Hack Brief: Site for ‘Beautiful’ People Suffers Ugly Million-Member Breach
BeautifulPeople.com, you may remember, is a dating site that allows members to vote on hopeful enlistees based on their looks, ensuring that people who belong meet certain standards of both attractiveness and shallowness. It bills itself as “a dating site where existing members hold the key to the door.” Turns out, the site maybe should have put them in charge of server security, as well. The personal data of 1.1 million members is currently for sale on the black market, after hackers took it from an insecure database.
Last December, security researcher Chris Vickery made a curious discovery while browsing through Shodan, a search engine that lets people look for internet-connected devices. Specifically, he was looking through the default port designated for MongoDB, a type of database-management software that, until a recent update, had blank default credentials. If someone using MongoDB didn’t bother to set-up their own password they would be vulnerable to anyone just passing through.