7 ms·
Parler’s amateur coding could come back to haunt Capitol Hill rioters
- vectorbunny 6y agoAs linked in article, scraping code here: https://github.com/ArchiveTeam/parler-grab/blob/master/parler.lua https://github.com/ArchiveTeam/parler-grab/blob/master/parle...
- eutropia 6y agoI’m morbidly curious: what was their tech stack?
- gregmac 6y agoSarah Mei did an interesting thread [1] on one aspect. A few months back, they had an unexpected outage that turned out to be caused by hitting 2,147,483,648 notifications. That number should look instantly familiar to most programmers. [1] https://twitter.com/sarahmei/status/1348474269064339456 https://twitter.com/sarahmei/status/1348474269064339456
- oceanghost 6y agoThat is terrifying.
- stunt 6y agoInteresting points. But, unnecessary humiliation as well.
- wmil 6y agoShe's a little over the top. I seem to recall that Twitter was running on Rails & Postgres for years after it had a ton of VC money.
- commandlinefan 6y ago> Its public API used no authentication. When users deleted their posts, the site failed to remove the content and instead only added a delete flag to it. Oh, and each post carried a numerical ID that was incremented from the ID of the most recently published one. There's really nothing wrong with any of that, unless you're specifically coding to defend against content scraping. I mean, the whole point of a "tweet" or whatever they're called in Parler land is to be public and discoverable. > failure to scrub geolocations from images and videos posted online Worse, but again, was the site even supposed to be designed with anonymity in mind?
- jcranmer 6y agoThe topper is that it doesn't appear that requesting post #N did any checks for if you are allowed to see it (i.e., it doesn't check if post #N is private or deleted). That means that naïve content scraping will uncover private/deleted posts, which is the really big "oops" that Parler had.
- commandlinefan 6y agoAh - well, yes, that's worse.
- trianglem 6y agoWas their security even supposed to work? Yes.
- whatshisface 6y ago>Worse, but again, was the site even supposed to be designed with anonymity in mind? According to reports from several HN users who tried making accounts, Parler requires drivers license photos as a part of the process you have to go through before you can post. Rather than being designed for anonymity, they seem designed to identify all of their users as unequivocally as possible.
- jasonladuke0311 6y agoSo it was a honeypot.
- partiallypro 6y agoI still doubt many rioters used Parler to coordinate. Glenn Greenwald has been investigating this and had as of a few days ago found none of those arrested on the platform. Facebook sat on the "stop the steal" FB groups for ~70 days and had so far not gotten much scrutiny.
- LarryDarrell 6y agoFrom what I understand, Parler was bankrolled and designed to do exactly what it was ultimately shutdown for. That is, be a concentrated anger-machine-echo-chamber. I'm not angry at the public corporations that have dropped Parler. I'm angry at the people that created Parler in the first place. It was basically a poison pill designed to test our feelings about free speech, designed to provoke. Mission accomplished, buttheads. I think we'll see the angry mob go end up at less discoverable, but more robust distributed platforms. Which is a shame, because it means eventually, when I say that you can find me on Mastadon/Scuttlebutt/etc, the average person will say, "Oh, you're on that extremist network?" The benefit to Facebook/Reddit/Twitter is that while Parler is dominating the discussion, they can start cleaning up their most toxic communities.
- deleted 6y ago[deleted]
- deleted 6y ago[deleted]
- mormegil 6y ago> I think we'll see the angry mob go end up at less discoverable, but more robust distributed platforms. Which is a shame, because it means eventually, when I say that you can find me on Mastadon/Scuttlebutt/etc, the average person will say, "Oh, you're on that extremist network?" That's always a problem with communities explicitly dedicated to freedom/non-censorship/etc., cf. Scott Alexander's https://slatestarcodex.com/2015/07/22/freedom-on-the-centralized-web/ https://slatestarcodex.com/2015/07/22/freedom-on-the-central... > There’s an unfortunate corollary to this, which is that if you try to create a libertarian paradise, you will attract three deeply virtuous people with a strong committment to the principle of universal freedom, plus millions of scoundrels. Declare that you’re going to stop holding witch hunts, and your coalition is certain to include more than its share of witches.
- jjeaff 6y ago>I think we'll see the angry mob go end up at less discoverable, but more robust distributed platforms. Not unless those distributed platforms are as easy to sign up for and use as twitter. I realize that not all the type of people that went to riot at the capitol or stupid, but the fact that they were there proves that most are intellectually lazy at best. Any extra effort to use a social network will completely block most from participating.
- Ancapistani 6y agoIf I’m understanding what happened correctly, the archivists here exploited a vulnerability to create numerous administrator accounts on the system, bypassing Parler’s security (as trivial as that was), and used those accounts to access private information from all individuals on the platform. My question is this: are the people who originally exploited this, created the image, and the users who downloaded it to collect the data going to be subject to federal charges? It seems obvious that they broke the DMCA in using the exploit and the FCAA in collecting and publishing the data acquired. If so, and the data were obtained through criminal means, is it even admissible in a criminal case? Full disclosure - I have/had a verified Parler account, dating long before the Capitol stuff. I tend to join pretty much all the new social network stuff to claim my name and so I know what I’m talking about when I discuss it elsewhere. I don’t think I ever posted a “Parley”, and if memory serves the only PMs I sent were asking a friend about LED headlight options for my wife’s vehicle. I’m not concerned about that conversation leaking, but it will amuse to me see if it’s in the collected dataset.
- dragontamer 6y agoIANAL, but... I expect the hackers to be subject to federal crimes. As I discussed elsewhere: opening mail addressed to someone else is a federal crime, because mail has an expectation of privacy. It doesn't matter how easy it is to open an envelope, all that legally matters is the assumed intent. If one party clearly wanted a message to be private, it is illegal to open that message. ------ In contrast, a Postcard has no expectation of privacy. And therefore, it is perfectly legal to read a postcard.
- nwsm 6y agoWere these posts private? I've never been on Parler so I have no idea, but I'm not reading anything that suggests they were direct messages or "private" accounts making the posts.
- dragontamer 6y agoThey were marked "deleted". Which means the privacy question is a bit ambiguous. They were public at one point, but at the time they were leaked out, they had a deleted flag and clearly were meant to be private. IANAL, but I'd expect it to be illegal to grab data marked "deleted". If you were a few hours earlier and archived them before they were deleted, that probably would be legal.