Live data from Hacker News

Parler’s amateur coding could come back to haunt Capitol Hill rioters

arstechnica.com

51–52 of 52 posts

Re: Parler’s amateur coding could come back to haunt Capitol Hill rioters

#51

Earlier quoted context omitted.

> From what I understand, Parler was bankrolled and designed to do exactly what it was ultimately shutdown for. That is, be a concentrated anger-machine-echo-chamber. How is/was Parler different from Facebook in this regard? Facebook makes money on ads, so the longer you stay on their site, the more money they make. One way to get people to stay longer is by encouraging the sorts of posts that gets people riled up. I…

Yes, the mechanism is the same. However, Facebook has lines that when crossed result in being moderated. Their moderation system is obviously imperfect and a lot of the time they act too late, but it's there. Parler was courting all the line-crossers with the promise that there would be no such moderation on their platform. That ended with predictable results.

There was more moderation going on, on Parler, than anywhere else. Users would start out shadow-banned until the moderators approved of their groupthink.

It wasn't just calculated to bring out the worst: it was actively fostering it.

Re: Parler’s amateur coding could come back to haunt Capitol Hill rioters

#52
post #44
post #43

Earlier quoted context omitted.

If you’re not requiring any level of authorisation to enable someone to read a post (ie, this post has been removed, you can’t see it any more or this is a private post, you must be a friend of its author to see it), then you’re just relying on people not being about to guess it’s ID and grab it from the API. It’s a poor version of security through obscurity. Could have easily been rectified by using UUIDs instead of…

They used sequential integer, which means it wasn't even security through obscurity. There wasn't any form of security. Not even a post it with "please don't hack me". With a browser and enough time at hand even my grandfather could have dumped their whole DB.

If by "dumped their whole DB" you mean "a snapshot of their public pages", then yes. Otherwise, no. This was an ArchiveTeam-affiliated scraping operation that relied on slurping down as much public-facing data as quickly as possible, just like their other efforts.

> When news of donk_enby's archival efforts broke, several viral tweets, Reddit posts, and Facebook posts claimed that she had captured private information, scans of drivers licenses and IDs, and other highly sensitive information. She said those posts are “not at all” accurate.¶ “Everything we grabbed was publicly available on the web, we just made a permanent public snapshot of it,” donk_enby told me.

https://www.vice.com/en/article/n7vqew/the-hacker-who-archiv...

Please stop making bombastic claims that will lead to people finding it easier to believe the kinds of unfounded rumors referenced above.

Post reply on HN