Live data from Hacker News

DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

micahflee.com

21–30 of 209 posts

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#21
> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers.

Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required.

Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct procedure their government already wants them to use. The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions. Their incompetence put their nations at risk, and now it's clear they have failed to keep their intel safe. They have failed hard, let them fail hard.

Second, journalists and researchers have almost completely lost their power. In a non-democratic world (we're nearly there, just give them a little more time), when a journalist exposes corruption or incompetency, that journalist/researcher is simply silenced by the government. Silence the journalists and nobody knows what's going on so oppression can continue unchecked. Every person who gets silenced has a greater chilling effect on the whole society; nobody wants to be next. This is how authoritarians gain power. Oppression with no resistance or consequence legitimizes the oppression.

If we were just talking about typical corporate incompetence re: security, and the only thing at stake is a single stock or individuals' data, I would say disclose responsibly. But when it comes to stopping autocracy, the gloves have to come off. They sure as shit aren't gonna play by any rules, so neither should we.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#22
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#23
post #10

Earlier quoted context omitted.

I don't disagree generally, but it should be noted that the TeleMessage federal contracts predate this administration. > According to Padgett and government records reviewed by NBC News, government contracts (some of which are still current) involving TeleMessage go back years, predating the current Trump administration. One current contract that mentions TeleMessage allocated $2.1 million from the Department of Home…

Sure, but was it being used to send secure military messages in the past? Or was it being used as a slightly more secure text messaging replacement by agencies that weren’t subject to the same security requirements as the Secretary of Defense?

It is my understanding that the normal procedures mandate that government supplied locked down devices be used for classified communications, not personal phones running Israeli cloud-connected messaging apps.

This is comparable to everyone using Hillary's email server for classified messaging, except also controlled in a foreign country, and oops very insecure.

Even office drones working at a bank aren't allowed to do such things.

This is not normal.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#24
post #22
post #2

So one of their servers had a /heapdump endpoint that publicly served a heap dump of the server? This whole saga is out of control. This group didn’t really “publish” anything, though. They’re offering access to journalists through a request form. They’re also not saying how much actual message content they have because the 410GB of heap dumps makes for a bigger headline number.

Sounds like someone had a Java app and mistakenly exposed all of the JMX endpoints over HTTP. It's not the default configuration, and likely done out of carelessness.

Or intentionally. There could be an APM agent which just lets you run heap dumps any time you want, or they enabled heap-dump-on-crash, or had a heap dump shutdown hook, etc. There's a lot of ways to trigger dumps. If we're talking about a full dump, and the apps were using most of the memory allocated to their container/VM/etc, 410GB is actually not that many dumps (we're probably talking uncompressed). At 4GB/dump, that's around 100, over possibly several years.

I just wonder where they were storing them all? At one place I worked, we jiggered up an auto shutdown dump that then automatically copied the compressed dump to an S3 bucket (it was an ephemeral container with no persistent storage). Wonder if they got in through excessive cloud storage policies and this was just the easiest way to exfiltrate data without full access to a DB.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#25
post #20
post #9

Earlier quoted context omitted.

Why would the company be embarrassed? The users (i.e. high level U.S. officials) did no due diligence. Of course a private company is going to take the easiest and cheapest route. If it goes bad, just shut down and spin up a new entity. Some speculate this was intentional intelligence gathering by the Israelis which is plausible too.

> Some speculate this was intentional intelligence gathering by the Israelis which is plausible too. How does this make sense? If they were gathering data, why would they add a public download? Surely the Israeli officials would not want foreign powers to access this? Per Hanlon's razor, I don't think this is attributable to anything other than incompetence.

I mean, it could theoretically have been to provide plausible deniability, but it seems extremely more likely to have been incompetence and carelessness (and if they were also sending everything to Israel, it was probably through some unencrypted ftp upload).

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#28
post #4

Earlier quoted context omitted.

Can you imagine co-opting a trusted and secure (and free) bit of software and just making it worse at seemingly every turn? And charging for it?! I’m not sure what is more embarrassing: to be the company or to be a user.

The changes to the application are intentional by all parties because message archiving was required by law.

Well, I suppose technically this /heapdump endpoint does satisfy that archive requirement.

Re: DDoSecrets publishes 410 GB of heap dumps, hacked from TeleMessage

#29

> Because the data is sensitive and full of PII, DDoSecrets is only sharing it with journalists and researchers. Yeah I'm normally a big proponent of responsible disclosure, but in this case, I think the more painful, damaging leak is required. Firstly, autocrats, fascists & oligarchs don't care that much if you hack them. They will just keep using these tools (or another one just like it) ignoring the correct proced…

> The citizens of affected nations need to be made angry by their leaders' failure to do their jobs correctly, and that's only gonna happen when there are consequences for their actions.

This is a really dangerous line of thinking. It's the line of thought that slides forwards to "I love America so much, but to save America I have to get Americans to really feel the pain, and to do that I need to to them to wake them up and make them see how things are bad."

Hurting people in order to make them see how they are being hurt is almost never the right call.

Post reply on HN