Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

21–30 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#21

This sounds like an incredible fuckup by Twilio. If it's true that their authentication verification was the entrypoint, they could be liable for leaking an enormous amount of personal information.

How is this Twilio’s doing? Parler was not a customer when this happened. This was Parler being held together by duct tape and not having choices. This is what happens when a young and populated site dependent on services loses all of said services. That is to say: you are a fool to trust websites, especially Parler.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#24
post #8

This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…

Pretty clear where their priorities lay, huh. Breaking the security of their users is less important than getting new users.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#25
post #6

Earlier quoted context omitted.

Yes.

Why doesn't chain of custody apply to data?

It does, but in a murder trial, the weapon was generally out of police custody for at least some time, right?

There's an opportunity to introduce reasonable doubt when a third-party is in possession of the data in-between, but it's likely this sort of data isn't going to be the only evidence in any resulting prosecutions. It's far more likely to be probable cause for warrants.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#26
post #2

Discussion of how it was done here: https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_par... Edit: this Reddit post appears to be inaccurate. More details here: https://news.ycombinator.com/item?id=25725268

This copypasta is incorrect. See more here:

https://news.ycombinator.com/item?id=25725268

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#27

Sounds like Twillo was actively helping hackers "That allowed them to see which users had moderator rights and this in turn allowed them to reset passwords of existing users with simple “forgot password” function. Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease."

As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.

Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#29

This sounds like an incredible fuckup by Twilio. If it's true that their authentication verification was the entrypoint, they could be liable for leaking an enormous amount of personal information.

This loooks serious. I might have to start looking into Twilio alternatives form my company. Does anyone have any suggestions?

If you read what happened you'd know that this could never happen if they built their system with the minimum care required. Twillio is absolutely not the culprit.
Post reply on HN