| ▲ | sidrag22 9 hours ago | |
> The data had been pulled by abusing the platform’s find-friends feature Sounds like the find-friends feature shouldn't allow access to the majority of that data unless the "friend" accepts, don't think the "scraper" got 7mil accepts just because they had access to emails... To me this is 100% a breach, even more so because its already happened once years ago to 700k, and they changed nothing to prevent it. | ||
| ▲ | jeroenhd 6 hours ago | parent | next [-] | |
A lot of chess.com information is public (by default) if you know someone's profile. Stuff a couple million email addresses and phone numbers into the "find friend" API and all you need to get profile information is the associated account username. Chess.com should probably prevent scraping, but as we can read in just about every comment thread about LLMs/Cloudflare/Anubis/Go-away, that's not as easy as it sounds these days. | ||
| ▲ | samus 8 hours ago | parent | prev [-] | |
It might very well be possible that there were API endpoints that exposed way too much information. I also think that this wouldn't qualify as "scraping". | ||