Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

1–10 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#2
So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control.

This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it.

I hope the message dump is juicy.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn?

And charging for it?!

I’m not sure what is more embarrassing: to be the company or to be a user.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#5
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

[flagged]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#7

[flagged]

I don't disagree generally, but it should be noted that the TeleMessage federal contracts predate this administration.

> According to Padgett and government records reviewed by NBC News, government contracts (some of which are still current) involving TeleMessage go back years, predating the current Trump administration. One current contract that mentions TeleMessage allocated $2.1 million from the Department of Homeland Security and FEMA for “TELEMESSAGE MOBILE ELECTRONIC MESSAGE ARCHIVING,” beginning in February 2023, with an August 2025 end date.

https://www.nbcnews.com/tech/security/photo-appears-shows-mi...

https://www.usaspending.gov/award/CONT_AWD_70FA3123F00000028...

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#8
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

That's not a great generalisation for the whole country. How many ex Mossad people interested in doing actual implementation in tech companies do you think there are? It's like "aren't those US software companies all supposed to be top notch, ex NSA yadda yadda?"

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#9
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity.

Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#10

[flagged]

I don't disagree generally, but it should be noted that the TeleMessage federal contracts predate this administration. > According to Padgett and government records reviewed by NBC News, government contracts (some of which are still current) involving TeleMessage go back years, predating the current Trump administration. One current contract that mentions TeleMessage allocated $2.1 million from the Department of Home…

Sure, but was it being used to send secure military messages in the past? Or was it being used as a slightly more secure text messaging replacement by agencies that weren’t subject to the same security requirements as the Secretary of Defense?
Post reply on HN