4 ms·
For sure. I shared this in another comment earlier, but they literally were using a free trial of Okta [1] to secure prod. This is why all of their user data
by snoshy 6y ago
For sure. I shared this in another comment earlier, but they literally were using a free trial of Okta [1] to secure prod. This is why all of their user data got leaked. Their code was written to fail open, so if Okta didn't respond for some reason to auth requests, access was granted by default.
[1] https://twitter.com/okta/status/1348191370528256002 https://twitter.com/okta/status/1348191370528256002
- duskwuff 6y agoMy understanding is that that was a myth. The data which was exfiltrated from Parler was retrieved through their mobile API, which allowed for easy enumeration of content and didn't implement some expected access controls (like blocking access to deleted content).
- ashtonkem 6y agoThem using a trial version is not a myth; that is from the official Okta Twitter account. My understanding of the scraped data is that some APIs used both sequential keys, and ignored both permissions and their soft delete flag. It’s not clear to me whether or not that API was permanently unauthenticated, or if it failed open once Okta locked them out.
- duskwuff 6y agoThat API was effectively public by design. It's the same API that anyone using the Parler mobile app would have been accessing.
- tptacek 6y agoThat API --- their most obvious, public API --- appears to have done no authz, despite using sequential identifiers. There are private feeds on Parler. That's clownish. I don't understand why anyone would trust them going forwards.
- ashtonkem 6y agoI don’t understand either, but lots of people appear to be doing lots of things I don’t understand. So I’m going to assume that people will continue us to trust them going forward, even if I think they shouldn’t.
- tptacek 6y agoI don't know what the pill color for this is, but, like, welcome to the desert of the real and all that.