> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
A lot of chess.com information is public (by default) if you know someone's profile. Stuff a couple million email addresses and phone numbers into the "find friend" API and all you need to get profile information is the associated account username.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
I only started playing less than a year ago. I paid for one year because of game review to improve my game. Didn't know lichess exist, but I'm not paying for a second year for sure
23 comments
[ 3.4 ms ] story [ 33.6 ms ] threadIt sure seems like the evidence doesn't point to scraping to me.
https://infosec.exchange/@haveibeenpwned/117263977537458510
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
Btw I hate that chess.com puts game reviews under their most expensive plan, I ain't paying so much for something I can get in lichess for free.
Far superior to chess.com in all regards. If you're still on chess.com, make this your opportunity to switch. You won't regret it.