Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

31–40 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#32
post #27

Earlier quoted context omitted.

As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.

Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.

"The truth is, these are not very bright guys, and things got out of hand." - Deep Throat, during Watergate

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#35
post #27

Earlier quoted context omitted.

As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.

Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.

Because you want your users to be able to access the service if Twilio is having downtime rather than your service being essentially down for them. Twilio killing their account was probably not an assumed use case. The biggest expected impact was new user SMS authentication which you could run after the downtime is over. Better some spam users than losing those potential users was their thought I'm guessing. I suspect password reset also failing open wasn't thought of as deeply because it's a rarer path but it got bundled together with the SMS auth code path.

edit: I'm sure we've all had really stupid requirements pushed on us by the business side for the sake of user experience or increasing metrics. Or written bad code at 3am during crunch time.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#36

This sounds like an incredible fuckup by Twilio. If it's true that their authentication verification was the entrypoint, they could be liable for leaking an enormous amount of personal information.

This loooks serious. I might have to start looking into Twilio alternatives form my company. Does anyone have any suggestions?

I'm highly doubting Twilio is the culprit here. Sounds like Parler was just treating failures as valid authentication. Keep in mind that at the time the hackers gained access, Twilio had already suspended Parler's account, so there is little to no possibility of this being on Twilio's shoulders.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#38
post #34

Could these "Researchers" be prosecuted under CFAA? Purposely accessing information known to be private? EDIT: accidently wrote DMCA

Yes, of course. This is an illegal hack.

Edit: I should add, it would be under the CFAA.

Edit #2: I could be wrong, it looks like they used Parler's APIs, and didn't bypass any auth. I really shouldn't have even called this a hack, it's more just archiving. But weev went to jail for the same thing, so I'd say there's a chance of prosecution, would come down to a court case. If I was the person who did this, I would never step foot in America, just to be safe.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#40

Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.

Just call everyone a terrorist and absolve your soul of any uneasiness you have with this. Surely this hyperbole hasn't been used in recent history to push authoritarian and unethical measures by state and private actors paving a golden road to hell.
Post reply on HN