Welcome Guest

an aside about Parler

Posted on: January 22, 2021 at 16:09:12 CT
ashtray UF
Posts:
111045
Member For:
22.63 yrs
Level:
User
M.O.B. Votes:
0
never use the platform

Here is a list of their security failures:

1. No API authentication. Anyone could easily scrape data without logging in or having an account

2. Soft-delete messages and posts, and include them in the public API for everyone to see, and yes, that includes private messages between individuals.

3. Geolocation tags are still present in the media files, showing where the device was located when the media was created.

4. Message and Post IDs are sequential integers instead of using a UUID or GUID, making it trivial to scrape every single message and post via the public API

Sounds like a sample project escalated to production
Report Message

Please explain why this message is being reported.

REPLY

Handle:
Password:
Subject:

MESSAGE THREAD

     RE: House leader calls for FBI investigation into Parler - MOCO SON MU - 1/22 16:37:39
     an aside about Parler - ashtray UF - 1/22 16:09:12
          Or a conspiracy mind would say it sounds like a place - TigerMatt STL - 1/22 16:13:59
               RE: Or a conspiracy mind would say it sounds like a place - ashtray UF - 1/22 16:14:42
          What do you recommend? - escalade MU - 1/22 16:12:53
               Tigerboard (nm) - ashtray UF - 1/22 16:13:21
          Sounds perfect for Trump and the boyz. (nm) - Newcatbirdseat MU - 1/22 16:12:09
     nothing on all the other riots, yet - fatrat MU - 1/22 16:03:35
     That b*tch is a man baby(nm) - Kushy MU - 1/22 16:01:52
     It’s over (nm) - pickle MU - 1/22 15:55:42




©2025 Fanboards L.L.C. — Our Privacy Policy   About Tigerboard