Salma Typhii
A
I get that a breach is never good just like breaks in infection control are never good, but how much, realistically, can someone do with what data Spoutible has of mine? Yay, you found my throw-down email and phone number 🤷🏻‍♀️
Isa-Lee Wolf @IsaLeeWolf
So I was on the bad site for a second, and found this.

And now I am torn between pointing out that Christopher didn't write it, I did, and not stepping my toe in the fetid waters of twitter.
10:41 AM - Feb 06, 2024
10:51 AM - Feb 06, 2024
Avatar Avatar Avatar
0
45
13
Isa-Lee Wolf
A
In response to Salma Typhii.
EXACTLY!!

And I don't think anyone was actually hacked, I haven't seen anything confirming it.
11:06 AM - Feb 06, 2024
2
11
Salma Typhii
A
In response to Isa-Lee Wolf.
As far as I could tell it was more of a proactive, white hat, hack where a security expert found a flaw, alerted the Spoutible team, who then alerted us? You know, the way computer security should work
11:10 AM - Feb 06, 2024
1
12
Dan Nguyen
A
In response to Salma Typhii.
I don’t think that’s the case. Someone contacted Troy Hunt alerting him to the existence of the file of 207k records. It’s likely they saw the data being sold on the black market and told Hunt about it. Why would a white hat researcher scrape all 200k records before notifying security experts?
11:55 AM - Feb 06, 2024
2
3
Isa-Lee Wolf
A
In response to Dan Nguyen.
Where did you get the data being sold on the dark web from that excerpt?

It very clearly says that the person who "found" the vulnerability reached out to Hunt.

Not the data.

The vulnerability.
12:11 PM - Feb 06, 2024
1
1
Dan Nguyen
A
"Where did you get the data being sold on the dark web from that excerpt?"

To get 207k user records (i.e. the entire active userbase), you would have to scrape the API 207k times. This isn't hard, but it also isn't "white hat" behavior — hitting the API just ONCE would prove the vulnerability
In response to Isa-Lee Wolf.
12:14 PM - Feb 06, 2024
1
5
Isa-Lee Wolf
A
In response to Dan Nguyen.
So from nowhere in the article. You just made it up based on how you think they may have come to that number.
12:15 PM - Feb 06, 2024
1
2
Dan Nguyen
A
In response to Isa-Lee Wolf.
The notifier sent Hunt "a file with 207k scraped records". You're right, it's possible someone did all that work (which would risk exposing them to criminal investigation) and told Troy about it, out of the goodness of their heart.

The more likely case is this person found the file, then told Hunt
12:19 PM - Feb 06, 2024
1
0

 

{{ notificationModalContent }} {{ promptModalMessage }}