Hacker News new | ask | show | jobs
by nullymcnull 3048 days ago
The post kind of dances around exactly what 'information' was exfiltrated from the targeted user, but it's pretty clear from a close reading that it has to have included his Chrome passwords.

  unfortunately we could not be able to enter the registration-only web sites he was using to provide this information to other pirates.

  We found ... that the particular cracker had used Chrome to contact our servers so we decided to capture his information directly

  .. to dump that cracker's information needed for us to gain access to those illicit web sites

  this method worked, in fact, and we were able to receive this information
This all followed by screenshots from the "registration-only web sites" they could not previously reach.

Also, at least one of the initial reddit reports which set off this whole thing was due to A/V software detecting an executable file included in the installer (which was dropped but not executed on all user installs) as "Chrome Password Dump" malware.

Edit: The earliest responses about this from FSLabs seem to confirm that they were running the password dumps on anyone who was using known pirated serials; it looks safe to say that the linked post is overstating how targeted their actions actually were.

  This method has already successfully provided information that we're going to use in our ongoing legal battles against such criminals.
If they truly believe that they have any hope of using any information thus gathered to aid them in their 'legal battles' against crackers and pirates, this is one deeply confused company.