Oct 31, 2017
13,236
Failure to purge authentication tokens taken in first breach leads to second one.

gab-hack-no-2-640x606.jpg


The compromise came to light after someone hijacked the account of Gab founder and CEO Andrew Torba and left a post criticizing him for not paying an 8 bitcoin ransom for the safe return of documents used to verify the identity of some users. The unknown hacker also accused Torba of failing to disclose the full extent of the earlier breach.

"The attacker who stole data from Gab harvested OAuth2 bearer tokens during their initial attack," Torba wrote. "Though their ability to harvest new tokens was patched, we did not clear all tokens related to the original attack. By reusing these old tokens, the attacker was able to post 177 statuses in an 8-minute period today."

Gab's failure to purge bearer tokens may have stemmed from unfamiliarity with the open source Mastodon code the site runs or an unwillingness to require users to go through the hassle of resetting OAuth2 bearer tokens. The theft of the tokens came as a surprise to many because they weren't included in a trove of hacked Gab data posted by the Wikileaks-style site Distributed Denial of Secrets following the breach.

giphy.gif


Hack me (don't) if old.
 

oldboss

Shinra Employee
Member
Nov 9, 2017
1,481
Oh no.

Reading that side bar content has almost given me an ulcer.
 

Slayven

Never read a comic in his life
Moderator
Oct 25, 2017
97,966
To truly own the libs, you yourself have to be owned
 

Ashlette

Member
Oct 28, 2017
3,254
It's scary that some people look at that site's headlines on the right and say "hmm, this is fine".

If that site was shut down for good, nobody would miss it. Nobody important anyways.
 

DiipuSurotu

Banned
Oct 25, 2017
53,148
Does this kind of hacking keep happening to those sites because they are very frequently targeted, or is this because they have shit security?
 
OP
OP
ThisThingIsUseful
Oct 31, 2017
13,236
Does this kind of hacking keep happening to those sites because they are very frequently targeted, or is this because they have shit security?

The latter, I'm pretty sure. You have to think sites like Facebook, Twitter, Instagram, hell stuff like NBCNews.com are targeted frequently.

If you want a nerdy deep dive Troy Hunt offers a in-depth look into and even some back and forth that happened: https://www.troyhunt.com/gab-has-been-breached/

This has been a really good read, thanks!
 

CreepingFear

Banned
Oct 27, 2017
16,766
It's scary that some people look at that site's headlines on the right and say "hmm, this is fine".

If that site was shut down for good, nobody would miss it. Nobody important anyways.
Those are tame compared to some of the stuff I saw shared on Facebook during the Obama years. I unfollowed people before finally quitting Facebook altogether.
 

CreepingFear

Banned
Oct 27, 2017
16,766
There's a term in the IT industry about people knowing just enough to get themselves in trouble. Well, the people that started Gab and Parler knew just enough to start a website, but not to keep it secure.
 

Psittacus

Member
Oct 27, 2017
6,251
8 BTC is too high, they should have made it laughably low to really drive the point home
 

IggyChooChoo

Member
Oct 25, 2017
8,230
When will I get to search for the posts of my second cousin-in-law? She quit Facebook last October after her posts about Hillary drinking children's blood kept getting taken down, and I need to know exactly how crazy she got on Gab/Parler in case she and my second cousin ever get back together!