Earlier quoted context omitted.
As I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.
Seems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.
70TB of Parler users’ messages, videos, and posts leaked by security researchers
61–70 of 1001 posts
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#62This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…
Pretty clear where their priorities lay, huh. Breaking the security of their users is less important than getting new users.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#63Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#64When you purposefully leak private data, you no longer get to hide behind the title "Security Researcher".
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#65Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#66Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#67Could these "Researchers" be prosecuted under CFAA? Purposely accessing information known to be private? EDIT: accidently wrote DMCA
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#68This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…
I'd assume that Parler's engineers motivations had more to do with politics than providing a secure platform for protecting dissidents under duress.
(Or, if we look at the history of a recent major war, the mediocre engineers working for the other side thought they were the good guys.)
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#69Where are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.
People are forgetting that if they're ok with this sort of behavior now, it'll be difficult for them to argue-against or prevent the same behavior when their opposites are in control.
Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers
#70Sounds like Twillo was actively helping hackers "That allowed them to see which users had moderator rights and this in turn allowed them to reset passwords of existing users with simple “forgot password” function. Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease."
Maybe Parler should have done their due diligence and planned for if their email verification service stopped working. The logic doesn't even make sense. Twilio goes down for them and then they just allow anyone access to user accounts.