Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
Privacy Security

Twitch Source Code and Business Data Leaked (therecord.media) 66

An unknown individual has leaked the source code and business data of video streaming platform Twitch via a torrent file posted on the 4chan discussion board earlier today. From a report: The leaker said they shared the data as a response to the recent "hate raids" --coordinated bot attacks posting hateful and abusive content in Twitch chats -- that have plagued the platform's top streamers over the summer. "Their community is [...] a disgusting toxic cesspool, so to foster more disruption and competition in the online video streaming space, we have completely pwned them, and in part one, are releasing the source code from almost 6,000 internal Git repositories," the leaker said earlier today. The leaker claims that the leak contains the "entirety of twitch.tv, with commit history going back to its early beginnings, mobile, desktop and video game console Twitch clients, various proprietary SDKs and internal AWS services used by Twitch, every other property that Twitch owns including IGDB and CurseForge, an unreleased Steam competitor from Amazon Game Studios, and Twitch SOC internal red teaming tools."

Twitch has confirmed the breach. In a tweet it said, "We can confirm a breach has taken place. Our teams are working with urgency to understand the extent of this. We will update the community as soon as additional information is available."
This discussion has been archived. No new comments can be posted.

Twitch Source Code and Business Data Leaked

Comments Filter:
  • Damn (Score:4, Informative)

    by gregarican ( 694358 ) on Wednesday October 06, 2021 @01:44PM (#61866815) Homepage

    Yeah it looks pretty legit. And pretty bad. Here's an initial analysis of some of the contents --> https://sizeof.cat/post/twitch... [sizeof.cat]. I'm thinking their team is busier than a one-legged man in an ass kicking contest right about now.

    • Re:Damn (Score:5, Informative)

      by phantomfive ( 622387 ) on Wednesday October 06, 2021 @01:49PM (#61866831) Journal

      If you want to know how much your favorite streamer is making, Here is the link [pastebin.com]. That's reportedly gross earnings from August 2019 to October 2021.

      • Jesus I went into the wrong profession....couple of million for streaming??!?!?
      • On of the most amazing parts of the data dump is how the GitHub repos for the DB-centric source code had the username/password credentials stored directly in the files. Any rookie knows how to reference them as server-side variables piped in from an .env file. The .env file is excluded/ignored from code commits and thereby harder to expose. Unbelievable. Glad I don't use this Twitch service, and have barely heard of it.

        • Yeah from that we can deduce that the source code is filled with security holes, because they aren't thinking about security at all.

        • At this scale you don't provision individual servers with env files. You put credentials in a centralize private key store (and then you need credentials for the store) and dynamically spin up server on the fly with automated scaling. It actually gets quite challenging to manage effectively and still give developers easy tools to work locally.

          Your point about not putting credentials in source control is spot-on though.

        • by cribb ( 632424 )

          Glad I don't use this Twitch service, and have barely heard of it.

          Justin.tv ring a bell then?

      • by AmiMoJo ( 196126 )

        Are these numbers right? Some of the streamers I know are making half a million, a million a year.

        Is that what's paid to them or before Twitch's cut and tax etc?

        • Streamers have said that it's accurate.

        • 1. That's revenue over the period of a bit over 2 years, accumulated - directly from Twitch.
          2. This doesn't include sponsorship deals, merch profits, Youtube profits (lots of streamers will post the VODs to YT), and all other sources of revenue outside Twitch itself, but accessible thanks to Twitch fame.

      • by djinn6 ( 1868030 )

        Does that include StreamLabs donations too or is it just revenue from Twitch itself?

        • Reportedly it's only the Twitch revenue.

          • I don't necessarily doubt you, but you've said "reportedly" twice now and provided no source.

            • You should doubt. I added "reportedly" specifically to indicate that I was unsure of my source.

              In these cases I'm quoting what streamers have said but who knows if they were accurate. Better information should come later.

            • by EvilSS ( 557649 )
              Twitch would have no idea what they earn from donations outside Twitch so no, it does not include Streamlabs or other donation systems.
      • Lines 185 and 186, proof the dark side is more popular than the light side

      • by AmiMoJo ( 196126 )

        Interesting comment on Twitter.

        "The #twitchleak is the top 10000 streamers. According to Google, Twitch has 9.2 million monthly active streamers. So the top 10000, is not just the top 1%, but the top 0.1%

        And 25% of that top 0.1% do NOT make minimum wage"

        https://t.co/9KeFK5PBZQ [t.co]

        Seems like a lot of the top streamers had either significant audiences or fame prior to starting. Most streamers never make any real money from the platform, and it usually takes years of grinding to get anywhere. Not a great career.

        • According to Google, Twitch has 9.2 million monthly active streamers.

          I don't think that's right. Everyone who has a Twitch account counts as a streamer. For example, I technically have a stream even though I have never done anything with it, but Twitch users can follow me and wait forever until the day I turn on my stream.

          Most streamers never make any real money from the platform, and it usually takes years of grinding to get anywhere. Not a great career.

          I do think that is true.

  • Chaotic neutral (Score:5, Insightful)

    by phantomfive ( 622387 ) on Wednesday October 06, 2021 @01:54PM (#61866849) Journal

    It warms the heart to see hackers leaking code for no reason than to create chaos and revenge. None of this "ransomware" or "get rich from hacking" nonsense.

    Do it for the love, not for the money.

    • Or the hate because the source code surely isn't going to change human behavior. Because if it could Linux would have us all hugging and singing kumbaya by now.

      • by tlhIngan ( 30335 )

        Or the hate because the source code surely isn't going to change human behavior. Because if it could Linux would have us all hugging and singing kumbaya by now.

        No, the problem is that Twitch has a griefer problem. They do nothing but disrupt streams spewing their crap, and Twitch has done little to nothing to fix the problem.

        Likely because the problem is in their platform.

        The goal of the source code leak isn't to make an open source twitch, it's to basically let everyone go through the code and cause proble

    • by suss ( 158993 )

      Surely it's a coincidence that facebook went down at about the same time... I wonder if we can expect a similar leak from there; zuckerberg would lose a lot more than 6 million dollars if that happened.

      • by lsllll ( 830002 )
        You mean 6 billion?
        • by suss ( 158993 )

          Can it be 60 billion this time? It's all meaningless anyway, since it's not real money, just facebook "value".

          • by lsllll ( 830002 )
            Well, it's real money to a certain extent. Not if he wanted to sell all his shares at the same time, but if he was to sell 5000 shares a day, he can cash out some of that money, at least until the investors realized what he was doing.
      • zuckerberg would lose a lot more than 6 million dollars if that happened.

        Maybe, but we've seen from many other times that getting hacked has no long-term impact on stock value. Equifax got hacked pretty bad but their stock is higher than ever (and the quality of their code hasn't improved).

    • Do it for the love, not for the money.

      I think the phrase is, "for the lulz," grandpa.

    • It warms the heart to see hackers leaking code for no reason than to create chaos and revenge. None of this "ransomware" or "get rich from hacking" nonsense.

      Do it for the love, not for the money.

      So you love people breaking into private property just for pseudo-principled shits and giggles. That people vote your dribble "insightful" is a sad indictment on slashdot users in general.

      • If you leave your door open, homeless people will wander in. Twitch left the door wide open.

        And it's still open.

        • If you leave your door open, homeless people will wander in. Twitch left the door wide open.

          And it's still open.

          Yes, that happens. That is still no reason to celebrate it. You are deeply broken. Get help.

  • Searchable list of top earners: https://www.twitchearnings.com... [twitchearnings.com]

    Atleast a decent channel is on top (Critical Role, DnD/RPG)

  • What are the chances there are undocumented APIs now vulnerable to attack (Hint: much, much greater than 0%) There are bound to be APIs made for special events or superstar streamers that are going to be instant targets now. This is going to be fun to watch.
    • by mysidia ( 191772 )

      There are bound to be APIs made for special events or superstar streamers that are going to be instant targets now.

      Well, if they're smart, then they may be available only to certain Client-IDs... I imagine a possibility that the near future Twitch may have a mass-invalidation of credentials and everyone has to generate tokens, followed by some serious audit work - or Amazon just stepping in to do a massive overhaul of their times.... Probably end users should expect to say goodbye to product develop

  • I clicked on a twitch link once - my fans immediately went full throttle and my CPU meter pegged. I just assumed it was malware / mining crypto / some other bullshit I don't want on my machine, and quickly closed the window.
    Never clicked on twitch link again...

    • No. First, the video is implemented worse than Youtube's - definitely higher CPU load. Also, chat filled with animated emotes going at a dozen lines per second can make a good CPU squeal. Never mind some streamers add "games" for the audience, played in Javascript, right over the top of the video stream.

  • Censorship (Score:2, Interesting)

    Any read on if or if not The Algorithm is suppressing certain creators or classes thereof?

  • This is a non-story. After all, it's only an Amazon service that was hacked. Nothing too worrying.

  • So we can now finally see how terrible Twitch's code really is?

Top Ten Things Overheard At The ANSI C Draft Committee Meetings: (5) All right, who's the wiseguy who stuck this trigraph stuff in here?

Working...