Oh, it is good.

https://twitter.com/hashtag/ParlerLeaks

https://twitter.com/hashtag/parlerhack

Post any good finds.

Best explanation I've seen why this is a big deal.

WordPress Config file being accessible is a big yikes. Gives you the destination for the DB as well as the username and password to sign into it. MySQL export and anything not using MD5 Hash is visible right away - the rest? Decrypt.

Soon as the DB has been exported, game over.

https://twitter.com/IckleIzu/status/1331401417186299909

  • aaaaaaadjsf [he/him, comrade/them]
    ·
    4 years ago

    Well you can use any email service, not just proton mail. The admins just recommend proton mail. They would have to take control of your email account as well I guess

    • ChapoBapo [he/him]
      ·
      4 years ago

      Sure, so they’d have to guess my email account. But they wouldn’t have to take control of both my chapo chat account AND my email account, they’d have to take control of my email only. Then they could reset my chapo password. So that’s why I said the email becomes the single point of failure - if that’s compromised, then everything’s compromised. So I shouldn’t use ChapoBapo@protonmail.com, but if I use a random unrelated email address and the attacker was specifically targeting getting access to my chapo chat account for ... some unknown reason then I can see how having the email would be an additional layer of protection.