Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

11–20 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#11
post #8
post #3

Earlier quoted context omitted.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

That's not a great generalisation for the whole country. How many ex Mossad people interested in doing actual implementation in tech companies do you think there are? It's like "aren't those US software companies all supposed to be top notch, ex NSA yadda yadda?"

They do start a lot of tech companies specifically: https://en.wikipedia.org/wiki/Unit_8200#Companies_founded_by...

The US only has voluntary military service, so the dynamics are different

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#12
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

[deleted]

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#13
post #4
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

The changes to the application are intentional by all parties because message archiving was required by law.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#14
post #9
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

>Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

Which does not bode well for the customers' counter intelligence abilities

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#15
post #3

Earlier quoted context omitted.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

[flagged]

This article doesn't mention Mossad, though. Do you have any other sources?

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#16

[flagged]

I find it interesting that so many people are still treating this administration as if they are acting in good faith about anything.

They don't just seem to be incompetent, they seem to be wilfully negligent.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#17
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

The changes to the application are intentional by all parties because message archiving was required by law.

Sure, but they were not required to be done incompetently and insecurely.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#18
post #10

Earlier quoted context omitted.

I don't disagree generally, but it should be noted that the TeleMessage federal contracts predate this administration. > According to Padgett and government records reviewed by NBC News, government contracts (some of which are still current) involving TeleMessage go back years, predating the current Trump administration. One current contract that mentions TeleMessage allocated $2.1 million from the Department of Home…

Sure, but was it being used to send secure military messages in the past? Or was it being used as a slightly more secure text messaging replacement by agencies that weren’t subject to the same security requirements as the Secretary of Defense?

> but was it being used to send secure military messages in the past?

We have no information on that one way or the other.

> a slightly more secure text messaging replacement

Yea but it wasn't secure at all. For any purpose.

> that weren’t subject to the same security requirements as the Secretary of Defense?

Regardless of who is using it and for what purpose I'd like the server to actually be secure.

This isn't a left vs. right issue. This is an overall government incompetence issue.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#19
post #3
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Aren’t those Israeli software companies all supposed to be top notch, ex Mossad, yadda yadda? Doesn’t sound like it. I hope the message dump is juicy.

I thought Israel has mandatory military service, so ex-mossad or ex-military signals intelligence doesn't really say much? Presumably they're directing people based on their skill set, so you'd expect most hackers to end up in mossad for their mandatory service.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#20
post #9
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

How does this make sense? If they were gathering data, why would they add a public download? Surely the Israeli officials would not want foreign powers to access this?

Per Hanlon's razor, I don't think this is attributable to anything other than incompetence.

Post reply on HN