This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…
To give a bit of context, this is the "Keyboard Cowboy Hack The Planet" Parler lead engineer: https://pbs.twimg.com/media/ErcFo5tXAAAa0KP?format=jpg&name=...
70TB of Parler users’ messages, videos, and posts leaked by security researchers
291–300 of 1001 posts
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#292Earlier quoted context omitted.
There's a surprising amount of insecure code in the wild; and naive engineers who are willingly ignorant in their security practices. I'd assume that Parler's engineers motivations had more to do with politics than providing a secure platform for protecting dissidents under duress. (Or, if we look at the history of a recent major war, the mediocre engineers working for the other side thought they were the good guys.)
If you’re referring to world war 2, axis engineers were in no way “mediocre”.
"Allied intelligence noticed each captured tank had a unique serial number. With careful observation, the Allies were able to determine the serial numbers had a pattern denoting the order of tank production. Using this data, the Allies created a mathematical model to determine the rate of German tank production. They used it to estimate that the Germans produced 255 tanks per month between the summer of 1940 and the fall of 1942."
One source of many: https://www.wired.com/2010/10/how-the-allies-used-math-again...
This information was used to estimate force size and thus counter it, and it turns out this method was surprisingly accurate.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#293Wiki says Parler is a team of 30 people, So realistically, does that mean like 10 devs running a social network with 5-10 million users? I imagine its pretty ceazy there right now after getting booted off AWS, google just banned u off play store, so cant use them, i assume they cant use microsoft because theyll ban them there as well, it would be cool to see if they are able to get things up and running again. (Ive n…
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#294Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#295Earlier quoted context omitted.
I'm not gonna lie: I find it very difficult to be upset by this when the site was a haven for people who want to mass executions for people like me. For me, the world is a little more complex than "privacy at all costs." It's hard to decide where to draw the line.
My impressions is that everyone whinging about privacy with regards to giving seditionists and terrorists a space to coordinate and share misinformation after the biggest attack on the US since 9/11 are just being contrarian or are absolutist to a fault in their libertarian ideals (which I mostly share). People minimizing this attack and not treating it like a legitimate 9/11 scale crisis for the US are not consideri…
This is an absolutely disgusting and disgraceful thing to say.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#296Earlier quoted context omitted.
I generally agree that information from here related to the attack is in the public interest. But this is going to also reveal people who had no part of it. I don't think it's fair to justify revealing innocent peoples data.
The rules are different when the democracy is at stake, as this country's history should have taught you.
A good half the problems in the world are created when we try to force oversized round pegs through undersized square holes. Besides which, was Parler not the site that required excessive amounts of personal info just to sign up?
That means if authentication failed open, that could mean that this researcher has obtained access to reams of PII. Which they'll deny or state that of courae they didn't collect or look at, but the potential breach is large enough that doing something like this is so unconscionably reckless and stupid, it ranks right up there with the event that even has this site in the public eye in the first place.
Another brick through the stained glass windows of American civil discourse. We don't even need other country's help to push us to the brink because of reckless moves like this.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#297This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…
To give a bit of context, this is the "Keyboard Cowboy Hack The Planet" Parler lead engineer: https://pbs.twimg.com/media/ErcFo5tXAAAa0KP?format=jpg&name=...
I'm not following, what does this provide in support of the discussion? What context does this provide other than a picture and username? If the notion is of this person being lower or lesser because they worked for parler, then you aren't seeing the forest through the trees.
Plenty of engineers make mistakes, many are just as ego centric. Go to Defcon, talk to all the expert "hackers" I guarantee 95% of the people there make common mistakes, we all do.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#298Earlier quoted context omitted.
There's a surprising amount of insecure code in the wild; and naive engineers who are willingly ignorant in their security practices. I'd assume that Parler's engineers motivations had more to do with politics than providing a secure platform for protecting dissidents under duress. (Or, if we look at the history of a recent major war, the mediocre engineers working for the other side thought they were the good guys.)
>and naive engineers who are willingly ignorant in their security practices. Fairly sure we could replace algorithm and data structure whiteboard interviews with security interviews and we'd all be better off
But a far more expedient process is to just give candidates an essay exam to see if they are functionally literate in their profession.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#299Earlier quoted context omitted.
So logically then, Twitter and all its users should be cancelled for freely allowing Antifa to organize there.
Ah yes, Antifa, known for throwing milkshakes, is equivalent to pipe bombs, trucks filled with guns and explosives, and people walking around with zip ties looking for pols to kidnap inside a government building they killed a cop to break into. Right. I forgot.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#300Earlier quoted context omitted.
Talk about hyperbole. In no way did even 1% of the population on Parler want mass executions for people like you.
According to Wikipedia, there are 4,000,000 active Parler users. You think you can assert with confidence that there are not 40,000 people with Parler accounts who want mass executions? I'd like to think you're right, but I'm not as confident as you are. Not after watching someone beat a Capitol Police officer to death with a flag pole flying the American Flag. People think they are defending their country against ev…