Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

121–130 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#121
post #49

Earlier quoted context omitted.

Is it? The article indicates at least some of this comes from merely incrementing an integer in the video URLs. > I am now crawling URLs of all videos uploaded to Parler. Sequentially from latest to oldest. VIDXXX.txt files coming up, 50k chunks, there will be 1.1M URLs total...

People have been sent to prison before for nothing more than fetching publicly available web pages by incrementing numbers in a URL: https://en.wikipedia.org/wiki/Weev

...and publishing the personal data they got their hands on this way ("In revealing the flaw to the media, the group also exposed personal data from over 100,000 people")

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#122

Earlier quoted context omitted.

Wikileaks leaked John Podesta's emails, including such criminal activity as his recipe for risotto.

It's generally a good idea for leakers to be selective about their releases (Snowden did a better job than Manning in that area IMO). I guess Wikileaks is between a rock and a hard place, because if they started editorializing then that would lead to political bias.

Political bias? Like when Wikileaks supported researching the Pizzagate conspiracy during the 2016 US election and posted links to /r/The_Donald "investigation" threads?

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#123
post #34

Could these "Researchers" be prosecuted under CFAA? Purposely accessing information known to be private? EDIT: accidently wrote DMCA

Practically no. Judges, tech community lobbyists, and basically the entire state is on their side.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#124
post #8

This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…

> I would also probably buy said malicious actors a beer if I met them, accompanied by a high five.

Take your lazy dicksucking elsewhere. Suggestion: Go back to reddit.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#125
post #86

Earlier quoted context omitted.

The ramifications of this will absolutely set a record for the future as the inevitable reverse will happen. People are forgetting that if they're ok with this sort of behavior now, it'll be difficult for them to argue-against or prevent the same behavior when their opposites are in control.

They are betting everything on the belief that they will win permanently this time, and their opponents will never get control again.

It reminds me of Pascal's wager. How confident can one be that one's chosen political team will definitely win out in the long run? 90%? That seems very high, but even if you're 99% sure, are you willing to act in a way that will surely warrant retribution in the unlikely adverse scenario? Seems like a pretty dumb wager to make.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#126

When you purposefully leak private data, you no longer get to hide behind the title "Security Researcher".

AFAIK, they have not publicly released any data dumps from this (yet? Maybe they're planing to).

If I were sitting on a dataset like this, I'd probably try to share it with the authorities like the FBI and selected journalists who I feel would behave responsibly.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#127
post #49

Earlier quoted context omitted.

People have been sent to prison before for nothing more than fetching publicly available web pages by incrementing numbers in a URL: https://en.wikipedia.org/wiki/Weev

I don't know how it works "over there", but where I'm from "URL-hacking" is not considered hacking, but data publicly available.

...and you are 100% sure that if this got before a court, the decision would go your way?

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#128
post #57

While I understand that Twilio is probably not at fault for the actual leak, I'm curious if they gave Parler some time to migrate/shift before cutting them off from their services. It's easy not to care since Parler is the "bad guy" here, but I do think that Internet infrastructure companies need to give a reasonable heads-up before pulling the rug under business customers.

They ignored AWS’s warnings for weeks. It seems unlikely that a grace period would do anything.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#129

When you purposefully leak private data, you no longer get to hide behind the title "Security Researcher".

A more obvious criterion would be that there's no implication the people who compromised Parler actually do any kind of research on computer security. The article indicates this was a script-kiddie level vulnerability.

On the other hand if an actual researcher leaks data they're still a researcher; they might be a bad person, but that's orthogonal.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#130
post #27

Earlier quoted context omitted.

As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.

Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.

>Why would anyone design a system that way

Because they knew that, being a save haven for violent white supremacists, it was likely one or more of their service providers would terminate service and wanted to continue to operate despite any termination.

Post reply on HN