Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

51–60 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#51

Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.

Don't worry, the "hacked material" rule on twitter will prevent anything derived from this being posted on twitter.

Right???

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#52

Earlier quoted context omitted.

Yes, of course. This is an illegal hack. Edit: I should add, it would be under the CFAA. Edit #2: I could be wrong, it looks like they used Parler's APIs, and didn't bypass any auth. I really shouldn't have even called this a hack, it's more just archiving. But weev went to jail for the same thing, so I'd say there's a chance of prosecution, would come down to a court case. If I was the person who did this, I would n…

Is it? The article indicates at least some of this comes from merely incrementing an integer in the video URLs. > I am now crawling URLs of all videos uploaded to Parler. Sequentially from latest to oldest. VIDXXX.txt files coming up, 50k chunks, there will be 1.1M URLs total...

Weev when to jail for the exact same thing under the CFAA.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#53
post #8

This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…

Agreed that the problem looks like 'fail open', but there is the additional possibility that they had no plan for this failure mode at all beyond timing out.

In that context, and with folks with no regard for consequences in charge, an emergency decision to allow everything seems plausible.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#54
post #27

Earlier quoted context omitted.

As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.

Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.

This assumes it was by design, likely someone unfamiliar with the security implications thought they were improving the customer experience by not failing hard.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#55

Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.

"the media". You're not being honest, you either havent used the platform or are deliberately lying here. Either way a platform that freeley allows the organization of violent mobs has no place, and neither does anybody who supports it.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#57
While I understand that Twilio is probably not at fault for the actual leak, I'm curious if they gave Parler some time to migrate/shift before cutting them off from their services.

It's easy not to care since Parler is the "bad guy" here, but I do think that Internet infrastructure companies need to give a reasonable heads-up before pulling the rug under business customers.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#59

Earlier quoted context omitted.

Yes, of course. This is an illegal hack. Edit: I should add, it would be under the CFAA. Edit #2: I could be wrong, it looks like they used Parler's APIs, and didn't bypass any auth. I really shouldn't have even called this a hack, it's more just archiving. But weev went to jail for the same thing, so I'd say there's a chance of prosecution, would come down to a court case. If I was the person who did this, I would n…

Is it? The article indicates at least some of this comes from merely incrementing an integer in the video URLs. > I am now crawling URLs of all videos uploaded to Parler. Sequentially from latest to oldest. VIDXXX.txt files coming up, 50k chunks, there will be 1.1M URLs total...

[deleted]

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#60
I just can’t help but laugh that this service existed and to become a verified user (or whatever they called it) you had to upload a front and back scan of your driver’s license?? And then this happens and people who stormed the capitol are whining about being labeled terrorists and unable to fly home. 2021 has sucked but the fallout almost makes up for it in this case.
Post reply on HN