TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Parler Databases Disclosed

180 点作者 lox超过 4 年前

24 条评论

neya超过 4 年前
&quot;Twilio put out at midnight last night. In that Press Release, Twilio accidentally revealed which services Parler was using. Turns out it was all of the security authentications that were used to register a user. This allowed anyone to create a user, and not have to verify an email address, and immediately have a logged-on account.<p>Well, because of that access, it gave them access to the behind the login box API that is used to deliver content -- ALL CONTENT (parleys, video, images, user profiles, user information, etc) --. But what it also did was revealed which USERS had &quot;Administration&quot; rights, &quot;Moderation&quot; rights.<p>Well, then what happened, those user accounts that had Administration rights to the entire platform... The hackers, internet warriors, call it what you will, was able to use the forgot password link to change the password. Why? Because Twilio was no longer authenticating emails. This meant, they&#x27;d get directly to the reset password screen of that Administration user.&quot;<p>I&#x27;m not from the US, but as an outsider, this leaves a really bad taste with how Twilio handled the situation AS A BUSINESS.
评论 #25727591 未加载
评论 #25739354 未加载
评论 #25726941 未加载
评论 #25727332 未加载
评论 #25728895 未加载
评论 #25726772 未加载
评论 #25729951 未加载
评论 #25727281 未加载
评论 #25727726 未加载
评论 #25727078 未加载
评论 #25727458 未加载
willejs超过 4 年前
This post seems fake. There was a group of people archiving the public content of parler using this docker container <a href="https:&#x2F;&#x2F;github.com&#x2F;ArchiveTeam&#x2F;parler-grab" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;ArchiveTeam&#x2F;parler-grab</a> and archiving it here <a href="https:&#x2F;&#x2F;tracker.archiveteam.org&#x2F;parler&#x2F;" rel="nofollow">https:&#x2F;&#x2F;tracker.archiveteam.org&#x2F;parler&#x2F;</a>.<p>I can&#x27;t validate anything else in this twitter post. The administrator accounts part all seems fake, unless anyone has found the rest of the content or has a better source?<p>Previous discussion deeming its fake here <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25725268" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25725268</a>
评论 #25731649 未加载
评论 #25733722 未加载
评论 #25727179 未加载
评论 #25727104 未加载
zenexer超过 4 年前
Can we get some better sources? This seems like an awful lot of hearsay, and there have been several comments from HN readers in this thread[0] and another[1] indicating that there is no public evidence to support these claims. Given that the author is alleging this is a crowdsourced effort, such evidence should be trivial to locate, but none has surfaced.<p>[0]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25727332" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25727332</a><p>[1]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25725268" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=25725268</a>
评论 #25739862 未加载
mikewarot超过 4 年前
AWS gives 5Gbps connectivity to instances, according to <a href="https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;whitepapers&#x2F;latest&#x2F;ec2-networking-for-telecom&#x2F;overall-instance-bandwidth-limitations.html" rel="nofollow">https:&#x2F;&#x2F;docs.aws.amazon.com&#x2F;whitepapers&#x2F;latest&#x2F;ec2-networkin...</a><p>So, if the sum total of Parler was 70 Terabytes, as claimed... the transfer time would be 38 hours, if it was hosted on one instance... but it obviously wasn&#x27;t. It was more likely only a matter of minutes.<p>This shows a new type of cloud hosting vulnerability. Your entire corporations infrastructure could be mirrored faster than you could notice.
评论 #25727695 未加载
评论 #25727484 未加载
评论 #25727422 未加载
评论 #25728296 未加载
评论 #25727300 未加载
fabian2k超过 4 年前
How would disabling Twilio disable authentication entirely? From what I see it is used to send SMS and maybe Email as well. So I could understand that it would prevent login, registration and password reset if that service is offline, but it shouldn&#x27;t allow any of these without authentication.<p>Unless the software skipped authentication entirely when this service was unavailable, which I find hard to imagine. But that seems to be what is claimed right now.
评论 #25726765 未加载
评论 #25728374 未加载
traveler01超过 4 年前
I don&#x27;t know why but what&#x27;s happening to Parler doesn&#x27;t feel right at all...
评论 #25727491 未加载
评论 #25727261 未加载
评论 #25727589 未加载
评论 #25727451 未加载
评论 #25733400 未加载
评论 #25727312 未加载
notadev超过 4 年前
I wonder if Twitter will be nuking any info from their site, with their policy against posting hacked information and whatnot.
kodah超过 4 年前
The description of the hack is not accurate. Okta is the service that disclosed the endpoints used.
评论 #25726769 未加载
评论 #25726728 未加载
cycrutchfield超过 4 年前
The explanation is a jumbled mess, but I think there are two key parts here:<p>1. Somebody reverse engineered the iOS app, which allowed them to access Parler&#x27;s API and enumerate all of the content on the app<p>2. The Twilio shutdown affected SMS verification for new account registration, meaning people were now able to programmatically create many new user accounts which they could combine with #1 to scrape all the data without being rate limited
评论 #25739942 未加载
icare_1er超过 4 年前
I find it hard to believe this timing is a coincidence...
评论 #25727240 未加载
scotty79超过 4 年前
Wait. So how did it work exactly? Why would you get to reset password after clicking &quot;I forgot password?&quot;<p>I thought password reset flow is initiated from the email link not from &quot;Forgot password&quot; link and just paused till email link is clicked.
评论 #25753496 未加载
woliveirajr超过 4 年前
In the midst of all this, one thing always bite any site when some break-up happens:<p>&gt;Also, a lot of posts were deleted by Parler members after the riots on the 6th. Turned out... Parler didn&#x27;t actually delete anything.. just set a bit as deleted.<p>The perils of soft&#x2F;logical delete instead of hard&#x2F;real deletion.
wobblyasp超过 4 年前
Seems to be another faked &quot;hack&quot; of Parler. Does Twilio even have a user management component? Why is the explanation of the hack a jumbled mess?<p>I&#x27;ll believe it when after private convos are leaked.
rubinlinux超过 4 年前
This twitter thread puts this in a bit different light, I think. <a href="https:&#x2F;&#x2F;twitter.com&#x2F;davetroy&#x2F;status&#x2F;1327253991936454663?lang=en" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;davetroy&#x2F;status&#x2F;1327253991936454663?lang...</a>
davidg109超过 4 年前
Very shoddy development. It sounds that if there was ever a Twilio outage, the same vulnerability could have played out. Not hard to know how Twilio is used either, especially as employees come and go. This was a disaster waiting to happen either way.
aaron695超过 4 年前
This comment seems to explain what really happened best -<p><a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ParlerWatch&#x2F;comments&#x2F;kuqvs3&#x2F;all_parler_user_data_is_being_downloaded_as_we&#x2F;giuz38a&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;ParlerWatch&#x2F;comments&#x2F;kuqvs3&#x2F;all_par...</a><p>One &#x27;hack&#x27; enumerating content<p>One &#x27;hack&#x27; mass producing accounts to spam with
irscott超过 4 年前
My question is-<p>Looking at this dump, it appears to just be URLS. If the site doesn&#x27;t exist anymore than the URLs point to nothing.<p>What&#x27;s actually exposed? What am I missing here?
trst超过 4 年前
<a href="https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;EPYU4kn" rel="nofollow">https:&#x2F;&#x2F;imgur.com&#x2F;a&#x2F;EPYU4kn</a> I warned about this
hehehaha超过 4 年前
If I am understanding this correctly, Parler devs left the app as MVP. They never rebuilt it with security and privacy in mind.
ht85超过 4 年前
Your security is only as good as your unpopularity. Karma.
90red超过 4 年前
More terror ops against conservatives.
Yetanfou超过 4 年前
If there is one lesson to be learned from these last few weeks it is that you can not rely on any external service if you do anything which goes against the dominant political narrative. I have never been on Parler&#x27;s site so I can not check the veracity of their supposed implied or direct support for seditious acts but that does not seem to matter anyway, it is enough to stand accused to be considered a witch and burned at the stake.<p>Build your own is the device, keep your equipment on your own premises, make sure not to have single points of failure - that implies you need to have a backup access provider just in case your internet connection gets cancelled. Don&#x27;t rely on electronic payment processors, you can use them but make sure to have a backup. Don&#x27;t rely on a single bank, have multiple accounts, preferably in more than one country.<p>It is a sad thing that it has to come to this but I think we&#x27;ll eventually end up with politicised service institutions which cater to &quot;progressives&quot;, others which cater to &quot;conservatives&quot;. They won&#x27;t state this directly but it will be known that a conservative builder is better of at this bank and that insurance company, he&#x27;ll prefer to buy this coffee and that brand of razor, etc. A shame, really, the more divided society becomes, the harder it will be to find a common cause when such is needed, e.g. in case of a national emergency like an epidemic.
评论 #25727298 未加载
评论 #25727423 未加载
评论 #25727438 未加载
评论 #25727292 未加载
yurgen228超过 4 年前
I find it all hard to believe
atemerev超过 4 年前
Oh come on, it was a honeypot from the beginning.<p>Everybody in the last few days was talking about Parler -- they got more exposure than ever in their life. The takedown from AWS was announced a few days before, so more users could register. Parler was running a &quot;Verified Parler citizen&quot; (wat?) campaign, to gather more personal data. And now, hackers conveniently exposed everything. Hackers are unpredictable, you know.<p>I am not defending the Parler audience; the honeypot was elegant, but is it ethical?
评论 #25726912 未加载
评论 #25727278 未加载
评论 #25727120 未加载
评论 #25726974 未加载
评论 #25727048 未加载