Live data from Hacker News

GitHub censored my research data

gwillem.gitlab.io

81–90 of 206 posts

Re: GitHub censored my research data

#81
post #61
post #60

Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…

Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.

I don't believe that gitlab's offered service is "DDoS Protection"

Re: GitHub censored my research data

#82

I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…

>send an automated email if malware is detected, and include links explaining how to fix it

Twitter is better. Warned users are the best motivation to fix.

Re: GitHub censored my research data

#83
post #73

Earlier quoted context omitted.

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

You mistook "free and accessible" with "public". You may exercise freedom of speech but not on server that belongs to a private company - it is their right to limit what kind of content they like. But in an essence you are right - companies should exist to benefit society, but it is not how it exactly works right now.

You mistook gitlab for webshops with malware.

Re: GitHub censored my research data

#85

Earlier quoted context omitted.

I edited my post, but I don't think that's really fair. The business most likely outsourced the development of their site to someone who probably assured them that they would build a secure site. The business probably trusted them (maybe the developer was even recommended) yet here we are. The business didn't know enough about building a secure website, so hired someone they assumed did. Edit - Poor analogy removed.

A solution to this is to hire a pentester for your site. You can find them for ~$5k, with followup tests for new features being around $2k. A professional, world-class pentest runs around $50k, but a lot of smaller sites can't afford that. You can't really hire someone with the expectation that they'll develop secure code. Finding flaws in code people thought was secure is a pentester's job, and it's a completely dif…

I agree, but my point is the people who hired the developers probably don't even know what a pentester is.

Re: GitHub censored my research data

#86
post #71

Earlier quoted context omitted.

And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.

Are they in the business of journalism? Lots of people are saying "But the sites are already exploited" ... they are probably still exploitable further also, and GH/GL don't want to be at that party.

Would they be required to publish this story if they "were in the business of journalism"?

This is not about whether they are legally required to do anything, but whether what they are doing is responsible behavior.

Re: GitHub censored my research data

#87

Have you thought about contacting Adblockers or even Browsers? They might be interested in this data to block the sites for the average Joe.

From the article:

7. I have, prior to publication, submitted all URLs and malware samples to Google’s Safe Browsing team. They have since only acted upon a small portion of the sites.

Re: GitHub censored my research data

#88
post #61
post #60

Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…

Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.

Well there is Frantech / BuyVM. We had a VM we used as a proxy for about $15 a year + the $3 IP DDoS filtering. We had several proxies on top of our Limestone Networks server (they didn't offer protection at the time - still this is cheaper).

Game servers become hot targets by kids who just don't care and do anything to get your server taken down, whether it be competition or a user got banned or just about any reason they can sum up to try and find any given approach to take your service down.

Edit:

Forgot to mention the free CloudFlare option as well (unless they stopped doing this, haven't had to deal with these things in a few years, but I have a feeling it's still about the same, there's likely even more offers now out there).

Re: GitHub censored my research data

#89

I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…

> It won't resolve everything but it's a lot nicer than naming&shaming businesses who have effectively done nothing wrong.

They are putting their users at risk through negligence. Many would argue that's wrong.

Re: GitHub censored my research data

#90

Earlier quoted context omitted.

A solution to this is to hire a pentester for your site. You can find them for ~$5k, with followup tests for new features being around $2k. A professional, world-class pentest runs around $50k, but a lot of smaller sites can't afford that. You can't really hire someone with the expectation that they'll develop secure code. Finding flaws in code people thought was secure is a pentester's job, and it's a completely dif…

I agree, but my point is the people who hired the developers probably don't even know what a pentester is.

Yes. A lot of them also respond with threats when you try to contact them to tell them about vulnerabilities. It's not really up to the author to shoulder that kind of responsibility.

https://news.ycombinator.com/item?id=12309035 is informative. For what it's worth, it changed my mind on the matter.

Post reply on HN