Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

81–90 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#81

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

The charitable answer is that organizations across US society are currently all trying to be very still and quiet and not do anything to provoke a vindictive assault by this administration.

The less charitable one is that Moxie was the opinionated and uncompromising core of the Signal Foundation and has been removed from the board and completely vanished from the public eye. What it stands for now is a touch less clear.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#82
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…

IT staff that knew it was illegal to provide them tools for a conspiracy were fired or silenced. So the only people left were their cronies, who instantly complied with their illegal request, to the best of the cronies' abilities. For such national failures, the buck has to stop at the very top, not on some IT monkey.

This is typical for highly corrupt governments and autocracies, they crumble from within because the autocrats can't trust random, competent people so their inner circle becomes saturated with people who are selected on the basis of loyalty not competence, and these people end up making the most important decisions and running the country.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#83
post #67

Earlier quoted context omitted.

This feature must be explicitly enabled, it is not on by default nor by accident.

huh, I sure seem to be needing to debug this a lot, I guess I'll just leave it turned on all the time that way I can say a few seconds next time. Larry Wall says one of the virtues of being a great developer is laziness!

[dead]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#85
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…

Would tend to agree with most of that, but I think the assertion is Petey needed to ask his IT leadership to do the due diligence before diving in, not that he needed to decide using his own depth of skills and experience.

I assume he did and they said it was a bad idea - the memo they'd released a few weeks prior about Signal vulnerabilities seems to suggest a lack of faith in that approach - but he was already banging away on his phone with all the grocery reminders and definitely not battle plans he needs to keep pushing out. Which is also how it feels in the enterprise space these days.

Strange thing to see our bureaucracy start to behave like a corporation instead of the other way around.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#86
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

(read with sarcastic tone) But hey, this is a 'lite' version or a 'red' version (icon is red) or a 'purple' version (icon is purple), so I am cooler that then others that have the standard.

I haven't used WhatsApp for 'a very long time' as I have exited the FB ecosystem, but back in the day I remember seeing "lite" or "WhatsApp+" or other variations of the software. I wouldn't be surprised that those "lite" or "+" come with baggage.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#89
post #57

Security standards need to start banning heap dumps.

I’m pretty sure they already do, especially endpoints open to the whole internet that are unauthenticated.

If only there was a rule saying "don't do that, this would not have happened
Post reply on HN