DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
61–70 of 209 posts
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#62> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…
> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to to them to wake them…
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#63Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#64Earlier quoted context omitted.
Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.
One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#65- Pete Hegseth
That line simultaneously becomes funnier and more depressing.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#66Security standards need to start banning heap dumps.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#67Earlier quoted context omitted.
There’s room for both sides of the razor. The heapdumpz could be there maliciously, but incompetently made globally accessible.
From the Wired article: "The archive server is programmed in Java and is built using Spring Boot, an open source framework for creating Java applications. Spring Boot includes a set of features called Actuator that helps developers monitor and debug their applications. One of these features is the heap dump endpoint," So the heapdumps being available is a Spring Boot feature so it does not appear to be malicious.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#68Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#69> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…
> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to to them to wake them…
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#70Earlier quoted context omitted.
From the Wired article: "The archive server is programmed in Java and is built using Spring Boot, an open source framework for creating Java applications. Spring Boot includes a set of features called Actuator that helps developers monitor and debug their applications. One of these features is the heap dump endpoint," So the heapdumps being available is a Spring Boot feature so it does not appear to be malicious.
This feature must be explicitly enabled, it is not on by default nor by accident.