Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

51–60 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#51

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to to them to wake them…

This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have lie and cover up the truth of the being done to them so they'll never see how bad things have gotten."

Lying to people in order to make them never see how they are being hurt is almost never the right call.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#52

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

You're making me wonder if Signal is the customer of the third party and not the government.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#54

Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.

Amazingly the app is on the governments list of approved apps. The scandal is what they’re discussing on there: highly sensitive information you normally go to very secure channels to talk about.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#55

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions.

The consequences likely wouldn’t be felt by those leaders though. Who knows what info is in those logs about informants, agents etc etc. Leak it openly and they’re dead.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#56
post #17

Earlier quoted context omitted.

The changes to the application are intentional by all parties because message archiving was required by law.

Sure, but they were not required to be done incompetently and insecurely.

The fundamental concept of plaintext archiving (escrow) of messages from e2ee messaging apps is insecure by most definitions.

They could have used user-custody public key cryptography, where the end devices have the pubkey of the customer, and archive only re-encrypted messages to TM that they can’t read.

That is not, of course, what they did. They just archive them in plaintext.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#59

cannot the pentagon with their billions in funding make a secure app?

Yes, and they do. The fact that the leaders of our present kakistocracy don't use it should not be an indictment of the civil and military workers in the US military.

No, the fact that they still work for the US government given “our present kakistocracy” is a sufficient indictment.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#60

Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.

The app exists to comply with the regulations, was my understanding.
Post reply on HN