just came true.

    1. Re:Congrats by arth1 · · Score: 1

      FTFA: "LeakedSource said breaking with usual tradition because of the kind of breach, it will not make the data searchable."

      In other words, they found themselves there. Now if someone could hack LeakedSource, it would be interesting...

      Anyhow, 412 million seems like a rather high number. That's about 50% of the adult population of USA and Europe combined!

    2. Re:Congrats by Anonymous Coward · · Score: 0

      Buddy of mine had like four accounts, all with very different ways of describing his 5'4 190lb frame and about half his hobbies in vastly different combinations. ... It's possible he had way more than that I guess.

    3. Re:Congrats by Anonymous Coward · · Score: 0

      A "buddy" eh? ;-)

  8. More than the population of the US by JustAnotherOldGuy · · Score: 5, Funny

    339 million accounts, but 338.8 million were fake accounts with pictures of large-breasted women who were eager to have sex with me. And they all live "near" me, even though I live on the International Space Station in low-Earth orbit.

    --
    Just cruising through this digital world at 33 1/3 rpm...
    1. Re: More than the population of the US by Anonymous Coward · · Score: 1

      I live in England, but apparently dozens of Eastern European porn stars live within a mile of me.

      And (it gets better) they're all gagging for cock, not just any cock, but mine!

    2. Re:More than the population of the US by Anonymous Coward · · Score: 1

      if you're on the ISS, that puts you within about 250 miles of most of the planet's women each day, just not for very long...

    3. Re:More than the population of the US by Anonymous Coward · · Score: 0

      That must make long-term relationships rather difficult. Sounds like a perfect candidate for AFF!

    4. Re: More than the population of the US by Anonymous Coward · · Score: 1

      In space, no one can hear you FAPFAPFAPFAPFAP.

    5. Re: More than the population of the US by EETech1 · · Score: 2

      I'm sure everyone on the station and NASA would know...

      There's that rapid oscillation from ACs living quarters... AGAIN

      Let's just wait and see if it stops in 3 minutes, it usually does.

      Prepare for masturbatory post ejaculation altitude connection maneuver in... 5...4...3...2...1...

    6. Re:More than the population of the US by Anonymous Coward · · Score: 0

      Speaking in astronomical terms, they really *are* basically piled right up in your backyard.

  9. Really? by Anonymous Coward · · Score: 0

    There's that many people signing up for this.

  10. Again? by jcr · · Score: 1

    Didn't this happen already, something like a year go?

    -jcr

    --
    The only title of honor that a tyrant can grant is "Enemy of the State."
    1. Re:Again? by Pembers · · Score: 1

      You're probably thinking of Ashley Madison.

    2. Re:Again? by Anonymous Coward · · Score: 0

      Nope, this is at least the second time for them. https://haveibeenpwned.com/PwnedWebsites#AdultFriendFinder

      There have been rumblings of them leaking info much longer than this, but the admins just didn't seem to care enough to get off their asses, do their jobs and protect their users.

    3. Re:Again? by Pembers · · Score: 1

      I see. Thanks for the information. So should we start a pool on how long it'll be before they get hacked again? ;-)

  11. SHA-1 hash function, which by modern standards.... by geekpowa · · Score: 2

    Surely SHA-1 is perfectly fine as long as you salt it sensibly? The only way you can materially improve on SHA-1 is to use a hashing algorithm that is computationally expensive.

  12. Chalk up another one for private industry by smooth+wombat · · Score: 1, Interesting

    Almost another half billion accounts of people spread to the four winds because of how much better private industry is than government.

    When you add up all the hacks private industry has allowed because of their incompetence one can easily count 2 billion people, many no doubt duplicates, having their personal information compromised.

    But excuses will be made about how great private industry is, how it's not really the programmer's fault or the database administrator's fault or the web designer's fault. Nope, it will be someone else's fault because private industry does things so much better than government it's easy to pass blame and no one will be held accountable as a result.

    --
    We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
    1. Re:Chalk up another one for private industry by Anonymous Coward · · Score: 0

      So no government databases were hacked, ever?

      Try again.

    2. Re:Chalk up another one for private industry by OzPeter · · Score: 1

      Almost another half billion accounts of people spread to the four winds because of how much better private industry is than government.

      That's why government regulation of private industry is bad /s

      --
      I am Slashdot. Are you Slashdot as well?
    3. Re:Chalk up another one for private industry by ArtemaOne · · Score: 2

      You realize all the military private info was hacked not long ago? Look up the OPM breach. Private industry security isn't consistently better/worse than government.

    4. Re:Chalk up another one for private industry by Anonymous Coward · · Score: 0

      You're right. Dammit, government, step up AND HELP ME FUCKING GET LAID. What am I paying all these taxes for anyway?

    5. Re:Chalk up another one for private industry by Anonymous Coward · · Score: 0

      No excuses needed, because these breaches already shown everyone how much better private industry is, in two most important aspects:

      1. I have a choice not to give my information to these sites. For example, this leak did not affect me at all, because I never had an account with them. You often get no such choice for government websites, when IRS leaked your information, you never had the choice of not giving your info to IRS at the beginning.

      2. The company owning the website will suffer the consequences, much better than taxpayers paying for the damages due to government mistakes.

    6. Re: Chalk up another one for private industry by Anonymous Coward · · Score: 0

      So are you proposing the government would run a better sex hookup site? Do tell.

  13. Re: SHA-1 hash function, which by modern standards by Entrope · · Score: 1

    Yes. While SHA-1 has seen successful collision attacks (attackers can find two messages that generate the same hash), practical preimage attacks (attacker finds a message that generates either a specified hash value or the same hash value as a specified message) are not currently known. I would guess that these passwords effectively did not use salts.

  14. Never hacked, not recommended. SHA-2 better by raymorris · · Score: 5, Informative

    There are no known SHA-1 collisions. Essentially, it's never been fully hacked. As you mentioned any hash must be salted for password use, and salted SHA-1 would be fine for most any public web site.

    However, a partial crack of SHA-1 exists. The NSA or the Chinese government might well be able to crack it.

    SHA-2 is recommended for all new hashes. For example, new TLS (SSL) certificates are signed with SHA-2, not SHA-1. In 2017, major browsers may stop accepting TLS certificates signed with SHA-1.

    Upgrading can be easy if you used the crypt() system call, or a higher-level function that calls crypt() underneath. That includes MySQL encrypt(), Perl crypt(), etc. If you do, just change the salt you use for the initial hashing - the password CHECKING code remains unchanged.

  15. How many are legitimate? by Anonymous Coward · · Score: 0

    Like seriously, how many of these accounts are real and not just fake accounts made by the site to fool people into thinking there's a lot of people out there.

  16. Re: SHA-1 hash function, which by modern standards by NotInHere · · Score: 1

    There aren't even preimage attacks known for MD5.

  17. Amount of women I fucked from AFF. by Anonymous Coward · · Score: 3, Informative

    Three. One even became my girlfriend for two years. So there are real women on there.

    1. Re:Amount of women I fucked from AFF. by Anonymous Coward · · Score: 0

      Why'd you need to call tech support three times, anyways?

  18. Re:Don't worry by Anonymous Coward · · Score: 1

    How long until we find Carlos Danger (Anthony Wiener) or Diane Reynolds (Chelsea Clinton) in the dumps?

    That said, if you find one listed as "Evergreen" I'd advise that you run and don't turn back.

    That's Hillary, if you didn't know.

  19. Re:Don't worry by Anonymous Coward · · Score: 0

    Did the mod who modded this as "Interesting" not get the joke?

  20. I think I was on that site by Anonymous Coward · · Score: 0

    Some time between 7 and 13 years ago, I can't remember the details. All I found was an unending parade of spammers and scammers. What a complete waste of time and energy.

    I do remember googling "free email services" to find a place to set up a throwaway account that was completely unconnected to me. Now I see another confirmation that was the right thing to do.

    1. Re:I think I was on that site by Anonymous Coward · · Score: 1

      I was, both on the "vanilla" AdultFriendFinder.com and the more explicit Alt.com.

      It was very fake-ridden, but the fakes were easy to spot, even in the old times without Google image search. Sometimes it got weird when a silver or gold (i.e. paying) account popped up that contained picture material well-known from your favorite porn picture aggregator, so I assume some of these were indeed set up by the Friendfinder Network themselves as I can't imagine that people would set up paid-for fakes.

      All in all, we met a total of six real couples (all but one being US couples stationed in Germany where we reside, too) over a period of like 3 years, which -- given that back then there wasn't "the" German portal for such activities like today it is with Joyclub -- isn't really that much plus indeed a real single bisexual woman. As mostly in these cases there was of course a catch with the latter -- bisexual good-looking women usually aren't single for long -- but that's another story. If you really wanted to meet someone there you certainly had the opportunity to do so.

      However, already back then the security standards were low. For instance, full profile access officially was limited to non-paying users and guests, but with a simple script you could easily dig up all details (particularly the pictures), so I quickly hacked together a small script that would leech the desired data and reassemble the page into a view similar to a paying (or temporarily elevated) user's view. Also, all relevant account data was encoded in a hex string that, even worse, was forwarded per GET. I never went the lengths to decipher that, but I'm almost sure that you would've been temporarily able to lift yourself to paying member level through that.

      For all practical reasons, you could earn a temporary increase to silver standard as well by idling in the chat all day (which also explains the low overall activity there despite being populated with users). That was good for IIRC 10 profile accesses, but with the aforementioned script it was well enough to not waste them for fake profiles.

  21. WOW Sweden! you pervs! by Anonymous Coward · · Score: 0

    Swedish is pretty localized to Sweden and there is 1 266 684 accounts registered with main language Swedish in the database.
    That would indicate that over 10% of Sweden's population is registered there! (13.2%) of Swedens 9,6 million inhabitants.

    Seems legit :D

  22. Re:SHA-1 hash function, which by modern standards. by AmiMoJo · · Score: 1

    Indeed, the real problem is that passwords are a terrible way of securing stuff. Human memory is too easy to predict and model, which is why even "good" passwords consisting of multiple words and numbers are relatively easy to crack these days, even with slated SHA-1 protecting them.

    Didn't Google say they were working on something better than passwords? We need it sooner rather than later. Hard to imagine what form it will take though. Biometrics are obviously stupid, and it needs to be convenient and secure and compatible with a wide range of devices and services to work.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  23. Re:SHA-1 hash function, which by modern standards. by Anonymous Coward · · Score: 0

    The only way you can materially improve on SHA-1 is to use a hashing algorithm that is computationally expensive.

    And, so, we improve on it by making it more computationally expensive. What's wrong with that?

  24. oh darn - changing my password AGAIN! by ripvlan · · Score: 1

    You'd think one could trust these amoral website companies to keep everything secure from "the man" --- but noooo!

    I'm running out of passwords. Password1, Password2, Password123456, now i'll just hold down the 99999999 key.

  25. I wonder... by ne1av1cr · · Score: 1

    Need to search that data for the name "Melania"

  26. HACKING by Anonymous Coward · · Score: 0

    Hey everyone , I don't really know much about this hacking things but I can direct you to a professional hacking company who helped me to track and hack my boyfriend's iPhone and his Facebook respectively... For any social network or iPhones and other phones hacking , you can just contact them at mastershield55@gmail.com... Their charges are minimal and negotiable.... You can thank me later

  27. BLANK ATM CARD HACKER by garyhacker · · Score: 0

    Get BLANK ATM Programmed Card and cash money directly in any ATM Machine around you. There is no risk of being caught, because the card has been programmed in such a way that it's not traceable, it also has a technique that makes it impossible for the CCTV not to detect you, and you can only withdraw a total amount of $7,500.00 USD in a day. Now email us today at our E-mail address at: garymckhackermachine@gmail.com and get your card today.. garymckhackermachine@gmail.com