Gab got hacked again 📦

172    08 Mar 2021 20:18 by u/ManInTheMiddle

https://poa.st/notice/A50ih7kAya8OBGvnMG https://gab.com/

72 comments

90
Man, that sucks. I'm getting sick of all the bullshit hacks lately. "Hacktivism" was cool when it was faceless corporations. Torba's just one guy (and a small team) against the world.
51
Hopefully gab figures it out and stabilizes things.
30
yeah i hope gab can figure out how to implement basic security into their website with over 10 million users
51
Seriously pathetic. He's trying to expand servers, fix bugs, raise capital, deal with all the bank deplatfomings, fight hacking, etc. all at once with a team of like 5. When the pendulum swings our way we have to remember this.
37
Remember- when you have your boot on its neck, or a gun to its temple, remember. They want us dead. They think this shit is funny. Show no remorse
5
Exactly. The left sees us as the antithesis to everything they believe in, and they'll stop at nothing to destroy us and ruin our lives.
19
This is why they need to slow down and get focused. They are trying to do too much at once, like buying a fucking bank. They need to just focus on making a tight website first. That being said I love Gab, and wish it all the best.
11
Their priorities should be: 1. Get a bank (because without that, they can't fund anything.) 2. Secure the website by hiring top-notch security professionals. 3. Do whatever you want.
4
lol just casually saying "Get a bank". Do you know how much time, effort and red tape is involved in operating any financial institution? They need to start naming the banks who are refusing them so we can go after them. The left does it, the right can apply the same pressure.
1
I know. But my point was it should be their top priority.
79
And it’s always the conservative websites that get attacked. They don’t want you having anywhere to speak freely.
40
that's how censorship works. ruqqus is small enough to fly under the radar for now, but that'll change when they finish dusting off the big boys appreciate your time with the shitposters while you have it, there might not be any left tomorrow
16
We'll always have /pol/, the eternal honeypot that's too big to fail (tm).
12
Honestly since Ruqqus is so slow with new headlines (compared to TD or plebbit), I find myself spending way more time in /pol/ lately.
7
I keep getting short global bans for being a shitposter. My last one was for 3 days, because I didn't know it was against the rules to admit to trolling outside of /b/. Fuckin' jannies.
6
Don't kid yourself. The major platforms have 1000x the target on their backs. It just turns out that sites like Gab and the boomers that make them have poor OPSEC.
1
Found the glowie.
2
He isn't wrong, Gab has poor OPSEC.
38
They really need to get their security together.
39
true. but it's like the entire world is weighing down on new start-ups. How can any website flourish under these circumstances; In this environment? Torba and Gab are struggling and they are relatively speaking massive. What if they came after Ruqqus? Or hell, Ruqqus a year ago when it was a wee baby? Especially with the massive campaign to deplatform Gab. Banks cutting off their services, PayPal refusing to host them, targeted communities on Reddit (/r/GabWatch) meticulously acting to destroy it. "Build your own platforms" it ain't right. Gab's not struggling because of security issues, Gab is struggling because an absolutely massive mob are trying to eliminate it. If they went after any website with the veracity they go after websites like Gab they would fall too. I'm developing my own website and this terrifies me. I'm not a fucking security consultant. I don't have tons of resources to invest into one either. I just want to speak
15
Part of it is that all software sucks, and hardware mostly sucks too. People (including me) make fun of the "rewrite it in Rust" crowd but there's something real behind that sentiment. We need to be moving things to safer tools with fewer footguns.
7
Any suggestions for developing a small website? Would you suggest writing new websites in Rust? It just seems like these attacks are so sophisticated, and overwhelming.
22
For starters, *don't fucking store passwords in plaintext*, which, if the hack message is to be trusted, appears to have been part of the problem.
5
Wait what? Storing passwords in plaintext is an automatic unforgivable fail. Honestly even unsalted hashes is a huge fail imo. I've actually changed doctors in the past because when I hit "forgot password" on the patient portal they just emailed me my password.
3
I don't think the passwords to accounts were stored as plain text >While the passwords of private groups were not encrypted, those of individual users did have a cryptographic hash https://techbriefly.com/2021/03/02/gab-was-hacked-the-hacker-threatened-to-leak-private-data-of-15-000-users/
4
The hack message mentions "7k passwords"
2
It depends on what your site is like, and how it needs to work. If it's something like a blog or publication, you should use a static site. Static site generators like Hugo and Jekyll take folders full of simple Markdown files and turn them into a fully themed HTML site. These are cheaper to run than traditional websites and can't be hacked since there is no code running on the server. If your site needs dynamic server-generated content and you can't use an existing well-regarded engine then you might look into using Go. It's very fast, easier to learn than Rust, and fairly safe.
2
I was just doing a deep-dive into Hugo, very cool. I guess you're right I don't necessarily need a dynamic website.. at all! Thanks for your advice! Going down the hugo path would probably be easier but I kind of want to learn HTML/CSS tbh. I also want to construct it from the ground up. That being said, something like Apache would be incredibly cost effective for loading a basic static page, which is my intention.
2
In that case you could start with HTML/CSS (for the learning) and get a basic site up, then see if you can turn your creation into a custom Hugo theme. Then you have full control. The main advantage of static site generators like Hugo is that you can easily make changes to huge parts of your website by changing a configuration file and running a single command to rebuild the whole site.
2
> Torba and Gab are struggling and they are relatively speaking massive. They didn't have proper security measures in place. Ruqqus does.
30
Scumbags even have the cynism to virtue-signaling. They probably asked those 5 btc as ransom and then claimed Torba *doesn't care* because he didn't pay. WE DON'T NEGOTIATE. This is morals, something that these entitled fucking retards will never know.
17
I'd be mad if he paid it, frankly.
10
Yep it would only encourage more attacks
7
And the hacker is talking as if 8 bitcoin is a minor price to pay. Checking on bitcoin prices right now, it's at over $53 thousand dollars a piece. That 8 bitcoin demand is equivalent to a ransom of over $424,000. That's not chump change.
22
These fucking bastards are relentless. They won't just silence you on their own platforms, they will systematically attack new platforms composed of users that just want to get away from them
19
And gab is down
16
What fucking moron: 1. Doesn’t use a throwaway email 2. Unironically submits identifying information to a website
13
Also, use a unique meaningless password with a manager like bitwarden so if one site gets compromised it means jack shit for any other account
5
I use short sentences in 1337.
7
+1 for Bitwarden, plus you can self-host.
15
They knew that the hashed passwords were taken, I have no idea why they did not force a password change for everyone. That is all they had to do, it was just a matter of time before someone cracked some and used them.
12
Cybersecurity, take that shit seriously
10
Fucking leftist trying to destroy any opposing site. First they took down Parler and forced their CEO out, now it's on to Gab.
9
It is crazy that not only liberal leftists but non libtards are happy too 🙄. Gab is operated by 6 user's only compared to tech giants twatter and FB.
8
Torba managed to piss a lot of people off. He can't secure his main product, but constantly announces new products: his own browser, his own Zoom clone and today his own Clubhouse clone. https://reclaimthenet.org/gab-hints-at-free-speech-clubhouse-competitor/
6
Well I agree with that but most of the tech giants are leftist operated and do endless censorship. If he comes out with the free speech alternative then there shouldn't be any problem. I like Gab but I don't use it's browser. Doesn't Google and FB have it's own different other apps and services? And about security yes it is a concern but twatter like platform can be hacked then Gab is still infant.
6
Coming Soon! **Torbank**
9
I love that Donald Trump caused all this. Sometimes, one person can create huge ripples.
-1
Trump is so divisive and detested he was — and is — the fuel on the left-wing extremist fire. The nation should hope he fades away as soon as possible.
8
> The nation should hope he fades away as soon as possible. Ah, yes, the populist should disappear so that we can return to the ""normal"" of the elites in Congress exploiting the people, and RINOs driving towards progressivism at the speed limit. Fuck off, neocon.
11
Trump didn't fuel the extremism, he just exposed it.
0
Fuck off neocon
-1
Ok Communist
8
Oof size: Mega
8
They got SQL injected in 2021 ROFL
8
Full message archived before Gab shut down: https://archive.is/mSYxk
7
large sites get hacked too: https://www.forbes.com/sites/zakdoffman/2020/04/20/facebook-users-beware-hackers-just-sold-267-million-of-your-profiles-for-540/
5
It's down now with a server error
5
maybe this will help gab in the long run and strengthen their security or they will give up which i hope they don't
4
It's just the Biden Administration reaffirming nobody likes them. Buncha short bus pan clankers.
4
hopefully they don't come after ruqqus to if they do just remember what they took from us when a great cyber civil war breaks out show them no mercy if we get lose make sure to put up a fight and lose with honor
3
Ok, so this is where all those spam emails came from. Getting a bunch of spam emails all of a sudden and this looks like a possible culprit.
3
pocketnet seems like the answer.
2
Caution needs to be taken when using these alternate sites. People really need to learn from places like Parler and Gab, no matter political affiliation.
2
Yup, at the very least: fake name, fake 10 min email.
2
I don't get it. I feel like hackers are smarter than that to be against a free speech platform such as Gab.
1
People that are into tech tend to be lefties. It doesn't even have that much to do with intelligence
2
That's embarrassing. Tough for them I'm sure, they basically have everyone and their nan going at them, probably at government level too, list be tough to defend against. That said, they know this, they should employ the best they can find to combat it.
1
https://ruqqus.com/+technology/post/89ux/andrew-torba-from-gab-addresses-todays
-12
They got owned
-14
get fucked lol