43 ms·
70TB of Parler users’ messages, videos, and posts leaked by security researchers
- shadowgovt 6y agoIt feels like this sort of fail-open should never have passed a security audit. ... but that's probably one of the lessons here: unless we demand accountability, we generally have no idea of what practices services we rely upon are using. How many systems we use daily do any kind of formal audits?
- sphuff 6y agoDiscussion of how it was done here: https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_parler_user_data_is_being_downloaded_as_we/giu04o6/?utm_source=share&utm_medium=ios_app&utm_name=iossmf&context=3 https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_par... Edit: this Reddit post appears to be inaccurate. More details here: https://news.ycombinator.com/item?id=25725268 https://news.ycombinator.com/item?id=25725268
- mxcrossb 6y agoThe linked post celebrates this saying they can share this data with law enforcement, but is it legal for them to pursue cases based on the evidence found in stolen data?
- moksly 6y agoYes.
- psychometry 6y agoWhy doesn't chain of custody apply to data?
- ceejayoz 6y agoIt does, but in a murder trial, the weapon was generally out of police custody for at least some time, right? There's an opportunity to introduce reasonable doubt when a third-party is in possession of the data in-between, but it's likely this sort of data isn't going to be the only evidence in any resulting prosecutions. It's far more likely to be probable cause for warrants.
- moksly 6y agoIt does, but it’s actually the fourth amendment that would be in place here, and numerous child pornography cases as well as the Panama papers have shown that US courts will allow illegally obtained data, as long as it was obtained by private citizens who were not working with law enforcement and that the data can be established as reasonably untampered.
- ceejayoz 6y agohttps://www.nolo.com/legal-encyclopedia/searches-private-citizens.html https://www.nolo.com/legal-encyclopedia/searches-private-cit... > But, in some ways, there’s really no such thing as an “illegal” search by a private citizen, at least in the sense that police searches can be illegal: Regardless of issues like lack of probable cause, evidence found by private citizens acting on their own is usually admissible in court. That’s true even if the private citizen committed a crime like trespass or theft to accomplish the search.
- mxcrossb 6y agoThank you very much for the detailed link
- Triv888 6y agoI don't know but they have "legal" work-arounds: https://en.wikipedia.org/wiki/Parallel_construction https://en.wikipedia.org/wiki/Parallel_construction
- whymauri 6y agoThis copypasta is incorrect. See more here: https://news.ycombinator.com/item?id=25725268 https://news.ycombinator.com/item?id=25725268
- sphuff 6y agoAh, thanks for the info. I’ll edit my post.
- redwine11 6y agoSounds like Twillo was actively helping hackers "That allowed them to see which users had moderator rights and this in turn allowed them to reset passwords of existing users with simple “forgot password” function. Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease."
- Jonnax 6y agoMaybe Parler should have done their due diligence and planned for if their email verification service stopped working. The logic doesn't even make sense. Twilio goes down for them and then they just allow anyone access to user accounts.
- gsich 6y agoOr maybe self-host.
- marcinzm 6y agoAs I'm reading it, Twilio simply shut down the account, Parler is the one who reacted to that by assuming everything is authenticated if the API doesn't work.
- cm2187 6y agoSeems implausible. Why would anyone design a system that way. I suspect it must be a more complicated combination of circumstances as it often is.
- ceejayoz 6y ago"The truth is, these are not very bright guys, and things got out of hand." - Deep Throat, during Watergate
- andrelaszlo 6y agoI could only find "All the President's Men" (1976) as the source for that quote. While googling that, it seems like he never said "Follow the money" either :) https://en.wikiquote.org/wiki/All_the_President%27s_Men_(film) https://en.wikiquote.org/wiki/All_the_President%27s_Men_(fil... https://en.wikiquote.org/wiki/W._Mark_Felt https://en.wikiquote.org/wiki/W._Mark_Felt
- bpodgursky 6y agoThis sounds like an incredible fuckup by Twilio. If it's true that their authentication verification was the entrypoint, they could be liable for leaking an enormous amount of personal information.
- fredley 6y agoIt's hard to tell. It could be that Parler's systems were set up to just fail the wrong way if the Twilio auth system didn't respond (on error: allow). Whatever the case, this is going to be 'fun' to watch.
- mabbo 6y agoNot necessarily. See my other comment on this thread, but they may have failed-open when the OTP authentication dependency was down- ie, hey, Twilio throws an exception sometimes so presume the user is approved so we don't impact the user experience due to Twilio being flakey.
- marcinzm 6y agoHow so? Twilio simply suspended service which they are allowed to do based on the ToS. It was Parler that reacted to it by allowing unrestricted authentication rather than simply failing authentication.
- ceejayoz 6y agoNo, it'd be a fuckup by whoever code it to go "if Twilio is unavailable, just let them in". It's highly unlikely Twilio's API responds with something like {"authenticated": true} when you haven't paid your bill or they suspend you.
- mStreamTeam 6y agoThis loooks serious. I might have to start looking into Twilio alternatives form my company. Does anyone have any suggestions?
- simlevesque 6y agoIf you read what happened you'd know that this could never happen if they built their system with the minimum care required. Twillio is absolutely not the culprit.
- mabbo 6y agoThis story truly terrifies me: my team owns my company's sign up page. (I speak for myself and not them, of course). Sounds like Parler, fearing that their OTP provider might go down, decided to fail-open, ie: if the dependency throws an exception, presume there's something wrong with the dependency and that the code provided is acceptable. It never occurred to them that the dependency could be down permanently, or that malicious actors[0] would be able to realize it and exploit to quickly. Lesson learned: do not fail open where security matters, where authentication matters. Failing closed prevents new users/customers from signing up, but it protects your existing users/customers. [0]From a security standpoint, these are malicious actors. I would also probably buy said malicious actors a beer if I met them, accompanied by a high five. Edit: this is a hypothesis of course. Maybe the bug was somewhere else in the system- it could be in Twilio's provided integration library where the fail-open occurred.
- user-the-name 6y agoPretty clear where their priorities lay, huh. Breaking the security of their users is less important than getting new users.
- simlevesque 6y agoExtreme growth hacking
- Cthulhu_ 6y agoYeah, just open the flood gates to bots. Twitter would be 100x as large now. Wasn't it something like 99% of e-mail was spam? The downsides of an open / decentralized platform.
- amanaplanacanal 6y agoMaybe we should stop idolizing free speech, and instead work towards inexpensive speech :)
- 6y ago
- cmdshiftf4 6y agoAll of this is surely going to end well.
- nip180 6y agoWhen I read that the FBI was asking for help in identifying people at the capital on January 6th I didn’t think someone would actually help.
- andromeduck 6y agoIf you think that's funny, someone made a post asking for people's names, locations and list of crimes so that they could be pardoned and people obliged. https://www.washingtontimes.com/news/2021/jan/10/social-media-offer-pardon-capitol-rioters-fake-doj/ https://www.washingtontimes.com/news/2021/jan/10/social-medi...
- nip180 6y agoThe low hanging fruit of social engineering.
- deleted 6y ago[deleted]
- king_magic 6y agoWell, if nothing else, glad to see there is a paper trail to track down the terrorists who plotted and took part in last week’s insurrection.
- stuckindider 6y agoWhere are the comments about how awful it is for people's private messages to be leaked? Or is this okay because the media told me these guys are the bad guys.
- TameAntelope 6y agoI'm willing to own my belief these people are bad guys, no need to protect me by saying the media told me so.
- cbozeman 6y agoIf you think every person on Parler is a bad person, you're mentally deranged, period.
- boredumb 6y agoJust call everyone a terrorist and absolve your soul of any uneasiness you have with this. Surely this hyperbole hasn't been used in recent history to push authoritarian and unethical measures by state and private actors paving a golden road to hell.
- deegles 6y agoUmm I'm not sure which group you're referring to!
- stronglikedan 6y agoAre they distinguishable by their terroristic activities alone?
- _red 6y agoIts also complete accident that there is now a 20000 page "Patriot Act 2.0" being pushed as a solution.
- boredumb 6y ago
- dominotw 6y agoDNC emails were leaked by russian "security researchers".
- 1MachineElf 6y agoJust because Russians broke in doesn't mean it was them. I still believe it was an inside job.
- dominotw 6y agoYes, it could've been internal security researchers.
- akhilcacharya 6y agoDNC emails weren't planning terrorist attacks.
- stevespang 6y agoSecurity Researchers is a BS coverup title for criminal hackers - - - FBI should prosecute.
- swalsh 6y agoCould these "Researchers" be prosecuted under CFAA? Purposely accessing information known to be private? EDIT: accidently wrote DMCA
- Miner49er 6y agoYes, of course. This is an illegal hack. Edit: I should add, it would be under the CFAA. Edit #2: I could be wrong, it looks like they used Parler's APIs, and didn't bypass any auth. I really shouldn't have even called this a hack, it's more just archiving. But weev went to jail for the same thing, so I'd say there's a chance of prosecution, would come down to a court case. If I was the person who did this, I would never step foot in America, just to be safe.
- ceejayoz 6y agoIs it? The article indicates at least some of this comes from merely incrementing an integer in the video URLs. > I am now crawling URLs of all videos uploaded to Parler. Sequentially from latest to oldest. VIDXXX.txt files coming up, 50k chunks, there will be 1.1M URLs total...
- dragontamer 6y agoI believe from a legal standpoint, all that matters is whether the user intended it to be private or not. It is a felony to open a mail envelope addressed to someone else. It doesn't matter that a butterknife can cut open the envelope, the intent is clear.
- andromeduck 6y agoThis is more a postcard than a letter.
- dragontamer 6y agoThe public posts are probably allowed to be accessed (like a postcard). The issue comes with the posts that were deleted: they arguably have an expectation of privacy. EDIT: And direct messages, if they work like Twitter, DEFINITELY have an expectation of privacy. If Parler has a DM-like system, they are probably illegal to access.
- WillPostForFood 6y ago“Security researchers”?!
- thomastjeffery 6y agoWhen you purposefully leak private data, you no longer get to hide behind the title "Security Researcher".
- RoyTyrell 6y agoWould it be any better if it was sent to Wikileaks and published there?
- coldtea 6y agoOnly if it the data was government / private sector data, not citizen messages
- newacct583 6y agoWhat exactly the difference between "private sector data" and "citizen messages"? Wikileaks published a ton of data from personal sources. Famously, the Podesta leak was from a private account and absolutely contained personal communication (about, again famously, a favored pizza joint).
- coldtea 6y ago>What exactly the difference between "private sector data" and "citizen messages"? That "fuck businesses", while "leave actual people ok".
- Agaliarept21 6y agoI think where most people would reasonably draw the line is in the level of political power a person has over matters which impact the public interest. While I personally disagree with the leaking of Podesta's emails, the amount of political power and relevance he has makes him somewhat of a public figure. He is not in anyway comparable to your average person. I do see a public good in providing this data to law enforcement, so that they can obtain evidence to build a case against the people who were involved. I however can not see any public good in potentially exposing random people to identity theft and criminal harassment for simply registering an account on a website. While people could make the argument that the site has culpability for what happened so this data must be exposed, to hold that position in good faith you would then also have to say that a leak of Twitter, Facebook, and Youtube users is also justifiable. Seeing as those platforms have held worse calls for violence than any other platforms. Parler isn't a website where all the users who register are guilty of espousing harmful rhetoric. I would agree that there are some websites that exist like Stormfront where that would definitely be the case, but ultimately Parler is simply an alternative social media site with more lax moderation than Twitter. That lax moderation unfortunately will attract a large number of bad actors who have been banned from other sites. However this still doesn't change that this site isn't anything but a social media site with a different philosophical opinion on how moderated speech on their platform should be. Which means a lot of innocent people with no political power will be harmed.
- dingusthemingus 6y agoWiki says Parler is a team of 30 people, So realistically, does that mean like 10 devs running a social network with 5-10 million users? I imagine its pretty ceazy there right now after getting booted off AWS, google just banned u off play store, so cant use them, i assume they cant use microsoft because theyll ban them there as well, it would be cool to see if they are able to get things up and running again. (Ive never used Parler but i assume its just like a simple Facebook type webpage/apps)
- jjice 6y agoI was thinking about it this morning. They probably didn't have an easy time finding new employees too because of the nature and controversy associated with the site, potentially part of the reason for lack of moderation. Not defending, just observing. It's interesting from a business/development perspective when it comes to rapid scale and team size.
- TameAntelope 6y agoSetting aside moral qualms for a moment, the engineering problems they're having right now are probably one-in-a-career problems, so it would be interesting work, without a doubt.
- Jtsummers 6y ago> They probably didn't have an easy time finding new employees too because of the nature and controversy associated with the site, potentially part of the reason for lack of moderation. Parler established itself as a "free speech" social network platform. Part of its objective, based on that principle, was minimal or no moderation. Ironically, of course, they banned many people who came in with left-wing views. Which means they actually worked to create the extremist bubble that is now causing them problems with others.
- pavel_lishin 6y ago> They probably didn't have an easy time finding new employees too because of the nature and controversy associated with the site, potentially part of the reason for lack of moderation. Maybe, but I would wager that there are a lot of tech people who sympathize explicitly with the people that Parler is trying to attract, and an even larger contingent who would work there under the auspices of protecting what they believe is the right to free speech, etc.
- deleted 6y ago[deleted]
- maurys 6y agoWhile I understand that Twilio is probably not at fault for the actual leak, I'm curious if they gave Parler some time to migrate/shift before cutting them off from their services. It's easy not to care since Parler is the "bad guy" here, but I do think that Internet infrastructure companies need to give a reasonable heads-up before pulling the rug under business customers.
- ashtonkem 6y agoTwilio is far from the top of Parler’s infrastructure problems, to be fair. The issue is that a “reasonable” heads up here is literally years long for some of these products, especially AWS. It’s hard for these companies to show bad clients the door in a way that isn’t disruptive.
- wilde 6y agoThey ignored AWS’s warnings for weeks. It seems unlikely that a grace period would do anything.
- nickysielicki 6y agoThis whole ordeal really sours Twilio in my mind. Whereas AWS can plausibly claim that they don't want to host illegal content, what can Twilio say for themselves here? From Twilios perspective, providing Twilio's core product to Parler isn't any different than serving them to other platforms. They have no responsibility or liability. The lack of moderation on Parler is irrelevant when Twilio isn't involved with moving that data. For a Saas platform to abruptly cut-up a contract, immediately breaking the authentication mechanism for the site on the other end of the contract, which directly results in a serious data breach for thousands of users (the majority of which have done nothing wrong), because your employees and leadership don't like their politics, doesn't sound like something that a publicly traded company should engage in. edit: especially once it became obvious that AWS was going to bring the site down just a few hours later. They had a clear route to make their ideological stand and cause no damage by merely waiting 12 hours more.
- tootie 6y agoIf we had a responsible administration we'd probably be seeing takedown requests from DHS over national security grounds. This isn't just a speech issue, it's safety. There's a void of government guidance on how to deal with this in a measured way, so deplatforming is the easiest and safest option. They can't force Parler to moderate their content and they can't let themselves be party to fomenting insurrection.
- gigatexal 6y agoI just can’t help but laugh that this service existed and to become a verified user (or whatever they called it) you had to upload a front and back scan of your driver’s license?? And then this happens and people who stormed the capitol are whining about being labeled terrorists and unable to fly home. 2021 has sucked but the fallout almost makes up for it in this case.
- visarga 6y agoWas it really a comprehensive data breach? Or they just got a list of URLs. Because some claimed it's fake news.
- mellosouls 6y ago"researchers". Imagine what they'd be called if this was Reddit, Twitter or a non-conservative site they'd hacked.
- Triv888 6y agoterrorists of course
- QuesnayJr 6y agoThe hack is equivalent to if someone downloaded all of the content of Reddit, or a database of all tweets, if this post is to be believed: https://www.reddit.com/r/ParlerWatch/comments/kv0jo6/psa_the_heavily_upvoted_description_of_the_parler/ https://www.reddit.com/r/ParlerWatch/comments/kv0jo6/psa_the.... Would anyone even bat an eye if that happened?
- SamBam 6y agoFrom the original article > This may include things from deleted/private posts. I think people would be alarmed if private DMs were leaked from Twitter, yes. The data also includes the geolocations of posters.[1] Another comment also suggested that the photos of the driver's licenses that were used to verify users were also being downloaded, though I'm not certain if this is true. 1. https://gizmodo.com/every-deleted-parler-post-many-with-users-location-dat-1846032466 https://gizmodo.com/every-deleted-parler-post-many-with-user...
- Miner49er 6y agoYeah, but this apparently was all downloaded through Parler's publically accessible API, so if anyone should be to blame here, it is Parler.
- akhilcacharya 6y agoYou can literally download Reddit and Twitter archives anytime you want.
- deleted 6y ago
- x86_64Ubuntu 6y agoI've always been amazed at how hackers can exfiltrate so much data with no one even batting an eye. Doing the math, the pure data cost to Parler was $7,700 (($0.15/GB10) + ($0.11/GB 40) + ($0.09/GB20)) 1000 => $7,700 https://aws.amazon.com/blogs/aws/aws-data-transfer-prices-reduced/ https://aws.amazon.com/blogs/aws/aws-data-transfer-prices-re... Even the Chase Bank hack had an astronomical amount of data that didn't appear to set off any alarms.
- mxcrossb 6y agoOf course, being unaware of how much you’re being charged is par for the course with AWS!
- josh_frome 6y agoBest they can do is eventual consistency for billing, apparently.
- wilde 6y agoTo be fair, there’s a story on here every week about how cloud provider alarms are happy to ping you 24h after the spend.
- nrmitchi 6y agoAccording to reports, their monthly AWS spend (prior to today, obviously) was ~300k (or 3.6M/year). 7.7k is not really a noticeable increase, and any alarms that did trigger would likely have been attributed to increased user growth and platform load. That is if someone was even seeing a billing alarm alerting with every other issue that was going on.
- curiousllama 6y agoI've seen more than one company that had a cloud spend policy that boiled down to: "if you spend a lot, the finance guy is gonna send you a snarky email a week later" Totally not surprised they didn't catch a 7.7k spike in real time
- 6y ago
- xiphias2 6y agoWhere is the responsible security disclosure? If these guys are security researchers, then Julian Assange is the best security researcher of the world. This all looks like normal politics to me.
- nr2x 6y agoOne side has the guns, the other the hackers. Place your bets.
- BlueTemplar 6y agoPhoto caption says : "Trump storming the US Capitol on January 6, 2021" While as we know very well, chicken shit (and/or delusional?) as he is, Trump himself did no such thing.
- KuhlMensch 6y agoI don't know this news site, but I hope its a typo
- cbgonz 6y agoHmmm... comes close to lynching a ton of people, if you ask me. Never mind who´s right or wrong, the point is that we all agree upon trusting a judicial system to do this kind of thing, don´t we?
- Pfhreak 6y agoThese folks had their private messages exposed. In no way is that "close to lynching". Depending on what the user posted, they might be embarrassed, lose their jobs, or end up in court. We can have a reasonable discussion about the ethics of hacking a site like parler, but not if the starting point is "this is the equivalent of violent mobs literally murdering innocent people".
- nullc 6y agoPeople on twitter are posting addresses and lat&long from parler users. People have also been posting on twitter statements advocating for the murder of people involved in the events in DC this week. Of course, 99% of that is meaningless bluster but 99% of the crap on Parler was also meaningless bluster. So I think it remains an open question as to what the consequences of this hack will be. I don't think it's impossible that someone may be literally murdered. But if it happens I'm sure everyone in the causal chain will be as quick to claim no responsibility as the Parler CEO was...
- KuhlMensch 6y agoIf parler is being used for either wide-spread or violent-motivated sedition, that might sway the court of public opinion somewhat.
- Pfhreak 6y agoI interpreted the poster saying "hacking parler is close to lynching", which is what I was responding to.
- Consultant32452 6y agoMany had images of their driver's licenses revealed also. Calling this close to lynching is definitely hyperbole, but it's also true that their identity and addresses were revealed and their lives are in eminent danger.
- AnHonestComment 6y agoSo cyber criminals stole millions of peoples private communications and leaked them online — people who did nothing and who are under no individual suspicion? And HN is cheering? Patriot Act 2.0 in 3... 2... 1.... What’s extra funny is I recognize the names cheering — and on other days, they’d talk about how the Patriot Act is wrong. But these are bad hombres, you see?
- throwaway4good 6y agoI tried to access some of this - went to: https://donk.sh/06d639b2-0252-4b1e-883b-f275eff7e792 https://donk.sh/06d639b2-0252-4b1e-883b-f275eff7e792 Picked a URL from one of the files - eg.: https://parler.com/post/c86aa37121374606aa63439ff15362aa https://parler.com/post/c86aa37121374606aa63439ff15362aa And put that into archive.is - eg.: https://web.archive.org/web/20210110213100/https://parler.com/post/c86aa37121374606aa63439ff15362aa https://web.archive.org/web/20210110213100/https://parler.co... All just seems to be Parler "tweets"; not particular interesting.
- deleted 6y ago[deleted]
- throwaway4good 6y agoLet me be clear; nothing there that you could not find by just browsing Parler. Maybe there is a deleted post somewhere and that could be interesting but since it is not marked and there a millions of URLs it is kind of useless.
- judge2020 6y agoStory is that Parler didn't delete the media associated with posts once they were deleted, so while you lost access to the post's text, the video files using incremental names (eg. 1.mp4, 2.mp4 etc) meant you could download videos from posts that might be deleted.
- throwaway4good 6y agoI think the "story" here might be a bit of hyperbole as what is going on here is just an archiving of the public contents of Parler similar to what happens all the time with Twitter.
- mcintyre1994 6y ago> With this type of access, newly minted users were able to get behind the login box API used for content delivery. That allowed them to see which users had moderator rights and this in turn allowed them to reset passwords of existing users with simple “forgot password” function. Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease. Can anyone make sense of this? In all the "forgot password" functions I've seen, you click "forgot password" and they email you a link to reset the password. How does "Twilio won't send our emails any more" lead to the "forgot password" function allowing account takeovers? I'd have expected it to just make "forgot password" no longer work because nobody can get a reset link any more. I can't figure out how you could configure things for this to lead to a security flaw this bad - other than "write all emails that fail to send somewhere public" which I can't imagine anyone doing. I can't imagine Twilio writing rejected emails from a closed down account somewhere public either. How does Twilio shutting down the account mean password reset links leak?
- cataphract 6y agoI don't get it as well. Maybe the reset password page had a username and an e-mail and Parler stopped checking that those belonged together?
- _alex_ 6y agoI'm making a wild-ass-guess here, but it sounds like when you clicked "forgot password" it would text you a code to punch in to verify your identity. It sounds like that part failed open. So once twillio went away, any code would succeed.
- calibas 6y agoCan we kill the whole "security researcher" term right now? Hacker is so much easier to type.
- mzs 6y ago>the lack of moderation on Parler is not the issue. they actually have very robust moderation tools and all new users start out shadowbanned until enough of their post get approved for rightthink by their user moderators https://twitter.com/donk_enby/status/1347939939120533506 https://twitter.com/donk_enby/status/1347939939120533506 >This is not an ad network. This is a system where their most "influential" users can get paid to post organic-looking sponsored content. Their CEO talks about it… https://twitter.com/donk_enby/status/1346565749977051136 https://twitter.com/donk_enby/status/1346565749977051136
- magicalhippo 6y agoI'm really starting to feel like my grandparents, who smiled back at me in such a way I could tell they had no idea what I was talking about back when I was a kid. This hack made the "front page" of news sites here in Norway, and I've never heard of the thing. I guess it's only fitting that I just got my own lawn...
- boringg 6y agoWould not want to be a part of the Parler team before this, and certainly not after this week. I can only imagine they are dealing with an insane amount of fires, rapid growth/demand and it seems that they have a far from robust product. Compound all that with the political component and intense attention - it would be an unbearable grind.
- aokiji 6y agoFirst it gets removed from Google and Apple stores. Then it gets deplatformed from Amazon. Now a hack that was in the making for a while due to political motivations. This is a political purge.
- no-dr-onboard 6y agoCall the spade a spade. There is an inappropriate use of the word "researcher" in the title. More appropriately this should read "...scraped via IDOR vulnerability."
- WarOnPrivacy 6y agoIt's disgusting that total strangers can read our public social media postings.
- NoblePublius 6y agoI thought Twitter had a “no hacked material” policy.
- mcast 6y agoI tried to sign up for Parler out of curiosity when I heard it was being removed from app stores, but as soon as it required a phone number for account registration I deleted the app. I'm surprised it also didn't require a social security number and credit card as well. /s
- deleted 6y ago[deleted]
- ausbah 6y agosome parts of the site apparently require a SSN and drivers lisence
- chmod600 6y agoWhen Edward Snowden leaked information, he went through a journalist gatekeeper to do so as responsibly as possible. Even the Hunter Biden story went through the NY Post. This doesn't feel like a responsible, good-faith effort to save the republic. It feels like an attack on one's political enemies. Using the euphemnism "security researcher" in this case doesn't help. Perhaps underhanded tactics are needed to prevent evidence destruction, but call them what they are. Don't pretend they are curious academics or a corporation hardening their systems.
- 0x4d464d48 6y agoI'm left-winged with absolutely no love for Parler and believe a lot of people have blood on their hands for the violence incited last week. The security researchers were wrong to make this information publicly available but the fact that Parler actually put their users at risk like this with such a disturbingly glaring security flaw is absolutely infuriating and outrageous. I'm speaking as a believer in civil rights and user protection. Call it growth hacking or try to overlook this as a sympathetic mistake if you wish but this was a disgustingly reckless decision for any competent technical team to make and it deserves profound censure.
- willejs 6y agoThis wasn't leaked, it was archived from public sources. https://news.ycombinator.com/item?id=25727025 https://news.ycombinator.com/item?id=25727025
- willejs 6y agoSee original author clarifying this wasnt a leak or a hack. https://twitter.com/donk_enby/status/1348666166978424832 https://twitter.com/donk_enby/status/1348666166978424832
- bArray 6y ago> Parler, a social network used to plan the storming of the > U.S. Capitol last week [..] I thought "huh, never heard that before" - checked the source [1] and it's essentially some people working at DRFLab speculating that it _may_ have been the case. So not off to a great start. The links appear down to me, but if I remember correctly these were a series of links to Parler - which the website is now down due to AWS. So the "leaks" can no longer be downloaded. I also believe that the links were essentially all just public material from what I could find... [1] https://www.atlanticcouncil.org/content-series/fastthinking/fast-thinking-how-the-capitol-riot-was-coordinated-online/ https://www.atlanticcouncil.org/content-series/fastthinking/...
- liminal 6y agoI see a number of people here describing Parler as "unmoderated", but it turns out they do have extensive moderation [1] that they use to ensure ideological conformity in their posts. Then the most active users were paid for their content too [2]. This really makes it more of a propaganda weapon than a free speech platform. [1] https://twitter.com/donk_enby/status/1347939939120533506 https://twitter.com/donk_enby/status/1347939939120533506 [2] https://twitter.com/donk_enby/status/1346565749977051136 https://twitter.com/donk_enby/status/1346565749977051136
- whimsicalism 6y agoBy that standard, Instagram is a propaganda weapon. It both: a. pays popular users b. Puts warnings on political issues, like statements that Biden's crime bill contributed to mass incarceration [0] [0] https://twitter.com/ben_awareness/status/1339293381625864195 https://twitter.com/ben_awareness/status/1339293381625864195
- bzb6 6y agoThat’s true but Instagram doesn’t claim to be a free speech platform
- whimsicalism 6y agoSo that makes it permissible for private actors to publish 70TBs of private Parler users' messages?
- bzb6 6y agoI did not say anything like that
- whimsicalism 6y agoI guess I'm confused as to the relevance to this thread. This person claimed that two attributes made Parler a "propaganda weapon", I noted that other major platforms have those same properties, so you tacked on another condition. Presumably this was all in an effort to say something along the lines of - "because of the unique situation Parler is in, these actions were permissible." No?
- tekstar 6y agoAll the claims about the big tech censoring Parler got it wrong. It's not about censure. It's about legality, and Parler fucked themselves. Apple told Parler to moderate their extremist content, and Parler refused. At that point, if Apple left Parler on the App Store, Apple would be complicit. Same story played out for all the services. And guess what, treason by definition is infectious. Giving aid to an enemy of the United States. So Apple at that point would be opening themselves to a huge legal liability if they kept the app available. Nothing has been proven in court but big tech is naturally risk adverse. If Parler has agreed to moderate extreme content, even if they had done so dragging their feet, they would still be alive.
- quotemstr 6y agoRefusal to impose extralegal speech restrictions is treason? No, it doesn't work like that. See the Brandenburg case. You have no idea what you're talking about.
- tekstar 6y agoIllegal. Some of the content on Parler was illegal. Not extralegal. Illegal. And they refused to moderate it when asked. Some if it has the risk of ending up judged treasonous as well, and that's all that matters to a risk averse company.
- quotemstr 6y agoThe claim I see over and over is that broad swaths of speech on Parler were illegal. It's not true. Repeating it doesn't make it so. "Insurrection" --- a call to overthrow the government --- is 100% legal speech in the US under the Brandenburg precedent. You don't get to call a company's refusal to go beyond the law in enforcing speech a form of treason.
- tekstar 6y agoI never said there had to be swaths of illegal content. In other words you are asserting there was absolutely no illegal content on parler that would require them to moderate their content when asked. If that's the stand you want to take, cool, have a great day, I am not responding to you further. Corporate legal risk assessment is what killed Parler.
- sillysaurusx 6y agoThis person committed a crime to leak this data. I don't know how any of you can be this blatantly two-faced or so unprincipled. You're cheering on a criminal committing a crime. You're cheering on the suppression of an entire political party, while calling them extremists, fascists, terrorists, and every other -ist that you feel vaguely fits the bill. Yes, a few of them marched on the capitol. Yes, that was awful. No, you're not going to stop the underlying feeling by simply wishing it away, or taking more and more byzantine measures to suppress their ability to associate with one another.
- Finnucane 6y agoIt is certainly arguable that if this data contained evidence of serious crimes--such as plotting treason and murder of government officials--then under normal circumstances, it should be turned over to the appropriate agencies, such as the FBI, and not released publicly, so as to not doxx people who may not necessarily have committed any crime beyond the poor judgement of hanging with fascists. Whether we can beleive that the FBI, etc, will deal with this appropriately is another matter.
- sillysaurusx 6y agoThat’s a fine argument, and if someone had seen such a thing, it might even change my mind. But this was done preemptively: “that probably exists, so this is probably okay.”
- Finnucane 6y agoSome of it had been seen. The folks plotting criminal stuff weren't especially good at keeping it hidden.
- diragon 6y agoNot an entire political party. "All terrorists all Republicans" (which is most probably a true statement for the terrorists who attacked the Capitol) and "All Republicans are terrorists" are not equivalent statements. Republicans are way more than that alt-right fringe. They have a respectable history and many good political stances.
- huhtenberg 6y agoA second-hand recap of how it was done - https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_parler_user_data_is_being_downloaded_as_we/giu04o6/?context=3 https://www.reddit.com/r/ParlerWatch/comments/kuqvs3/all_par...
- imwillofficial 6y agoThis title is misleading. Leaking private data of users after accessing it illegally is not “security research”, its criminal hacking.
- deleted 6y ago[deleted]
- grawprog 6y ago>In a press release announcing the decision, Twilio revealed which services Parler was using. This information allowed hackers to deduct that it was possible to create users and verified accounts without actual verification. >With this type of access, newly minted users were able to get behind the login box API used for content delivery. That allowed them to see which users had moderator rights and this in turn allowed them to reset passwords of existing users with simple “forgot password” function. Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease. So these 'security researchers' are random hackers that illegally gained access to accounts and servers are actively doxxing people and this behaviour's now being praised? Apart from being illegal, I seem to recall severe backlash against several instances of doxxing in the past, which is exactly what these people have done. I wonder if people would still be cheering this on if 70TB worth of twitter information had been leaked instead.
- arbitrage 6y agoYou ask questions like you don't know the answer you're already looking for. Hate speech is not protected. Take your fascist apologies somewhere else.
- deleted 6y ago[deleted]
- beerandt 6y agoYea, there's no reason 70TB of downloaded data and millions of user accts (with each requiring an additional attack iteration) were needed to prove a security weakness. Let alone the creation of a coordinated, decentralized network of machines to exploit the attack and maximize data extraction. "Security Researchers" The doublespeak is getting maddening.
- Craighead 6y agoDomestic terrorists deserve no quarter. There is no double speak, this group of insurrectionists wanted to destroy the rule of law. Pettifoging this reality to play the 1984 card is weak.
- deleted 6y ago[deleted]
- ookblah 6y agoi like how there's two narratives here. like i get it, personal information shouldn't be leaked and i feel bad for those users who weren't a part of the extremism and getting potentially doxxed for it. at the same time anytime this happens to a larger corporation don't we absolutely SHIT on them for the substandard security procedures? and whatever happened w/ parler is looking more and more amateur hour here, nothing sophisticated to get the data. just because it's some "underdog" suddenly it's okay?
- jefe_ 6y agoIt's interesting to me that the demand for Parler was almost exclusively the result of policies enacted by other social media platforms. Perhaps there was merit to the notion that letting groups operate in a contained area of larger platforms would have been favorable to outright bans. This would allow the larger platforms to monitor engagement, control spread, and quietly respond as they desired, no one the wiser. Instead they made very public proclamations of content restrictions and bans, which escalated some casual participants to more engaged participants. These participants then gathered on a new platform that promised the ability to say anything, so they started saying anything. But then some people started to believe anything. And then the beliefs turned into action, and then it became a real problem. But the outcome is in no way surprising. What is surprising is that the response now is the same response that started it all, more public bans and content restrictions. It's trivial to start a social media app (especially when security is not the priority), so in a few months another app will pop up, and it too will get out of hand, but what then? It seems like policymakers and thought leaders aren't thinking long term and are doing nothing to look at underlying issues.
- cactus2093 6y agoSounds like you're arguing for more of an approach of placating them, giving them a platform and trying to listen to them as misunderstood victims. Seems to me like that's exactly what the rest of the country has been doing this whole time. For years everyone went along with the fringe right and placated them. The mainstream media covered Trump closely. Talked to his supporters to try to understand them. The more mainstream Republicans have backed up all the things Trump has done and said until now. Facebook got tons of flack the last 4 years for not silencing them sooner. Now it has escalated to dangerous levels of inciting violence that actually came pass, which has led to a stronger response. But you're arguing for continuing to go along with them? Why should we expect that continuing down the path we've been on for years would reverse the trend of them getting more and more extreme?
- bborud 6y agoIf this is true, the adversaries of the US now probably have a considerable database of people who are vulnerable to manipulation and who can be used for active measures on US soil. Not that I don't think they didn't have a pretty good database of this already. But this still is the aspect of this that I find more worrisome. Russia, China and whomever else might be interested could weaponize this to great effect.
- pelasaco 6y agointeresting opinion from Glenn Greenwald: "Do you know how many of the people arrested in connection with the Capitol invasion were active users of Parler? Zero. The planning was largely done on Facebook. This is all a bullshit pretext for silencing competitors on ideological grounds: just the start." https://twitter.com/ggreenwald/status/1348619731734028293 https://twitter.com/ggreenwald/status/1348619731734028293
- throwoutttt 6y agoGood. We need to come together as a country, identify Trumpists and give them a chance to publicly repent or not else suffer the consequences of their wrong thoughts. Ideas are not free.
- ashudeep 6y agoNow the NLP researchers can study how influence through language works in the far right groups. This will give a good enough strategy for other social media and knowledge to us as a society to not fall prey to such traps in the future.
- deleted 6y ago[deleted]
- coast12 6y agoYou say leaked, I say additional backup :)
- chopin24 6y agoCan we now see how many users there actually were, and how many were in the US? Because there's no shortage of troll farm companies that exist solely to get people riled up.
- arthurcolle 6y agoSorry for the double post but hoping someone could chime in - How did they accumulate so much content so fast? 70TB seems insanely huge for a pretty new company, isn't it only like 5 months old?
- deleted 6y ago[deleted]
- kazinator 6y ago> Since Twilio no longer authenticated emails, hackers were able to access admin accounts with ease. I don't give a damn about Parler or USA politics. The troubling thing here is how the security underpinnings of an entire platform like Parler can be screwed over by third-party SaaS provider. The fact that the platform contained some "bad actors" is only a distraction. This is the real issue, or one of them.
- r00fus 6y ago> The troubling thing here is how the security underpinnings of an entire platform like Parler can be screwed over by third-party SaaS provider. News flash: Twilio doesn't control who gets in, just instead of returning ack/nack, they simply were unavailable. The onus of what to do in this case is entirely on Parler who foolishly decided to default to fail-open (presumably because Twilio being down might impact their bottom line or adoption). If that's a "real issue" then blame the ones who implemented this service for Parler.
- kazinator 6y agoSo basically, "I'm unable to verify that you are the owner of this e-mail address now due to the third-party verification platform being unavailable. So, just, here you go, proceed to resetting the password, whoever you are ..."\ Could just that be an integration bug? Things failed open because someone didn't code, or else test that case?
- diveanon 6y agoI mean let's call it what it is, a hack and dox. That being said, doing to lords work. Expose this cancer so it can be removed.
- zyxzevn 6y agoSo, can we now all see the contents of Hunter Biden's laptop as well?
- samuelizdat 6y agoNot a serious country
- ALittleLight 6y agoSo long as we're talking about white supremacists and hacking, I remember when a "white supremacist" hacker weev was convicted and sentenced to 41 months in federal prison for reading a few thousand sequential ids from an AT&T webpage. He reported the vulnerability to AT&T and showed a limited example to a journalist. This seems far worse - so of course we can expect criminal prosecution of these "researchers"?
- uses 6y agoWhy'd you put "white supremacist" in quotes? He's a proud neo nazi.
- ALittleLight 6y agoBecause I don't know much else about him apart from that story and I don't trust the media when they call people white supremacists. I intend the quotes to indicate that people call him a white supremacist, not that I don't.
- exabrial 6y agoI disagree with everything Parler, but this is a pretty steep ethical violation.
- dwd 6y agoThere's been a bit of talk that Parler was only ever a way for alt-right Republican operatives such as the Mercers to have their own social media and data gathering platform after the Cambridge Analytica fallout. This is the data they wanted...
- tonfreed 6y agoOn the one hand, dick move. If I leaked that person's twitter messages it'd be a shitstorm. On the other hand, lock down your shit hard. Can't blame them for scraping it all down if it's just hanging out in the open like that
- 2Gkashmiri 6y agoCan anyone tell me what would have been the hosting and bandwidth costs of having 70tb on aws?
- Cyberthal 6y agoThe difference between a security research and a hacker is the same as between a protester and a terrorist, apparently.
- quantified 6y agoThis may have been covered in the previous 900 comments, but... Did security researchers leak the messages, videos and posts? Or did they access them (i.e. Parler leaked them to the researchers)? Seems the headline is misleading.