Rendered at 08:14:20 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
Shank 1 days ago [-]
> Every record has gam_audiences and audiences_member_of populated, Google Ad Manager audience segments, with values like coach-nudge experiment groups, trial eligibility, lapsed-user cohorts and rating-band targeting.
It sure seems like the evidence doesn't point to scraping to me.
happosai 1 days ago [-]
Have I been pwned reports 99% of email addresses from chess.com leak were already in their database. Rather strong indicator that the Hacker scraped an API with a list of email addresses.
I'm assuming they're basing this on the no-passwords part.
specproc 19 hours ago [-]
Lichess.org is an internet gem. No ads, no subs, incredible performance, low-toxicity, fully featured, free API, European.
Far superior to chess.com in all regards. If you're still on chess.com, make this your opportunity to switch. You won't regret it.
Mydayyy 11 hours ago [-]
When I started playing online chess, which was around a year before the hype came with corona, I checked out both websites chess.com and Lichess. I very quickly decided to use Lichess since it just appeared superior in all aspects and it, in my opinion, look way better.
Almost all of the people I met who play chess prefer chess.com and I just don't understand it. I just never managed to warm up with that site
stavros 18 hours ago [-]
I'm loving that "European" is a selling point now, but yes, agreed. Lichess is a gem.
sidrag22 1 days ago [-]
> The data had been pulled by abusing the platform’s find-friends feature
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
jeroenhd 1 days ago [-]
A lot of chess.com information is public (by default) if you know someone's profile. Stuff a couple million email addresses and phone numbers into the "find friend" API and all you need to get profile information is the associated account username.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
samus 1 days ago [-]
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping".
nilslindemann 1 days ago [-]
I just logged in to delete my chess.com account, got a message: "This account is closed, please log in with your e-Mail to reactivate". No word by them having been hacked.
dwroberts 23 hours ago [-]
Worth noting this was reported back in August, it’s not new
Lucasoato 1 days ago [-]
I just got a message from an Hacker: "You seriously just played London opening as white and King Indian defense as black for the last 3 months?"
Btw I hate that chess.com puts game reviews under their most expensive plan, I ain't paying so much for something I can get in lichess for free.
gregorygoc 1 days ago [-]
Exactly, chess.com is at value extraction phase. Lichess is much better platform now.
mitxela 1 days ago [-]
Wasn't this literally always the case and the very reason lichess was created? And yet it remains #2.
demibabs 1 days ago [-]
Some battles are won at the domain registry.
a_c 1 days ago [-]
I only started playing less than a year ago. I paid for one year because of game review to improve my game. Didn't know lichess exist, but I'm not paying for a second year for sure
m00x 1 days ago [-]
uh oh. If my ELO gets back to my friends I'm going to be very embarrassed.
MiroslavPokorny 1 days ago [-]
Hack or scraping, both are equally bad.
TheSpacerr 1 days ago [-]
Basically our data is free.
zx8080 1 days ago [-]
Peasants have no rights and shall be slaves.
ed_mercer 1 days ago [-]
email? Is a user's email up for grabs just like that?
jibal 5 hours ago [-]
email gets you username via find-friends, not the reverse. The emails were obtained independently of chess.com
It sure seems like the evidence doesn't point to scraping to me.
https://infosec.exchange/@haveibeenpwned/117263977537458510
Far superior to chess.com in all regards. If you're still on chess.com, make this your opportunity to switch. You won't regret it.
Almost all of the people I met who play chess prefer chess.com and I just don't understand it. I just never managed to warm up with that site
Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it.
Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days.
Btw I hate that chess.com puts game reviews under their most expensive plan, I ain't paying so much for something I can get in lichess for free.