21 ms·
Parler Databases Disclosed
- kodah 6y agoThe description of the hack is not accurate. Okta is the service that disclosed the endpoints used.
- codefined 6y agoOkta is a large, enterprise identity provider. I doubt in the case of a right-wing site existing they'd give out access to that provider on purpose? Did they mess up? I can't find any details about it yet.
- kodah 6y agoI won't speculate on their intent, but by publicly commenting on disabling the account it looks like it opened the door for the hackers, again, if any of this is true. It's entirely possible that Parler stored all of their data in S3, with metadata documents, and someone managed to find some creds in the app to list the object storage. These practices and this kind of vulnerability are both common.
- nikolay 6y agoIt just a scare tactic to discourage the use of Parler. It's so poorly written that it sounds like a kid.
- Cthulhu_ 6y agoNot that they need much to discourage Parler, lol.
- nikolay 6y agoI mean, to scare off the existing users of Parler, but, I guess, shutting the whole thing down by the Big Tech Cartel was more efficient. I just don't get how people get away with abusing an undocumented API to fetch and publish PII - something that's illegal. Remember how people did the same with with T-Mobile and got into a huge trouble? Until we keep having these double standards, there always will be polarization and tensions! And how is this mess good for America and the world?!
- osgovernment 6y agoIf you're not signed up as a foster/adoptive parent, now is a good time if you want to have an impact. There are going to be a lot of kids flooding into the system from families that felt emboldened to become domestic terrorists by the President and those he surrounds himself with.
- aidenn0 6y agoProbably a bigger effect is all the people who lost their jobs to covid. Domestic abuse always follows a large spike in unemployment
- osgovernment 6y agoCertainly not disregarding that either, however it is also likely compounded by people that think COVID-19 is a ploy by liberals to fraudulently steal an election.
- Benjmhart 6y agoCope harder loser.
- dang 6y agoObviously you can't post like this or https://news.ycombinator.com/item?id=25710342 https://news.ycombinator.com/item?id=25710342 to HN, regardless of how wrong someone is or you feel they are. We ban accounts that do this. I'm not going to ban you right now, because although you've broken the site guidelines in the past, it looks like you've mostly posted good comments. But if you don't start following them, we'll have to ban you next time. If you wouldn't mind reviewing https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html and taking the spirit of this site to heart, we'd be grateful.
- jedimastert 6y agoUnfortunately there was also a massive dip in reports because of schools not being in session.
- neya 6y ago"Twilio put out at midnight last night. In that Press Release, Twilio accidentally revealed which services Parler was using. Turns out it was all of the security authentications that were used to register a user. This allowed anyone to create a user, and not have to verify an email address, and immediately have a logged-on account. Well, because of that access, it gave them access to the behind the login box API that is used to deliver content -- ALL CONTENT (parleys, video, images, user profiles, user information, etc) --. But what it also did was revealed which USERS had "Administration" rights, "Moderation" rights. Well, then what happened, those user accounts that had Administration rights to the entire platform... The hackers, internet warriors, call it what you will, was able to use the forgot password link to change the password. Why? Because Twilio was no longer authenticating emails. This meant, they'd get directly to the reset password screen of that Administration user." I'm not from the US, but as an outsider, this leaves a really bad taste with how Twilio handled the situation AS A BUSINESS.
- Udik 6y ago> Because Twilio was no longer authenticating emails. Can someone explain what does this mean?
- dgellow 6y agoTrying to make sense of it, I believe that means Parler was delegating their email verification and 2fa checks to Twillio. And somehow, without access to Twillio's API, they defaulted to not do any check at all? I'm not sure what to do of this, that doesn't sound that realistic but who knows.
- beerandt 6y agoThat, or Twillio was reporting authenticated emails, without actually authenticating them? It seems to involve some skipped auth steps on someones part though, not just a fail-safe/fail-dead mixup. It's not clear.
- myaccount275 6y ago
- icare_1er 6y agoI find it hard to believe this timing is a coincidence...
- mewse 6y agoNobody is claiming that it's a coincidence. They're claiming that the "we're not providing services to Parler any more" public statements of Twilio unintentionally provided the information necessary to perform the hacks.
- fabian2k 6y agoHow would disabling Twilio disable authentication entirely? From what I see it is used to send SMS and maybe Email as well. So I could understand that it would prevent login, registration and password reset if that service is offline, but it shouldn't allow any of these without authentication. Unless the software skipped authentication entirely when this service was unavailable, which I find hard to imagine. But that seems to be what is claimed right now.
- brobdingnagians 6y agoIt appears Okta also banned them, they must have default succeeded instead of default fail, maybe an interaction between the two?: https://twitter.com/okta/status/1348191370528256002?s=20 https://twitter.com/okta/status/1348191370528256002?s=20
- fabian2k 6y agoThat would be extremely careless, and I find it very hard to believe that this happened. An unlikely, but more plausible option to me would be that after removal of the Parler account, someone else was able to register the same account and gain access that way. But that doesn't fit the description all that well, and I'd also expect that this would not work at all if the authentication service is not very careless.
- Mindwipe 6y agoParler's infrastructure was extremely carelessly built in lots of ways, so it doesn't shock me.
- audunw 6y agoMaybe another explanation is that they quickly hacked around the lack of these services just to get things working again? I can imagine them quickly making a bunch of ill-advised code changes just to get their platform working.
- benmmurphy 6y agoThey make a request to twilio and their logic checks for a failure response instead of looking for a success response. They are not getting back a different failure response and this causes the requests to be incorrectly be marked as success. For example here is how something like that might break: /auth -> returns {"success": true} and 200 on success -> normally returns {"success": false, "error": "BLAHLBAH"} and 200 on failure developer checks if response["error"] is null to check if it was successful or not after your account is disabled /auth starts returning empty json: {} with a 500 error code oops. now all the requests are incorrectly marked as success. i know this happens because i've seen similar things happen in real life. the error could also be more obvious and the code just fails open. someone has a try/catch and returns true either because of an accidental mistake or because they don't want users to be locked out when the provider is down.
- scotty79 6y agoWait. So how did it work exactly? Why would you get to reset password after clicking "I forgot password?" I thought password reset flow is initiated from the email link not from "Forgot password" link and just paused till email link is clicked.
- scotty79 6y agoApparently nothing like that actually happened https://www.wired.com/story/parler-hack-data-public-posts-images-video/ https://www.wired.com/story/parler-hack-data-public-posts-im... Al they got was just published data that they easily scraped.
- atemerev 6y agoOh come on, it was a honeypot from the beginning. Everybody in the last few days was talking about Parler -- they got more exposure than ever in their life. The takedown from AWS was announced a few days before, so more users could register. Parler was running a "Verified Parler citizen" (wat?) campaign, to gather more personal data. And now, hackers conveniently exposed everything. Hackers are unpredictable, you know. I am not defending the Parler audience; the honeypot was elegant, but is it ethical?
- l33tbro 6y agoI signed up to explore the site yesterday. Was curious from hearing in the news and it required an account to view. There was no verification process whatsoever. I popped in a fake email and then got immediate access. So not sure what this "Verified Parler citizen" thing refers to ...
- frollo 6y agoTo get verified you had to post a scan of your driving license or another document, which was then stored in Parler's database. After all that happened (and even before 6/1 it was clear that Parler was being closely watched by a lot of three letter agencies), it was clearly a honeypot.
- bmarquez 6y ago"Verified Parler Citizen" is basically a red badge to prove that you weren't a bot account. I think there were other benefits but I can't recall off the top of my head. As a privacy-conscious person, the thought of uploading the front and back of a driver's license + selfie, or passport just to get an "I'm not a bot" badge is ridiculous.
- srwx 6y agoPrior to Okta and Twilio revoking their accounts you needed to provide SMS authorization to create an account (you give them a number, they send you a code, etc.). It seems likely after their API access to Okta/Twilio was revoked their services weren't written to catch and handle the new exception these API calls were probably raising... Based on this twitter thread from Nov 2020 they may not have been hiring the best developers: https://twitter.com/davetroy/status/1327253991936454663 https://twitter.com/davetroy/status/1327253991936454663
- yurgen228 6y agoI find it all hard to believe
- willejs 6y agoThis post seems fake. There was a group of people archiving the public content of parler using this docker container https://github.com/ArchiveTeam/parler-grab https://github.com/ArchiveTeam/parler-grab and archiving it here https://tracker.archiveteam.org/parler/ https://tracker.archiveteam.org/parler/. I can't validate anything else in this twitter post. The administrator accounts part all seems fake, unless anyone has found the rest of the content or has a better source? Previous discussion deeming its fake here https://news.ycombinator.com/item?id=25725268 https://news.ycombinator.com/item?id=25725268
- creato 6y agoThe reddit post describing the hack mentioned creating "MILLIONS" of fake admin accounts: https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_parler_user_data_is_being_downloaded_as_we/ https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_par...
- willejs 6y agoThis directly references the public archive team effort, not evidence of a the hack. The comment and “story” that is circulating seems like it’s just taking the public archive team effort and adding some sort of falsehoods around a hack where they were also pulling data via admin functionality. I can’t find any other information about the admin hack apart from this potentially false story.
- de6u99er 6y agoCheck out my comment, below the top-comment in this post.
- willejs 6y agoYour post just links to the list of public Parler posts that were scraped from the website. Not evidence of a hack.
- albroland 6y agoThis was my take on reading the wild "2nd hand story" in that reddit post. Almost none of it makes any sense; instead it seems like people just crawled parler's public API and saved the responses into a big archive ("the leak"). The only "exploit" I see could be that parler uses incrementing IDs for posts/content allowing easy enumeration crawling.
- traveler01 6y agoI don't know why but what's happening to Parler doesn't feel right at all...
- Cthulhu_ 6y agoWhile it does feel reactionary (if that's the right word) that the services are only now revoking doing business with Parler, they are within their rights to stop the contract one-sidedly. I'm actually fairly sure that in the contract they don't even have to state a reason, but don't quote me on that. Something something free market.
- saargrin 6y agothat would be cool if they also implemented the same policy towards other violent/inciteful players and terror organizations
- Renaud 6y agoThey should, and many do. Once you start peddling in calls to violence against people, no just ideas, then you should lose access to your platform and well deserve to be investigated. Being complacent with these things gets people killed. You can have free speech all you want but are also responsible for what you say. Free speech doesn't mean you get a free pass without consequences.
- saargrin 6y agoexcept their efforts are largely focused and selective switch to arabic language and you will see things that could be easily identified as violent propaganda,yet they stay up because FB censorship system is not interested in enforcing rules in that sector from what i hear its pretty much the same for India
- deleted 6y ago[deleted]
- traveler01 6y ago
- Yetanfou 6y agoIf there is one lesson to be learned from these last few weeks it is that you can not rely on any external service if you do anything which goes against the dominant political narrative. I have never been on Parler's site so I can not check the veracity of their supposed implied or direct support for seditious acts but that does not seem to matter anyway, it is enough to stand accused to be considered a witch and burned at the stake. Build your own is the device, keep your equipment on your own premises, make sure not to have single points of failure - that implies you need to have a backup access provider just in case your internet connection gets cancelled. Don't rely on electronic payment processors, you can use them but make sure to have a backup. Don't rely on a single bank, have multiple accounts, preferably in more than one country. It is a sad thing that it has to come to this but I think we'll eventually end up with politicised service institutions which cater to "progressives", others which cater to "conservatives". They won't state this directly but it will be known that a conservative builder is better of at this bank and that insurance company, he'll prefer to buy this coffee and that brand of razor, etc. A shame, really, the more divided society becomes, the harder it will be to find a common cause when such is needed, e.g. in case of a national emergency like an epidemic.
- cycrutchfield 6y agoIt has nothing to do with "the dominant political narrative", and it has everything to do with violent rhetoric on their platform that they refuse to moderate. This violent rhetoric is against the Terms of Service for the external services that they rely on, hence the termination of those relationships.
- Cthulhu_ 6y agoThere's going against the dominant political narrative, and there's organizing and committing federal crimes like breaking and entering into congress. You have freedom of speech and the government cannot arrest you from saying things on the internet. However, organizing a raid on the government will get you in trouble, and never forget that nobody is obligated to give you a platform.
- yurielt 6y ago
- mikewarot 6y agoAWS gives 5Gbps connectivity to instances, according to https://docs.aws.amazon.com/whitepapers/latest/ec2-networking-for-telecom/overall-instance-bandwidth-limitations.html https://docs.aws.amazon.com/whitepapers/latest/ec2-networkin... So, if the sum total of Parler was 70 Terabytes, as claimed... the transfer time would be 38 hours, if it was hosted on one instance... but it obviously wasn't. It was more likely only a matter of minutes. This shows a new type of cloud hosting vulnerability. Your entire corporations infrastructure could be mirrored faster than you could notice.
- cycrutchfield 6y agoI think all the content was hosted on S3
- kodah 6y agoAn interesting bit is how easily broken the website was without key components. There's a worthwhile case study here (if any of this is true) that I would suspect concludes in divesting from SaaS and IaaS.
- cbozeman 6y ago> This shows a new type of cloud hosting vulnerability. Your entire corporations infrastructure could be mirrored faster than you could notice. This is actually fucking terrifying.
- WJW 6y agoAdditional interesting scenarios: - Nation states that manage to infiltrate a few spies into Amazon or Google could "just" copy the backups of the database without anyone being the wiser. - My favourite mission ever from the "Shadowrun" games: Step 1 was a mission to alter the backups of some main database (stored at some 3rd party) to include additional admin credentials. Step 2 was to "clumsily" attack the main target and not-quite-hack the main system so that they would restore from backup just to be sure, thereby importing the actual backdoor.
- 6y ago
- cycrutchfield 6y agoThe explanation is a jumbled mess, but I think there are two key parts here: 1. Somebody reverse engineered the iOS app, which allowed them to access Parler's API and enumerate all of the content on the app 2. The Twilio shutdown affected SMS verification for new account registration, meaning people were now able to programmatically create many new user accounts which they could combine with #1 to scrape all the data without being rate limited
- Tostino 6y agoI don't believe they were actually rate limiting per account regardless. The "hacker" Set later in the day on Twitter that there was a misunderstanding that the account creation script was related at all to the data scraping. Just that it was actually possible, but unnecessary because they didn't rate limit per account.
- notadev 6y agoI wonder if Twitter will be nuking any info from their site, with their policy against posting hacked information and whatnot.
- wobblyasp 6y agoSeems to be another faked "hack" of Parler. Does Twilio even have a user management component? Why is the explanation of the hack a jumbled mess? I'll believe it when after private convos are leaked.
- notmenope 6y ago> "The things that they are saying on here are vile and disgusting and should be removed from the internet" > "Let's archive everything that was ever posted on there are share it with the public"
- aaron695 6y agoThis comment seems to explain what really happened best - https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_parler_user_data_is_being_downloaded_as_we/giuz38a/ https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_par... One 'hack' enumerating content One 'hack' mass producing accounts to spam with
- hehehaha 6y agoIf I am understanding this correctly, Parler devs left the app as MVP. They never rebuilt it with security and privacy in mind.
- zenexer 6y agoCan we get some better sources? This seems like an awful lot of hearsay, and there have been several comments from HN readers in this thread[0] and another[1] indicating that there is no public evidence to support these claims. Given that the author is alleging this is a crowdsourced effort, such evidence should be trivial to locate, but none has surfaced. [0]: https://news.ycombinator.com/item?id=25727332 https://news.ycombinator.com/item?id=25727332 [1]: https://news.ycombinator.com/item?id=25725268 https://news.ycombinator.com/item?id=25725268
- Tostino 6y agoFor those coming to the comments later, it was bullshit. No one from that group was claiming admin accounts were able to be created. Just that you could easily create regular accounts with a script because email verification wasn't required anymore. That original reddit explanation was mostly bullshit. That so called technical person that knew much more than the poster apparently was misinformed.
- davidg109 6y agoVery shoddy development. It sounds that if there was ever a Twilio outage, the same vulnerability could have played out. Not hard to know how Twilio is used either, especially as employees come and go. This was a disaster waiting to happen either way.
- 90red 6y agoMore terror ops against conservatives.
- ht85 6y agoYour security is only as good as your unpopularity. Karma.
- woliveirajr 6y agoIn the midst of all this, one thing always bite any site when some break-up happens: >Also, a lot of posts were deleted by Parler members after the riots on the 6th. Turned out... Parler didn't actually delete anything.. just set a bit as deleted. The perils of soft/logical delete instead of hard/real deletion.
- cosmiccatnap 6y agoxkcd.com/1357/
- trst 6y agohttps://imgur.com/a/EPYU4kn https://imgur.com/a/EPYU4kn I warned about this
- trst 6y agohttps://imgur.com/a/EPYU4kn https://imgur.com/a/EPYU4kn I warned you guys about this yesterday
- irscott 6y agoMy question is- Looking at this dump, it appears to just be URLS. If the site doesn't exist anymore than the URLs point to nothing. What's actually exposed? What am I missing here?
- rubinlinux 6y agoThis twitter thread puts this in a bit different light, I think. https://twitter.com/davetroy/status/1327253991936454663?lang=en https://twitter.com/davetroy/status/1327253991936454663?lang...