Hackers Scrape 90,000 GETTR User Emails, Surprising No One (vice.com) 75
Just days after its launch, hackers have already found a way to take advantage of GETTR's buggy API to get the username, email address, and location of thousands of users. Motherboard reports: Hackers were able to scrape the email addresses and other data of more than 90,000 GETTR users. On Tuesday, a user of a notorious hacking forum posted a database that they claimed was a scrape of all users of GETTR, the new social media platform launched last week by Trump's former spokesman Jason Miller, who pitched it as an alternative to "cancel culture." The data seen by Motherboard includes email addresses, usernames, status, and location. One of the people whose email is in the database confirmed to Motherboard that they are indeed registered to GETTR. Motherboard also verified the database by attempting to create an account with three email addresses that appear in the database. When doing that, the site displayed the message: "The email is taken," suggesting it's already registered. It's unclear if the database contains the usernames and email addresses of all users on the site. Alon Gal, the co-founder and CTO of cybersecurity firm Hudson Rock, found the forum post with the database. "When threat actors are able to extract sensitive information due to neglectful API implementations, the consequence is equivalent to a data breach and should be handled accordingly by the firm and to be examined by regulators," he told Motherboard in an online chat.
Well, to be fair... (Score:2)
Hackers Scrape 90,000 GETTR User Emails, Surprising No One
The people at GETTR were probably surprised (otherwise they knowingly and willfully put deficient code online) ...
Re: Well, to be fair... (Score:3, Interesting)
I just registered... first time I heard about it.... thanks to the leak
Good point! (Score:1)
I just registered... first time I heard about it.... thanks to the leak
For online services all news is good publicity! Just look at the success of Twitter and Facebook where you would have thought a company would be wrecked ages ago by bad publicity...
Re: (Score:3, Interesting)
I just registered... first time I heard about it.... thanks to the leak
For online services all news is good publicity! Just look at the success of Twitter and Facebook where you would have thought a company would be wrecked ages ago by bad publicity...
I trust that was sarcasm? The lunatic right has been having some issues with their social media platforms recently.
Although, a honeypot social media would be a good way to keep track of them.
Re: (Score:3, Insightful)
Re:Good point! (Score:4, Insightful)
Yes, both twitter and facebook have had their controversies that generated bad publicity.
However, through their services, they managed to get and lock in a huge user base way before they were struct with any major controversy.
(At least none that the general public cared about. People like myself have been warning others over data privacy issues for decades now, but for the most part we've been called paranoid and conspiracy theorists).
You could say they were already 'too big to fail' in the eyes of the majority of their user base, when they were hit with bad publicity. Hence their user base, who was convinced that they need those platforms bailed them out again.
Here I'd argue that those platforms kept being successful despite bad publicity, not because of bad publicity.
I'm not sure if this is given for new platforms. We'll have to see how that pans out.
Re: Well, to be fair... (Score:4, Insightful)
Re: Well, to be fair... (Score:5, Interesting)
I hope you used fake data and a disposable email address.
The site is rather poorly developed and full of exploitable weaknesses. Take this account as an example:
https://gettr.com/user/RealAdo... [gettr.com]
It's got a tick (which isn't just Unicode attached to the name) so it's been "verified" to be the "real" Adolf Hitler somehow. Either the site operators are untrustworthy and will verify accounts as a joke, or the system is easily hacked and you can't be sure any verified account is really who they say they are.
Re: (Score:2)
The people at GETTR were probably surprised (otherwise they knowingly and willfully put deficient code online) ...
Nah, it was probably them that did it. They have to get this thing in the news headlines as much as possible.
They got 90000 users? (Score:1)
That surprised me..
Re:They got 90000 users? (Score:4, Insightful)
Nah, about 200 users and 89800 sock puppet accounts for shills.
Re: (Score:2)
Re: (Score:2, Flamebait)
Early on some accounts were showing 250k+ followers. They have clearly been fiddling the stats to make the site look more popular than it is.
Re: (Score:2)
I got modded down to zero in the last GETTR thread here for cracking joke it should be called "GUTTR" in response to articles exposing that they were scraping old tweets to fill in content and their security was crap.
I wonder where those brave, silent mods are today.
Re: (Score:2)
Give 'em time, they just woke up and modded me Troll.
It's still early in Trumpistan.
CFAA (Score:2, Troll)
Isn't that a violation of the Computer Fraud and Abuse Act of 1986?
Re: (Score:3, Insightful)
Isn't that a violation of the Computer Fraud and Abuse Act of 1986?
Yeah, but the Computer Fraud and Abuse Act of 1986 is overreaching legislation implemented by a corrupt and false government and true Libertarians should resent the government making laws about what people can and can't do.
Re: (Score:3, Informative)
Re:CFAA (Score:4, Insightful)
The Supreme Court just handed down a ruling that limited the application of CFAA in cases like that. Under the logic in Van Buren v. United States, using that kind of email registration test is almost certainly authorized, but grabbing the database through an API without permission would be illegal.
Re: (Score:3)
but grabbing the database through an API without permission would be illegal.
Yep. But laws aren't there to protect people that we don't like! Get with the program.
How are they hackers? (Score:4, Interesting)
Even the tortured interpretation of CFAA that the government liked to use to make open API calls sound like federal crime has been out the window for more than a month now, with the SCOTUS decision in Buren. Sloppy journalism.
Re: (Score:2)
Moreover, why would anyone outside the US give a fuck about the CFAA?
Re: (Score:3, Informative)
The API should not be giving out information like email address and date of birth in response to random requests.
Clear GDPR data breech, but since I was not registered on the site I cannot make a complaint. I looked at it but some of the stuff it recommended made me not want to sign up.
https://i2.wp.com/boingboing.n... [wp.com]
Well now (Score:2, Funny)
It's a good thing other online services never make these kinds of mistakes!
Re: (Score:2)
It's a good thing other online services never make these kinds of mistakes!
Yes, but we're not discussing other services. This thread is about that steaming shitpile called gettr or whatever it is. Don't be a smoothed-brain whataboutism-touting moron.
An updated tutorial about whataboutism (Score:1)
OK ladies and gentlemen, here is an updated tutorial to teach you how to successfully use "whataboutism" to protect your delicate little ears from harmful words that might hurt your brain.
Whenever you hear something you don't like, simply ask, "But whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout, whatabout," and so on, until the other pers
Re:Well now (Score:4, Funny)
It seems odd the American extreme right named their social media platform after a gay hookup app.
Or maybe not?
Re: (Score:2)
How many services do you know that were breached within days of launch?
Re: (Score:3)
Looks like as soon as politics are involved, security is fucked.
Maybe we shouldn't let politicians near the internet. It's better for the safety and security of all of us.
honeypot (Score:2)
C'mon obvious honeypot. Pooh figured this out for us. "I'm just a little black rain cloud, hovering under the honey tree."
Oh bother. I'm so rumbly in my tumbly. Could you spare a small smackerel?
Re: (Score:2)
C'mon obvious honeypot. Pooh figured this out for us. "I'm just a little black rain cloud, hovering under the honey tree."
Oh bother. I'm so rumbly in my tumbly. Could you spare a small smackerel?
I know - a honeypot would be great - but damn - Trump shut his font of wisdom down, Loyal Lindell is having real problems with his so called Free Speech site, and GETTR has 90K users? A good number that are probably law enforcement. Damn, this group is hardly the overwhelming sea change claimed.
Oh well, they need tracked in case they want to "tour" Washington again.
Re: honeypot (Score:1)
Them interwebs are too hard for the Trumpholes (Score:5, Funny)
In other news, GITTR is also being spammed by lefty trolls with Sonic the Hedgehog Furry Porn, [kotaku.com] who claim their posts are protected by Free Speech.
Film at 11.
Re: (Score:2)
I can pretty much promise you that the "gettr" technical work wasn't the work of a bunch of similarly-minded conservatives or "liberal-haters" or whatever you're saying. I'm sure the coding was just bought at market prices by whomever was selling, and politics had nothing to do with any of that.
Re: (Score:2)
GETTR markets itself as "the marketplace of ideas" (and appears on the 2nd page of google results here, so I guess the marketplace has spoken), but like most of the other sites claiming to be a haven for open and free debate it's actually just full of trolling and bile that makes any nuanced discussion impossible.
Um (Score:4, Insightful)
who pitched it as an alternative to "cancel culture."
So the concept of "cancel culture" is crazy and has to be put in scare quotes ... say the people celebrating the successful hacking attack on a speech platform they don't like, lol
Re: (Score:1)
who pitched it as an alternative to "cancel culture."
So the concept of "cancel culture" is crazy and has to be put in scare quotes ... say the people celebrating the successful hacking attack on a speech platform they don't like, lol
Yeah - but Republicans are just as good at cancel culture, so the argument is pretty null.
References provided on request, but big boys use their google fu.
Re: (Score:2)
When was the last time Repubs instigated violence to shut down their oppositions political rally? [chicagotribune.com]
Somehow, boycotting and the tactic of slandering someone to their employer to get them fired doesn't seem to be equivalent.
Re: (Score:2)
When was the last time Repubs instigated violence to shut down their oppositions political rally? [chicagotribune.com]
Somehow, boycotting and the tactic of slandering someone to their employer to get them fired doesn't seem to be equivalent.
Republicans tried to take over congress, Erected a gallows to hang Pence - threatened to kill Nancy Pelosi, and Cortez, and killed a cop.
Those are facts - if you don't believe them, you are one of them, and supported the putsch
Re: (Score:2)
Wait, people still believe the "killed the cop" lie after all publications who printed that lie were forced to retract it?
Re: (Score:2)
'take over congress', yeah keep up the hyperbole for what would been a 'mostly peaceful protest' under any other circumstances.
Here's your gallows. [shutterstock.com] I guess they were supposed to saw Pence's legs off first to get it to work.
Of course the narrative surrounding officer Sicknick who died of an unrelated stroke was a complete lie, because of course it was.
If being one of them means I'm opposed to bullshit liars on the left, then count me in.
Re: (Score:2)
Re: (Score:2)
Yup I'm the guy who receives projection after proving what a lying scum fuck you are. Thanks for being consistent and predictable.
Re: (Score:2)
Yup I'm the guy who receives projection after proving what a lying scum fuck you are. Thanks for being consistent and predictable.
Yes, yes indeed. No projection here, Cletus. Just having fun getting you triggered. Not at all surprising.
But tell me, were you upset when your guy called you low class during your peaceful tourist action? https://www.politicususa.com/2... [politicususa.com]
Re: (Score:2)
The irony is that the people most critical of Trump's honesty and that of the Republicans prove themselves to be even less trustworthy to anyone capable of thinking for themselves.
Enjoy lapping up your hyper partisan brazen propaganda and then regurgitating it here. I'm sure it makes you feel good.
Re:Um (Score:5, Insightful)
who pitched it as an alternative to "cancel culture."
So the concept of "cancel culture" is crazy and has to be put in scare quotes ... say the people celebrating the successful hacking attack on a speech platform they don't like, lol
Remember the old "won't someone think of the children!". Their problem isn't with the cancellation in "cancel culture", it's with the fact that they're not the ones dictating who gets cancelled.
As for the successful hacking, a huge part of the narrative among conservatives is the idea that there's all these uber-competent conservatives on the far right who are being unjustly silenced by the mainstream media. The fact that their amateurish Twitter alternatives keep getting hacked, and their sketchy political stars keep getting indicted, is evidence that these far right conservatives are a few coconuts short of a cargo cult. When Ben Shapiro is counted as an intellectual giant in your movement you need to watch that you don't hit your head on a doorstop.
Re: (Score:3)
"Cancel culture" is just a scary way of saying "freedom of association".
Re: (Score:3, Insightful)
"Cancel culture" is just a scary way of saying "freedom of association".
Freedom of association + doxxing + confrontation at restaurants + ...
Slogan (Score:2)
Their slogan: "Join and Gettr personal data scraped"
Re:Slogan (Score:5, Funny)
I thought it was "Gettr done!"
No, it is 'Gettr: Done.'
What did you expect? (Score:3)
In best private business tradition, it's made by the lowest bidder.
Status? (Score:1)
A question about "From the desk of Donald Trump" (Score:1)
People keep claiming that Trump's blog got zero traffic. How do we know that at all? It's not that the stats were publicly published..
PS: You can read the old blog here [archive.org]. I wonder how come it's still working even when the JavaScript is running from archive.org instead of the original site.
Re: (Score:2)
scraping ? (Score:1)
To be fair... (Score:2)
Gettr? Who names this stuff? (Score:2)
Honestly. "Gettr" sounds kind of rapey. Next thing you know Trump will try and crowdfund a trip to London and name it "Going to Pound Town".
Re: (Score:1)
If I want to hear from an asshole I'll just fart.