Quantcast
Channel: biscobosco
Viewing all articles
Browse latest Browse all 73

Yes - 99% of Parler posts were downloaded; No - it wasn't an Exploit/Intrusion/Hack

$
0
0

A rec list diary is in error — and quotes a discredited reddit thread.

No admin or authentication hack was exploited to archive parler data. In fact the site was badly coded and allowed unauthenticated access to posts.

virindiparlerhackcomment.png

 

www.reddit.com/...

The data downloaded was publicly available posts — which arguably should not have been public, since it included deleted posts which parler should have actually deleted.

Because parler’s security sucked, (unsure for how long, either recently, or longterm):

parler.com allowed public unauthenticated access to all posts including deleted ones via http!! This is bad. this was like having a lock on your front door,  (user interface) and then having absolutely no side wall on your house. (access to files via api)

There was no “active hack” of user credentials.  What the “other story up on dkos gets wrong”:

the whitehat - @donk_enby didn’t “break in.”

x

So, no drivers licenses.

However, what WAS DOWNLOADED  includes the raw files for videos that people took and posted which includes METADATA such as GPS info — Even if deleted because PARLER DID NOT ACTUALLY DELETE UPLOADED FILES and “posts” when you requested it. 

So the takeaway:

Whitehats to the rescue helping law enforcement w/ info to determine who was involved in the capital riot/insurrection via perfectly legal means.

And  — Any posts by rightwing influencers calling for violence in the leadup to this.

More:

x

And though the drivers license, or phone info was largely NOT downloaded, Amazon potentially/likely has it archived. Excellent. Let Law and order prevail!

x


Viewing all articles
Browse latest Browse all 73

Latest Images

Trending Articles





Latest Images