Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

101–110 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#101
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

User for sure

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#102

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

Remember Signal FOSS fork that got cease and desisted?

How is Molly doing these days? Is there an alternative server you could selfhost?

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#103

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

Signal has done nothing wrong here. There's nothing they could meaningfully say that would do anything except draw heat from people looking for a scapegoat.

This mess is entirely the fault of Telemessage and the people who chose to use it for top-secret comms.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#104
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

They are top notch - at working for profit and for the interests of their country.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#105
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

if a heap dump is a copy of all the bytes in memory, then wouldn't "thousands of heap dumps" likely be larger than 410GB?

napkin math:

  410GB/1000 dumps = 410MB per dump?

  410GB/2000 dumps = 205MB per dump

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#106
The title is outright wrong and should be criticized for spreading false information. They have NOT published anything, it's only for "researchers", which is a way of saying "we will write false title of this article just so we can get a lot of attention"

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#107
post #76

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

They don't need to "silence journalists", since a large number of people were duped to think real truth comes from random anonymous accounts on social media or from some charismatic political influencer they follow. It doesn't matter what leaks are exposed when it can just be handwaved as "fake news" and enough voters will buy that.

>It doesn't matter what leaks are exposed when it can just be handwaved as "fake news" and enough voters will buy that.

Especially in conditions when you don't have to lie at that.

It's not because voters are so gullible that they are ready to believe any word of a charismatic leader. The loss of trust to the mainstream media and to the scientific community is a natural phenomenon in environment when they only tell lies to push their political agenda.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#108

TeleMessage CEO LinkedIn bio - reads like a terrible AI hatchet job: "At the helm of TeleMessage, my leadership is defined by strategic innovation and a steadfast commitment to advancing telecommunications solutions. With a focus on SaaS products, our team has successfully navigated the industry's evolution, ensuring that we remain at the forefront of technological advancements. My role encompasses not only the overs…

This just reads like a terrible LinkedIn-speak to me.

Sufficiently advanced human written linkedin-speak is indistinguishable from a barely coherent chatgpt 3.5 that's been instructed to speak in business buzzwords.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#109
post #9
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

[dead]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#110
https://nitter.net/ProjPM/status/1915527064070881379#m

Is this group not very seriously discredited, with ties to FBI, convicted child porn criminals, etc? Or am I getting something mixed up?

This could still be a legitimate leak, of course. I'm just wondering if this info is publically known, or if I'm conflating things

Post reply on HN