> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
A lot of chess.com information is public (by default) if you know someone's profile. Stuff a couple million email addresses and phone numbers into the "find friend" API and all you need to get profile information is the associated account username.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
I only started playing less than a year ago. I paid for one year because of game review to improve my game. Didn't know lichess exist, but I'm not paying for a second year for sure
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
https://infosec.exchange/@haveibeenpwned/117263977537458510
I'm assuming they're basing this on the no-passwords part.
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
A lot of chess.com information is public (by default) if you know someone's profile. Stuff a couple million email addresses and phone numbers into the "find friend" API and all you need to get profile information is the associated account username.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
Worth noting this was reported back in August, it’s not new
I just got a message from an Hacker: "You seriously just played London opening as white and King Indian defense as black for the last 3 months?"
Btw I hate that chess.com puts game reviews under their most expensive plan, I ain't paying so much for something I can get in lichess for free.
Exactly, chess.com is at value extraction phase. Lichess is much better platform now.
Wasn't this literally always the case and the very reason lichess was created? And yet it remains #2.
Some battles are won at the domain registry.
I only started playing less than a year ago. I paid for one year because of game review to improve my game. Didn't know lichess exist, but I'm not paying for a second year for sure
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
Hack or scraping, both are equally bad.
uh oh. If my ELO gets back to my friends I'm going to be very embarrassed.
Basically our data is free.
Peasants have no rights and shall be slaves.
What's the forum shown in the screenshot?
email? Is a user's email up for grabs just like that?
Is scraping wrong that, is the question.