Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

151–160 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#151
post #8

This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…

The old age question with fail-closed is then not locking yourself out when things go wrong

Everything has/should have a "break window" escape, and yes, that's a security weakness, but I don't see many alternatives to that.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#152

Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.

most of us are trying to reflect on whether this is 'private messages' or 'evidence of crimes'

I doubt anyone on HN would take seriously any other service turning over evidence of a crime to authorities because its 'private messages'. We might not like that it is there policy but we damn well would know it is their policy and not use services where it is technically possible to plan crimes?

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#153
post #94

Earlier quoted context omitted.

Pretty clear where their priorities lay, huh. Breaking the security of their users is less important than getting new users.

Nah man, I won't criticize too hard. There but for the grace of god goes I, you know? I've had flakey dependencies. I've thought "maybe fail open is okay in this one case". You're growth hacking your company and you don't want to be held back because a dependency can't handle your scale. And hey, if a few fraudulent accounts get in, we'll just clean them up later. Cost benefit analysis here, right? But the road to he…

Isn't that exactly what the above comment is saying?

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#154

Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.

> the media told me these guys are the bad guys.

They sacked the capitol and cheered it on (yes, almost exclusively as far as the people on Parler are concerned).

They are indeed the bad guys.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#155

Earlier quoted context omitted.

Weev's conviction was vacated.

On a technicality because of where he was charged, not because of the law. I don't think he should have ever been convicted under the CFAA, but he was.

From Wiki on his case:

> While the judges did not address the substantive question on the legality of the site access, they were skeptical of the original conviction, noting that no circumvention of passwords had occurred and that only publicly accessible information was obtained.

It's a pity it didn't make it to full review on appeal to get a solid ruling on this.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#156
post #94

Earlier quoted context omitted.

Pretty clear where their priorities lay, huh. Breaking the security of their users is less important than getting new users.

Nah man, I won't criticize too hard. There but for the grace of god goes I, you know? I've had flakey dependencies. I've thought "maybe fail open is okay in this one case". You're growth hacking your company and you don't want to be held back because a dependency can't handle your scale. And hey, if a few fraudulent accounts get in, we'll just clean them up later. Cost benefit analysis here, right? But the road to he…

So, you agree with what I said.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#157

I've always been amazed at how hackers can exfiltrate so much data with no one even batting an eye. Doing the math, the pure data cost to Parler was $7,700 (($0.15/GB 10) + ($0.11/GB 40) + ($0.09/GB 20)) 1000 => $7,700 https://aws.amazon.com/blogs/aws/aws-data-transfer-prices-re... Even the Chase Bank hack had an astronomical amount of data that didn't appear to set off any alarms.

According to reports, their monthly AWS spend (prior to today, obviously) was ~300k (or 3.6M/year).

7.7k is not really a noticeable increase, and any alarms that did trigger would likely have been attributed to increased user growth and platform load.

That is if someone was even seeing a billing alarm alerting with every other issue that was going on.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#158
post #34

Could these "Researchers" be prosecuted under CFAA? Purposely accessing information known to be private? EDIT: accidently wrote DMCA

Practically no. Judges, tech community lobbyists, and basically the entire state is on their side.

That's not really how it works, jury nullification notwithstanding.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#159
post #99

Earlier quoted context omitted.

I generally agree that information from here related to the attack is in the public interest. But this is going to also reveal people who had no part of it. I don't think it's fair to justify revealing innocent peoples data.

[flagged]

You sound like the kid that couldnt understand why no one hungout with them

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#160
post #72

Earlier quoted context omitted.

Only if it the data was government / private sector data, not citizen messages

What exactly the difference between "private sector data" and "citizen messages"? Wikileaks published a ton of data from personal sources. Famously, the Podesta leak was from a private account and absolutely contained personal communication (about, again famously, a favored pizza joint).

>What exactly the difference between "private sector data" and "citizen messages"?

That "fuck businesses", while "leave actual people ok".

Post reply on HN