Oh, it is good.

https://twitter.com/hashtag/ParlerLeaks

https://twitter.com/hashtag/parlerhack

Post any good finds.

Best explanation I’ve seen why this is a big deal.

WordPress Config file being accessible is a big yikes. Gives you the destination for the DB as well as the username and password to sign into it. MySQL export and anything not using MD5 Hash is visible right away - the rest? Decrypt.

Soon as the DB has been exported, game over.

https://twitter.com/IckleIzu/status/1331401417186299909

  • ChapoBapo [he/him]@hexbear.net
    link
    fedilink
    English
    arrow-up
    1
    ·
    5 years ago

    Chapo: Use protonmail to sign up, browse using a VPN, assume everyone is a fed including the admins

    Parler: Give us your SSN and driver’s license photo lmao

      • ChapoBapo [he/him]@hexbear.net
        link
        fedilink
        English
        arrow-up
        0
        ·
        5 years ago

        The admins were admonishing people to use a proton mail email to setup 2fa on here and I don’t really understand the benefit. This single-use email just becomes the SPOF instead of chapo chat so what’s the difference? I don’t use an email.

        • Lrak [he/him]@hexbear.net
          link
          fedilink
          English
          arrow-up
          0
          ·
          5 years ago

          Also: let’s say my profile gets hacked. What are they going to do? Post? Comment? It’s not like they can send themselves money or buy things in my name.

          • ChapoBapo [he/him]@hexbear.net
            link
            fedilink
            English
            arrow-up
            1
            ·
            5 years ago

            I was thinking about this too and it’s like unless you’re using the same username/password on here as your bank, the worst that could happen is they hijack a power poster’s reputation on here and use it to influence people in some kind of negative way, which is a lot of effort for what actual benefit and also why we shouldn’t have power posters.