Live data from Hacker News

Parler Databases Disclosed

twitter.com

51–60 of 168 posts

Re: Parler Databases Disclosed

#51
post #42

Earlier quoted context omitted.

Hijacking top comment. Here's the data: https://donk.sh/06d639b2-0252-4b1e-883b-f275eff7e792/ #noflylist is trending on Twitter. Guess a lot of jobs will soon be available in Silicon Valley.

That is just a list of parler public urls.

The URL lists were used to distribute archiving of media content. 70TB of text, image, video, and metadata content was downloaded in a few hours with essentially a volunteer botnet.

The team at archive.org is importing the full archive right now.

Re: Parler Databases Disclosed

#52

Oh come on, it was a honeypot from the beginning. Everybody in the last few days was talking about Parler -- they got more exposure than ever in their life. The takedown from AWS was announced a few days before, so more users could register. Parler was running a "Verified Parler citizen" (wat?) campaign, to gather more personal data. And now, hackers conveniently exposed everything. Hackers are unpredictable, you kno…

The verification, according to their ToS, was only required if the user wanted to take part in their monetization program. Their ToS states that US law requires them to gather certain PII for auditing purposes. A regular user didn't need to submit anything but an email address.

Re: Parler Databases Disclosed

#53
post #4

"Twilio put out at midnight last night. In that Press Release, Twilio accidentally revealed which services Parler was using. Turns out it was all of the security authentications that were used to register a user. This allowed anyone to create a user, and not have to verify an email address, and immediately have a logged-on account. Well, because of that access, it gave them access to the behind the login box API that…

BTW, where is that Press Release? Can't find it on the Twilio website.

Re: Parler Databases Disclosed

#54

If there is one lesson to be learned from these last few weeks it is that you can not rely on any external service if you do anything which goes against the dominant political narrative. I have never been on Parler's site so I can not check the veracity of their supposed implied or direct support for seditious acts but that does not seem to matter anyway, it is enough to stand accused to be considered a witch and bur…

It has nothing to do with "the dominant political narrative", and it has everything to do with violent rhetoric on their platform that they refuse to moderate. This violent rhetoric is against the Terms of Service for the external services that they rely on, hence the termination of those relationships.

Re: Parler Databases Disclosed

#55

If there is one lesson to be learned from these last few weeks it is that you can not rely on any external service if you do anything which goes against the dominant political narrative. I have never been on Parler's site so I can not check the veracity of their supposed implied or direct support for seditious acts but that does not seem to matter anyway, it is enough to stand accused to be considered a witch and bur…

There's going against the dominant political narrative, and there's organizing and committing federal crimes like breaking and entering into congress.

You have freedom of speech and the government cannot arrest you from saying things on the internet. However, organizing a raid on the government will get you in trouble, and never forget that nobody is obligated to give you a platform.

Re: Parler Databases Disclosed

#56

AWS gives 5Gbps connectivity to instances, according to https://docs.aws.amazon.com/whitepapers/latest/ec2-networkin... So, if the sum total of Parler was 70 Terabytes, as claimed... the transfer time would be 38 hours, if it was hosted on one instance... but it obviously wasn't. It was more likely only a matter of minutes. This shows a new type of cloud hosting vulnerability. Your entire corporations infrastructure…

I think all the content was hosted on S3

Re: Parler Databases Disclosed

#59
post #52

Oh come on, it was a honeypot from the beginning. Everybody in the last few days was talking about Parler -- they got more exposure than ever in their life. The takedown from AWS was announced a few days before, so more users could register. Parler was running a "Verified Parler citizen" (wat?) campaign, to gather more personal data. And now, hackers conveniently exposed everything. Hackers are unpredictable, you kno…

The verification, according to their ToS, was only required if the user wanted to take part in their monetization program. Their ToS states that US law requires them to gather certain PII for auditing purposes. A regular user didn't need to submit anything but an email address.

Not exactly. They were promoting verification on their front page, as a measure to "fight bots". Verified accounts were displaying a "not a bot" badge.

Re: Parler Databases Disclosed

#60
post #4

"Twilio put out at midnight last night. In that Press Release, Twilio accidentally revealed which services Parler was using. Turns out it was all of the security authentications that were used to register a user. This allowed anyone to create a user, and not have to verify an email address, and immediately have a logged-on account. Well, because of that access, it gave them access to the behind the login box API that…

Did Twilio actually make this alleged press release? There is nothing like that on https://www.twilio.com/press/releases
Post reply on HN