Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

111–120 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#111
post #9
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

The Israeli would have made it secure so only them can access the data because knowing someone else's secret is worth something only when it's still a secret, if china, Russia and everyone can read the log of the American government it's worth nothing.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#112

We‘re doing something way less critical at my job. But we have two pentests per year by external companies. How on earth is this level of incompetence even legal.

I don't think it was. Apparently they faked their SOC2 as well

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#113
However bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane

https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#114

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

[flagged]

[dead]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#115
post #22

Earlier quoted context omitted.

Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.

From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."

This sounds utterly insane. Is Actuator a standard part of Spring Boot or is it an optional package of some kind?

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#116
post #48
post #3

Earlier quoted context omitted.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

And SBF of FTX fame was ex-Jane St so obviously was a serious finance professional. This is why using past employers as a shorthand for capability is unwise.

In fairness, FTX had a profitable bankruptcy [1]. So it's still better to be scammed by Jane Street alumni than to be scammed by the usual alumni of Goldman Sachs, JP Morgan etc

[1] https://www.bloomberg.com/news/articles/2024-05-15/ftx-bankr...

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#117
post #22

Earlier quoted context omitted.

Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.

From the Wired article, it may not have even been a mistake, depending on the version of Spring Boot. "Spring Boot Actuator. “Up until version 1.5 (released in 2017), the /heapdump endpoint was configured as publicly exposed and accessible without authentication by default."

Imaging putting up a firewall to mitigate this, then docker compose helpfully opening the ports for you. Security comes in layers.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#118
post #72

Earlier quoted context omitted.

One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.

That sounds more like a stupid person than smart lol

you can be smart in one area and stupid in others. the "not knowing you're stupid in others" is part of the "stupid in others".

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#119

However bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

> and people were buying it! real corporations and governments were buying this crap - it's insane

Anedote: in Wall Street, Global Relay and TeleMessage are the major players when it comes to achieving communication for compliance.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#120

Earlier quoted context omitted.

This just reads like a terrible LinkedIn-speak to me.

Sufficiently advanced human written linkedin-speak is indistinguishable from a barely coherent chatgpt 3.5 that's been instructed to speak in business buzzwords.

Hahaha, I was thinking the exact same thing! I can imagine myself reading this 10 years ago and think: Wow this guy is on top of his CV game, how concise and elegant. But now, everybody has this ultra condensed LinkedIn speak, it has become so cringe, so meaningless.
Post reply on HN