Live data from Hacker News

70TB of Parler users’ messages, videos, and posts leaked by security researchers

cybernews.com

991–1000 of 1001 posts

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#991
post #371

Earlier quoted context omitted.

Replace fizz buzz with spotting SQL injection issues.

There is plenty of use for coders who can't spot SQL injection issues. I can't think of much use for a coder who can't do fizzbuzz.

How?

Sql injection is so basic, that if you can't spot it, you probably can't do fizzbuzz.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#992

Earlier quoted context omitted.

/r/libertarian was famously unmoderated for years until the drama a couple of years when the head moderator finally resurfaced and decided to step in after alt-right mods took over the sub: https://www.reddit.com/r/SubredditDrama/comments/ajg8ng/rlib... Slashdot is the only major site that was unmoderated in this sense - during the 10+ years I read it the only post ever removed was one with links to Scientology mater…

Slashdot's moderation system is quite unique. It's fairly hard to get mod points and they expire quickly, so brigading is almost impossible. Posts have a very low mod cap (5) as well so it stays fairly flat. There is also a meta-moderation system although it's never been clear to me how effective it is. Probably the biggest thing keeping it in check is that they still a fully editor driven website. No article shows u…

The +5 to -1 range was a great idea as it made it harder to suppress a controversial opinion by burying it in downvotes. It still stands out as one of the best systems I've seen although I'm not sure it would work on something like Reddit. It would probably work well here though.

I was active on kuro5hin around the same time and that had a story queue where anyone could submit stories and other users could approve, disapprove and suggest changes; when a story hit a positive or negative threshold of approves - disapproves it was posted or deleted, and if didn't hit either within a week it was also removed. Again the thresholds were higher to get a story posted and to get it rejected, and only users with enough positive karma could see the queue at all. That worked pretty well.

In the early 2000s I was active on the "hidden" sids such as trolltalk where people would troll Slashdot and share it with others. At one point one poster ran a dictionary attack on the first 10k accounts using some very simple password guesses and captured several hundred or so - and then built a system that had them log into Slashdot regularly in such a way that they were most likely to receive moderation points, which were given to users who browsed regularly but not frequently. He then wrote an interface that wrapped Slashdot and allowed anyone using it to be able to moderate any comment there as if you had mod points, but actually by using moderation points from one of the pool of accounts.

If you ever saw posts with (Score 30: Troll) on them, that would be why...

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#993

Earlier quoted context omitted.

Slashdot's moderation system is quite unique. It's fairly hard to get mod points and they expire quickly, so brigading is almost impossible. Posts have a very low mod cap (5) as well so it stays fairly flat. There is also a meta-moderation system although it's never been clear to me how effective it is. Probably the biggest thing keeping it in check is that they still a fully editor driven website. No article shows u…

The best thing that I love about the Slashdot moderation system is that you can't moderate and post in the same discussion. It keeps people from simultaneously expressing their opinion and downvoting other opposing opinions.

It also only awarded mod points to people who browsed the site on a regular basis but not all the time - so logging in every day or two for an hour would give you them fairly often, but if you spent all day on there you never had mod points. I don't think I got them until I started to use the site less and less which was years after signing up in 2000.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#994

Wiki says Parler is a team of 30 people, So realistically, does that mean like 10 devs running a social network with 5-10 million users? I imagine its pretty ceazy there right now after getting booted off AWS, google just banned u off play store, so cant use them, i assume they cant use microsoft because theyll ban them there as well, it would be cool to see if they are able to get things up and running again. (Ive n…

What I don't understand is: if you're going to host something like Parler, knowing that it is extremely controversial, why wouldn't you host it yourselves? The money they would have saved over using AWS (at the scale quoted in the previous comments) could have paid for the servers and the people to manage them. I suppose the deplatformers would have just gone after whatever data center they used, though, or if they'd…

yea it sounds like a reasonable IT person at Parler would suggest preparing for getting booted off these big tools (aws, twilio, etc.) considering Parler sounds like exactly the type of product that would get kicked off these services.

One of the founders of pirate bay had a tweetstorm recently where he was like, i get that aws kicked u guys off, but like, u guys cant get a homepage up and running? I agree with this guy.

parlor was founded with politics in mind, maybe they are ok with shutting down their community because in a way that serves their political goals, sounds like parlor and aws are already suing eachother, i dont doubt uber-conservative users will find an alternative platform to use in the coming weeks.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#995

Earlier quoted context omitted.

> Speech is not gasoline It's a metaphor. Let me extend it a bit: Speech is the drought of repeated lies about the illegitimacy of an unwelcome outcome drying out the underbrush of widespread discontent. Speech gathers the tinder of a crowd committed to "stop the steal". Speech is the accelerant convincing those so predisposed that violence or the threat of violence is acceptable and even to be admired. And speech is…

> It's a metaphor. Clearly, here's a better beginning: “Let me extend the metaphor a bit". > Speech is the drought of repeated lies about the illegitimacy of an unwelcome outcome drying out the underbrush of widespread discontent. Did you mean hate speech? A drought is usually a negative. Sorry, I just can't make sense of that. > And speech is the match tossed offhandedly aiming the mob you primed and egged on at the…

> No good reason other than the centralisation of power.

Hiding some implementation details from bad actors isn't necessarily a bad idea, though of course you have to figure out whether you're doing the security equivalent of hiding a proprietary algorithm (bad idea) or hiding your secret key (good idea).

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#996

Earlier quoted context omitted.

I still get to see what's in my spam folder.

And you can still go to dark corners of the internet and view all sorts of hate speech.

You're stepping well outside the bounds of your analogy. Incoming email is like a social media feed, hence the comparison. It fails when you compare things like shadowbanning with spam, as I pointed out.

Going out onto the "dark corners" of the internet though, that would be equivalent, perhaps, to signing up for an equivalent email provider without a spam filter?

Nope, that doesn't work. Hard to tell what you could mean other than "my initial analogy didn't work so I'm going to move the goalposts".

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#997

Earlier quoted context omitted.

There is plenty of use for coders who can't spot SQL injection issues. I can't think of much use for a coder who can't do fizzbuzz.

How? Sql injection is so basic, that if you can't spot it, you probably can't do fizzbuzz.

It more likely means that you just aren't familiar with SQL.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#998

Earlier quoted context omitted.

You can report, but it takes weeks sometimes for the content to get actioned.

Sometimes it takes more than 8 years for Twitter to kick someone off who Tweets racist conspiracy theories about Obama actually being born in Africa.

What is racist about claiming that Obama was born in Africa?

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#999

Earlier quoted context omitted.

> https://pbs.twimg.com/media/ErcFo5tXAAAa0KP?format=jpg&name= ... I'm not following, what does this provide in support of the discussion? What context does this provide other than a picture and username? If the notion is of this person being lower or lesser because they worked for parler, then you aren't seeing the forest through the trees. Plenty of engineers make mistakes, many are just as ego centric. Go to Defco…

> If the notion is of this person being lower or lesser because they worked for parler No. I support free speech. But I for one wouldn't trust someone with my security who approaches his jobs like a "cowboy hacker". Infosec is hard and needs to be taken seriously. Only the paranoid survive.

I agree in not using the language as this gentlemen did, but sadly more and more people use it. I also abhor "infosec rockstar" and "Rockstar Developer" etc.

Re: 70TB of Parler users’ messages, videos, and posts leaked by security researchers

#1000
post #197
post #8

This story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or t…

More speculation on my part: I wonder if rather than a fail-open decision, it’s just how they designed local dev to work and the failure of the provider caused the app to behave as if in local dev mode.

That's a really good theory.
Post reply on HN