So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.
if a heap dump is a copy of all the bytes in memory, then wouldn't "thousands of heap dumps" likely be larger than 410GB? napkin math: 410GB/1000 dumps = 410MB per dump? 410GB/2000 dumps = 205MB per dump
DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
131–140 of 209 posts
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#132> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…
[flagged]
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#133Earlier quoted context omitted.
> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…
It is too early to tell, but given that these people openly attack scientists and other experts (they don’t agree with), I wouldn’t be surprised if they ignored advise of their IT experts.
Yes, there's a fleet of people who are supposed to make such tech decisions. The people involved specifically went against those rules. The existence of a group chat using an authorised app is a violation on its own, adding a journalist to it is a violation on top of a violation.
Adding a journalist was accidental, but using such an app (despite it not being approved) is very intentional.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#134Earlier quoted context omitted.
Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.
> The users (i.e. high level U.S. officials) did no due diligence. But why would they? It's not their job. They have massive IT staff supporting them. "High level U.S. officials" are just executives; the pointy-haired bosses to the pointy-haired boss. Only difference is these wear little decorative pins over their breast pocket. Every Fortune 500 company has dedicated IT staff for execs; someone you can call 24/7 and…
If their staff makes bad decisions, that’s their failure too.
We expect them to be ultimately responsible for what happens on their watch.
Was it Truman who said, “Woah, don’t bring the buck anywhere near me, it stops with my assistant”.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#135It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.
this is about an overseas elite who profited from US war aid for decades holding the US presidency by the balls, and everyone think this is just incopetence.
think for a second, if any other administration was using a telephone or a communication software made by a never heard before company overseas, would you think it was just incompetence? why these traitors clowns get a pass?
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#136Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#137However bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...
> and people were buying it! real corporations and governments were buying this crap - it's insane Anedote: in Wall Street, Global Relay and TeleMessage are the major players when it comes to achieving communication for compliance.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#138Wow, this whole TeleMessage leak feels like a spy thriller.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#139I love when politicians, lobbying for the backdooring all communication software are getting pwned in the same way. Too bad they lack either brain cells or basic human empathy to make a connection between these events.
I think that's giving them too much benefits. They know what they're doing, it's clear they want "security for me, but not for you", and claiming they're too dumb to know exactly what they're doing is playing it exactly like how they want it.
Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage
#140Earlier quoted context omitted.
Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.
I'm not sure why you'd expect intelligence agency types to be particularly good at engineering, tbh.
It’s especially true for spooks of a certain entity. Also, it’s easy to confuse brazenness, being protected from consequences, and usually downplayed or secret Western complicity with competence.