Sooo... FetLife is butthurt.

Monday, 16 February, Year 7 d.Tr. | Author: Mircea Popescu

The only question that matters in all of this is : Have they fixed the security holes putting their userbase at risk ? And the answer is that no, they have not.i

The question that doesn't matter, but is nevertheless included here for the lulz is, what have they done instead of fixing the security holes putting their userbase at risk ?

The answer is two things. The first thing is here :

Friend Onoes you were banned! You still show up in my friends list but if i click on your pic (name tooltip still works) it redirects me to my feed.
Me Aha. Except... a) I paid them for that account and b) it's unclear what exactly the relationship is supposed to be. This is extremely poorly thought out, as a strategy. It would seem they basically fly by the seat of their pants, or in other words : the entirely absent forethought shown by their very poor technological security practices readily translates in absent forethought shown by their operational and, (at least on a boasting level) legal practices. Imagine the havoc I could cause with this, if i disliked them. a) could easily result in having their cc payment processing suspended ; b) could easily result in endless drama through banning various community leaders in no way related to anything.

The other thing is


This is a notification of trademark infringement and violations of your
Acceptable Use Policy that are occurring on a site hosted on your servers.,
owned by one Mircea Popescu, has posted the followingpage:

On this page, Mr. Popescu has infringed upon our trademark =E2=80=9CFetLife==E2=80=9D,
registered in the United States with registration #3869809.

This program creates a likelihood of confusion, mistake and/or deception with the consuming public,
as it is connecting directly to our website. The confusion created can be that the product is the
same as FetLife, or that they are are somehow associated, affiliated, connected, approved,authorized
or sponsored by FetLife.

We have not authorized nor approve of this product. It is in violation of the Terms Of Use for our
website as well, and Mr. Popescu has been banned from our servers as a consequence of his actions.

In the above linked page, Mr. Popescu admits that he is posting this information in violation of our
Terms of Use and against the wishes of many of the people linked in this page. For example,
"management makes a point of not implementing it (a search function)", and "Don't you think people
have a right not to be included in your list ? People might, and if the list was a list of people,
I might care.

"In section 5, Network Unfriendly or illegal activity, subsection A, your customer agrees not to "
1. Attempts, whether successful or not, to gain access to any other system or users' private data
without express consent of the user." In the above linked page, Mr. Popescu not only admits to doing
this on FetLife - he brags about it.Each item noted above is sufficient to warrant immediate suspension
of his account, subject to your investigation towards possible termination as noted in section 4,
Unacceptable Conduct. As a consequence of this, were quest that you please immediately remove this
product from your servers,and provide our legal team with contact information for Mr. Popescu so that
we may proceed with further legal matters directly with him.

--James Huesmann
Senior CaretakerBitlove, Inc.

The problem with this is, of course, that I've filed a counter claim and they're more than welcome to argue the matter in court.

Now, Fetlife, how about you fix your piece of shit software instead of trying to bully ? I don't happen to bully well. (In which line : the second volume of the list in question is coming up later today.)

  1. Much like in the case of Automattic, denial is by far the preferred reaction of these obsolete entitities when confronted with security holes. Fixing is nowhere on the list. []
Category: Meta psihoza
39 Responses

  1. Did they at least try to contact you first?

  2. Mircea Popescu`s avatar
    Mircea Popescu 
    Monday, 16 February 2015

    No. Which unmitigated arrogance IS going to be coming out of their skin, yes.

  3. Mr. Popescu not only admits to doing this on FetLife - he brags about it.

    Granted, I don't have an account so I can't check - but didn't you just scrap publicly available data from the users' profiles? Doesn't seem like the list contains any actually private data.

  4. Mircea Popescu`s avatar
    Mircea Popescu 
    Monday, 16 February 2015

    All their claims are obviously spurious on the face, and for that matter if this is supposed to even be a DMCA notice it's pretty badly drawn up.

  5. Looks like I've been banned too. What, 'cause I'm on your friends list?! Way to wipe a five year old account in a lame attempt to cover your shame, Fetlife. Fuckin' a.

  6. Mircea Popescu`s avatar
    Mircea Popescu 
    Tuesday, 17 February 2015

    Ahaha what, seriously, they banned you because you were on my *friends list* ?!

    Going "oh, site X is saying things we don't want to hear and we think user Y is related to it so we're going to ban user Y for things some party that may or may not be related said on some site that may or may not be related, because we're the self-appointed God of the kindergarten that is the Internet" is one thing. Untenably stupid, obviously, but anyway. Going "AND ALL OF THEIR FRIENDS" is a pretty decent way to end up with the whole world banned lmao. I guess they gotta do whatever it takes to NOT actually fix the software.

    Turns out Bay Area communism and Mao communism actually have a lot in common ? Be thankful they didn't shave your head!

  7. Just in case :

    Was Barbara Streisand on Fetlife?

  8. Mircea Popescu`s avatar
    Mircea Popescu 
    Tuesday, 17 February 2015

    That probably happened beofre their time.

  9. It's disconcerting to see Fetlife imagine itself part of the Cathedral. Fetlife! A facebook for freaks from fucking Canada sees itself as some sort of momentuous, important powerplayer. Up there with Helliburton, Academi and Cuomo's sister in law. Is it the whippets I wonder?

  10. "FetLife was launched in January 2008 by John Baku, a software engineer in Montreal, Quebec."

    Other side of the continent. The French speaking, nuttier side.

  11. It is just Weev vs. ATT all over again.

  12. Mircea Popescu`s avatar
    Mircea Popescu 
    Tuesday, 17 February 2015

    @esrick What would you expect them to do, use all those forum donations / advertising revenues to fix the damned software ?

    @Anon Look into it, it's the derpiest stack imaginable - RoR on top of nginx/Ubuntu. I'm not even kidding.

    @BingoBoingo Fetlife can be AT&T once it actually lists for a billion, and Weev can be me also when he actually lists for a billion.

  13. Looks like MySql db too. You're right, they couldn't serve those searches whether they wanted to or not.

    That github by the way... omfg. No wonder they keep hiring and hiring and hiring and never get anywhere. Because, again, you're right, horror of horrors, worst pile of hairball spaghetti code ever. With tech like that the churn can't be anything but astronomic.

  14. It does sound a little like a teacher's note. "MP has been bad Mr. Parent" like.

  15. @Mircea Popescu

    Well, what makes this a special flavor of delicious is the power reversal.

  16. Mircea Popescu`s avatar
    Mircea Popescu 
    Tuesday, 17 February 2015

    @Anon I really fail to see the important difference between John Baku/Fetlife and any random Bitcoin scammer, like for instance Alberto Amandi, Josh Garza (or Sonny Vleisides) etc etc. Look at it! Boasts of technical competence ? Check. Blood curdling technical incompetence ? Check. Attempts to social engineer their way out of fixing anything (preferably first their heads, then the software) ? Check. Sure, they don't hold anything actually valuable, the random people trusting them aren't trusting them with any Bitcoin, fortunately for everyone involved. But who's to say that whatever users put on that site isn't actually as valuable to them ?

    This is an entire generation of idiots that has been trained to opt out of math "because it's hard" on the basis of "credits" for "contributing" socially (hey, he volunteered at the kitten shelter, how could he be held to learn derivatives!) and various administrative excuse notes.

    As they age, they fully expect to resolve conflicts with Russia by complaining (to whom, to God ? no, just to the ether) that "Putin doesn't understand", and with the Arabs by calling them terrorists and with me by pretending I don't really exist (which is what this entirely idiotic exercise actually is - they wrote a letter to some random business asking them to provide a certificate that I don't really exist, so that their wounded egos can go back to feeling good about what utter failures they are. Because that's what businesses are in the business of doing nao, forget money, they're here to make idiots feel better about themselves - and if you don't think so, then think again.)

    @Pust Quite exactly. And for exactly that reason : they're, mentally, still in school.

    @BingoBoingo I guess that's a point huh.

  17. Andrew Dieppa`s avatar
    Andrew Dieppa 
    Monday, 2 March 2015


    I've written an article about your incident on my website and I would like to further discuss what happened.

  18. Mircea Popescu`s avatar
    Mircea Popescu 
    Monday, 2 March 2015

    Freenode's probably the easiest.

  19. You will find this interesting:

    Feel free to email me if you want some advice who has been through the FetLife DMCA takedown notice bullshit before. ;)

  20. Mircea Popescu`s avatar
    Mircea Popescu 
    Sunday, 8 March 2015

    Probably best post publicly whatever advice that may be. As far as I'm concerned, being virulently litigious makes me immune to this low level sort of bs. As far as others are concerned, I have little doubt that the shit has significant chilling effect. Just going by the insistence with which they deploy it, it must work on plenty of people. That's unfortunate, and those people should be helped stand up to the grubby tactics of two bit "entrepreneurs" as much as possible.

  21. Like I
    Like I'd tell you 
    Friday, 10 April 2015

    fetlife is pissed cause when a woman signs up to the site she doesn't want to be put on some sort of fuck meat list without her consent.

    Legalities aside what you are doing is really shitty. Fetlife is meant to be a safer environment than other sites hence you are not able to search by age or sex.

    This makes it harder for creeps like you to find the youngest and most vulnerable members of the community to prey on.

    Shame on you. Leave us alone and fuck off to topix or something.

  22. Mircea Popescu`s avatar
    Mircea Popescu 
    Friday, 10 April 2015

    What you're doing is broadly known as Stockholm syndrome. If someone sells you a car that catches fire and burns your baby, don't be upset at the fire, be upset at the assholes that made a really, really shitty car.

    Go talk to that lying scumbag Huesmann and the rest of the Fetlife crew. THEY made the broken software putting you, and others like you at risk to save having to hire actual coders.

    Shooting the messenger is really extremely stupid a way to deal with the complexities of life.

  23. Something tells me "Like I'd tell you " left her comment off a directly traceable home broadband installation or similar. And is running windows, and her router still uses "admin" for a password, as it has for the past god knows how many years, and so on.

    But of course it's the intention that counts. She didn't tell you, and that makes a difference.

  24. Mircea Popescu`s avatar
    Mircea Popescu 
    Friday, 10 April 2015

    Omaigerd how did you guess all that!

  25. Just a hunch.

  26. Mircea Popescu`s avatar
    Mircea Popescu 
    Friday, 10 April 2015

    The "do what I mean" crowd. How did that go, "if you DWIM the Internet is unsafe at any speed" ?

  27. Go to hell.`s avatar
    Go to hell. 
    Friday, 10 April 2015

    Just because not everyone is an arrogant programmer or particularly skilled with the complexities of technology doesn't mean they suddenly forfeit the right to respect and privacy. Doesn't matter what their identity is-and frankly, I think your lack of ethics and morality is far more dubious than a fondness for whips or rope could ever be.

    Grow up.

  28. Mircea Popescu`s avatar
    Mircea Popescu 
    Wednesday, 15 April 2015

    Yes, that's what it means. EXACTLY that.

    Coming to terms with the simple facts of life is exactly what growing up is all about. Now stop misusing terms and get with the program.

  29. Probably best post publicly whatever advice that may be. As far as I'm concerned, being virulently litigious makes me immune to this low level sort of bs. As far as others are concerned, I have little doubt that the shit has significant chilling effect. Just going by the insistence with which they deploy it, it must work on plenty of people. That's unfortunate, and those people should be helped stand up to the grubby tactics of two bit "entrepreneurs" as much as possible.

    I thought you might like to know that I received a frivolous DMCA takedown notice from FetLife's James Huesmann myself, directed at The FetLife Creep List, Volume 1 (which is currently redirecting to another externally hosted copy, of course). What FetLife is doing is technically illegal, since under the DMCA it is illegal to (ab)use the DMCA process by sending takedown notices en masse while knowingly having no intent to or legal basis on which to follow up those notices. In every case that I'm aware of, FetLife's only action against even absurdly petty complaints is to send a DMCA notice, even in situations where it is obviously frivolous.

    Just google "frivolous dmca" for a wealth of information about companies losing a not-insignificant chunk of money for engaging in these frivolous suits. I have been compiling evidence of FetLife's frivolous litigation for several years now, and the mountain of evidence to support such a counter-suit against FetLife is growing by the month. So perhaps something can be done to help people stand up against John Baku and these two bit "entrepreneurs" after all.

  30. Mircea Popescu`s avatar
    Mircea Popescu 
    Friday, 8 May 2015

    It's not "technically" illegal, it's plain and simple illegal. The moral hazard is that they themselves are insulated from any sort of actual liability (by using the string of shells operating in various outlaw jurisdictions, like any scammers ever ; by using "plausibly deniable" agents - the Huesmann twerp, for instance, is not an employee or a legal representative of Bitlove - either the Cyprus shell or the Canadian DBA ; and so on).

    The correct avenue is to extract damages from whosoever actually buys into their bullshit, which is usually going to be an innocent DC manned by naive, well meaning random people with other backgrounds than law. While this is reasonably productive for you, and very damaging to unrelated third parties (the DCs), it's neither here nor there for the actual conmen themselves.

    Nevertheless, this is a license to print money. Simply host the material on any US based DC's servers, wait for the fraudulent DMCA notices, wait for the DC to fuck up, sue the DC and either settle if you want to keep milking the cow or take them to court if you particularly wish to own a DC.

  31. My enemy's enemy is my friend, so a gift is in order.

    Dox on James Huesmann -

  32. Lulz #trilemaleaks

  33. Dox on James Huesmann -

