Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

121–130 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#121
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

I'm not sure why you'd expect intelligence agency types to be particularly good at engineering, tbh.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#122

TeleMessage CEO LinkedIn bio - reads like a terrible AI hatchet job: "At the helm of TeleMessage, my leadership is defined by strategic innovation and a steadfast commitment to advancing telecommunications solutions. With a focus on SaaS products, our team has successfully navigated the industry's evolution, ensuring that we remain at the forefront of technological advancements. My role encompasses not only the overs…

"I'm a CEO. We're SaaS. I'm a CEO."

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#123

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

The charitable answer is that organizations across US society are currently all trying to be very still and quiet and not do anything to provoke a vindictive assault by this administration. The less charitable one is that Moxie was the opinionated and uncompromising core of the Signal Foundation and has been removed from the board and completely vanished from the public eye. What it stands for now is a touch less cle…

Meredith Whittaker seems kinda fearless though

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#124
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

> Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda?

Working with a few companies like these, I can tell you that the marketing is top-notch, and very aggressive. The products not so. Most get better with time.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#125
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

This is why Signal is so opposed to third-party apps (or forks) that connect to their service.

If you want to keep the branding of Signal being the secure app, you need to make sure that all Signal users are actually using a secure version of Signal.

If an insecure fork (like this one) becomes too popular, most groups will have at least one member using it, and then the security is gone.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#126
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

Yeah the /leakitbaby endpoint was meant for just them, not the world! Doh!

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#127
post #48

Earlier quoted context omitted.

And SBF of FTX fame was ex-Jane St so obviously was a serious finance professional. This is why using past employers as a shorthand for capability is unwise.

In fairness, FTX had a profitable bankruptcy [1]. So it's still better to be scammed by Jane Street alumni than to be scammed by the usual alumni of Goldman Sachs, JP Morgan etc [1] https://www.bloomberg.com/news/articles/2024-05-15/ftx-bankr...

How is that fair? It was luck from the AI investment. Pure luck.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#128
post #105
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

if a heap dump is a copy of all the bytes in memory, then wouldn't "thousands of heap dumps" likely be larger than 410GB? napkin math: 410GB/1000 dumps = 410MB per dump? 410GB/2000 dumps = 205MB per dump

Might be filtered somewhat, like extracted all ASCII text then compile that into the dump, rather than just the raw dump files.

Edit: reading the description on the dump again, seems exactly what they did:

> Some of the archived data includes plaintext messages while other portions only include metadata, including sender and recipient information, timestamps, and group names. To facilitate research, Distributed Denial of Secrets has extracted the text from the original heap dumps.

https://ddosecrets.com/article/telemessage

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#129

Earlier quoted context omitted.

One problem that smart people tend to make is in thinking that being really smart in one area is generalizable to all others. Just because they're good at AppSec doesn't mean they're good at networking or operating a webserver.

I agree with this. It's surprising how often I encounter people with that belief, because I was disabused of it very early on in my career; this industry is chockablock with people who are brilliant in 1 area and deficient in others.

That's why you need teams. Red team for example! Security team. App developers. Code reviews. You need all the process too. Security that relies on one genius is fragile.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#130
post #3

Earlier quoted context omitted.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

After all the concern over China and TikTok, why is the USG using a foreign chat program at all?

SuperPAC and other corruption
Post reply on HN