Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

71–80 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#72
post #3

Earlier quoted context omitted.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.

That sounds more like a stupid person than smart lol

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#73
post #9
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence.

But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket.

Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and say "my shit's broke" and they respond "we just overnighted you a new phone".

These people couldn't even install an app on their MDM-controlled device, now the narrative has become we expect them to be making low-level IT decisions too?

Next week we'll be scrutinizing Pete Hegseth's lack of thoughts on rotating backup tapes.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#74

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to to them to wake them…

I feel like it's valuable to not flatten the context here. We are talking about leaking texts by the Trump admin (and I guess some law enforcement agencies using this?).

There is a lot of daylight between dropping a bunch of texts for government officials and committing horrible violence against people as a whole! These are not the same thing! One could be good/fine while the other is bad!

Having said that I would worry for a WikiLeaks-style "oh now this random person's info is out there because it was in one of these e-mails".

I just want to see the gossip

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#75
post #54

Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.

Amazingly the app is on the governments list of approved apps. The scandal is what they’re discussing on there: highly sensitive information you normally go to very secure channels to talk about.

My understanding is that it was added fairly recently at that, and already this has happened. This must be a record time in "change of policy leading to the most embarassing result". Only a couple of months!

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#76

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

They don't need to "silence journalists", since a large number of people were duped to think real truth comes from random anonymous accounts on social media or from some charismatic political influencer they follow. It doesn't matter what leaks are exposed when it can just be handwaved as "fake news" and enough voters will buy that.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#77
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

"All supposed to be".

This is a country of 10 million people, a rather heterogeneous one at that. There are going to be better and worse companies.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#78
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…

> ... narrative has become we expect them to be making low-level IT decisions too?

I think that's a misdirection.

The narrative is that:

a) they were using a compromised piece of software

b) they should not have been using that software - not (necessarily) because it was compromised, but because it wasn't US DoD accredited for that use case.

(I understand your point that these guys are not tech savvy, and do not need to be, but they should be regulation-savvy (clearly they either are not, or willingly broke those regulations), and they should be following organisational guidelines that presumably cover the selection and use of these tools types.)

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#79
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…

Their massive it staff provides them with a way to communicate securely and they ignore it deliberately so that their communications are not preserved for history or for future court cases.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#80
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…

It is too early to tell, but given that these people openly attack scientists and other experts (they don’t agree with), I wouldn’t be surprised if they ignored advise of their IT experts.
Post reply on HN