Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

171–180 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#171

'Heapdump' is a term I learned from debugging android applications 15 years ago. Its just a snapshot of the java processes memory. Its going to contain plaintext. Now why those heaps are available at an open http endpoint is another matter, and is the interesting point. I'm guessing the client code had that endpoint hardcoded somewhere or they saw a request to it. I'm not seeing how they could know anything about the…

The observability endpoints have defaults in Sprint Boot and are usually not customized. So if you know the path to the API, you also know the path to the heap dump endpoint

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#173
post #142

Earlier quoted context omitted.

If we really think about the issue, then it is clear that 99.99% of the government information can be public with zero consequences to the citizens. I'm guessing the only few exceptions are active military ops, active spy ops and ways to access secure systems (passwords etc.). Everything else is more or less safe. Embarrassing to the politicians, but safe.

You need to account for the risk of blackmail, persecution, and embarrassment (e.g., evidence of infidelity, refugee status, medical condition). Most of the time, citizens have the right to keep secrets or lie.

Citizens - yes. Politicians outside of the job, using whatever comms they wish - also yes. Politicians on the job - no. All their job communications can be public, and humanity and citizens of the country would be actually much safer than now. Outside of the military/intel ones, of course.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#174

Earlier quoted context omitted.

I'm annoyed by moxie vs fdroid as the next guy, but this is way above his desire to make a buck from his honest work. this is about an overseas elite who profited from US war aid for decades holding the US presidency by the balls, and everyone think this is just incopetence. think for a second, if any other administration was using a telephone or a communication software made by a never heard before company overseas,…

> if any other administration was using a telephone or a communication software made by a never heard before company overseas, would you think it was just incompetence? One interesting thing I saw in the original article was that the US was using TeleMessage since February 2023. If that's true, it means we have two administrations who are responsible for this choice.

very true, but i don't imagine the previous administration was discussing tactical plans on said modified client

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#175

However bad their Signal fork was, at least it was legal. What's crazy is that this very company was also selling a cracked WhatsApp, which is a whole different kettle of fish... and people were buying it! real corporations and governments were buying this crap - it's insane https://smarsh.my.salesforce.com/sfc/p/#30000001FgxH/a/Pb000...

Why would that be illegal? In the Beeper case, the DOJ has not been sympathetic to companies attempting to ban third-party messaging clients of proprietary protocols [0] — is WhatsApp different?

The WhatsApp archiver, from what I can tell, seems to install a patch on the user's WhatsApp installation. Probably a security nightmare, sure, but I don't think it would be illegal.

https://techcrunch.com/2024/03/21/doj-calls-out-apple-for-br...

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#176

It's been weeks since the initial TeleMessage revelation... has the Signal Foundation responded in any way to the news? They condemn open source third-party clients and threaten trademark litigation when people use the "Signal" name in interop projects. Meanwhile, total silence when a defense contractor does the same thing.

Protecting your name is perfectly fine. You're allowed to make a fork of Firefox, you just can't call it Firefox or use any of Mozilla's branding. You're allowed to fork the open source part of VS Code, you just can't call it that or use Microsoft's branding. etc. etc. - you're free to do with open source whatever the license allows, but you're not allowed to use the original name or branding because you have zero ri…

That's not the issue here. VSCode and FireFox are false equivalents. Even if you'd rebrand the fork, Signal forbids non-official clients/builds from connecting to their servers. Enforcement has been selective but the last official word AFAIK is that you are not allowed to fork, rebrand, and distribute a client which alllows you to chat with Signal users.

Mozilla still allows you to install and download add-ons and use other Mozilla services like VPN and Relay from your LibreWolf build.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#177

'Heapdump' is a term I learned from debugging android applications 15 years ago. Its just a snapshot of the java processes memory. Its going to contain plaintext. Now why those heaps are available at an open http endpoint is another matter, and is the interesting point. I'm guessing the client code had that endpoint hardcoded somewhere or they saw a request to it. I'm not seeing how they could know anything about the…

The observability endpoints have defaults in Sprint Boot and are usually not customized. So if you know the path to the API, you also know the path to the heap dump endpoint

It's just /actuator/heapdump and usually isn't hard to find. It's off by default in more modern versions but used to be default enabled.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#178
post #54

Isn't it against the law in the United States to use outside channels for government communications? Wasn't this the whole scandal about Clinton? Please correct me if I am wrong.

Amazingly the app is on the governments list of approved apps. The scandal is what they’re discussing on there: highly sensitive information you normally go to very secure channels to talk about.

This is a pitfall of having an approved software list (whitelist).

Malfeasance or misfeasance could include flat-out spyware versions of software, often made available in internal "software stores," instead of legitimate software distributed from the developer or through official channels.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#179

Exposing unauthenticated /heapdump endpoints in production is a rookie mistake-especially for a service handling sensitive government comms. The presence of MD5 hashes and legacy tech like JSP just adds to the picture of poor security hygiene. This breach is a textbook case of why defense-in-depth and regular audits are non-negotiable.

[deleted]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#180
post #76

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

They don't need to "silence journalists", since a large number of people were duped to think real truth comes from random anonymous accounts on social media or from some charismatic political influencer they follow. It doesn't matter what leaks are exposed when it can just be handwaved as "fake news" and enough voters will buy that.

Journalists being a "check on the government" is a tale for the gullible. That's why there doesn't need to be any silencing of them. Glory to the exceptions, of course.
Post reply on HN