Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…
Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.
GitHub censored my research data
81–90 of 206 posts
Re: GitHub censored my research data
#82I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…
Twitter is better. Warned users are the best motivation to fix.
Re: GitHub censored my research data
#83Earlier quoted context omitted.
And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.
You mistook "free and accessible" with "public". You may exercise freedom of speech but not on server that belongs to a private company - it is their right to limit what kind of content they like. But in an essence you are right - companies should exist to benefit society, but it is not how it exactly works right now.
Re: GitHub censored my research data
#84Re: GitHub censored my research data
#85Earlier quoted context omitted.
I edited my post, but I don't think that's really fair. The business most likely outsourced the development of their site to someone who probably assured them that they would build a secure site. The business probably trusted them (maybe the developer was even recommended) yet here we are. The business didn't know enough about building a secure website, so hired someone they assumed did. Edit - Poor analogy removed.
A solution to this is to hire a pentester for your site. You can find them for ~$5k, with followup tests for new features being around $2k. A professional, world-class pentest runs around $50k, but a lot of smaller sites can't afford that. You can't really hire someone with the expectation that they'll develop secure code. Finding flaws in code people thought was secure is a pentester's job, and it's a completely dif…
Re: GitHub censored my research data
#86Earlier quoted context omitted.
And even if it were (a list of vulnerable systems, that is), why the fuck do they think that they should censor serious journalism? If you operate a public venue, then it is an important societal role of journalism to report on it if that public venue poses a risk to the public, whether that might also have negative consequences for the people operating it is completely irrelevant.
Are they in the business of journalism? Lots of people are saying "But the sites are already exploited" ... they are probably still exploitable further also, and GH/GL don't want to be at that party.
This is not about whether they are legally required to do anything, but whether what they are doing is responsible behavior.
Re: GitHub censored my research data
#87Have you thought about contacting Adblockers or even Browsers? They might be interested in this data to block the sites for the average Joe.
7. I have, prior to publication, submitted all URLs and malware samples to Google’s Safe Browsing team. They have since only acted upon a small portion of the sites.
Re: GitHub censored my research data
#88Do this kind of thing on your own domain. I have a list of major sites with currently active phishing pages.[1] This is basically a join of PhishTank and DMOZ. Nobody seems to be upset by that. Google is at the top of the list because of their hosting business. It's not just Google Sites. You can put a web site in a Google Spreadsheet cell, which Google doesn't seem to check as a possible phishing site. If you host f…
Okay, so assume he hosted the list himself and is now DDoS'd. Now what? I'll give you a budget of $100 a year.
Game servers become hot targets by kids who just don't care and do anything to get your server taken down, whether it be competition or a user got banned or just about any reason they can sum up to try and find any given approach to take your service down.
Edit:
Forgot to mention the free CloudFlare option as well (unless they stopped doing this, haven't had to deal with these things in a few years, but I have a feeling it's still about the same, there's likely even more offers now out there).
Re: GitHub censored my research data
#89I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…
They are putting their users at risk through negligence. Many would argue that's wrong.
Re: GitHub censored my research data
#90Earlier quoted context omitted.
A solution to this is to hire a pentester for your site. You can find them for ~$5k, with followup tests for new features being around $2k. A professional, world-class pentest runs around $50k, but a lot of smaller sites can't afford that. You can't really hire someone with the expectation that they'll develop secure code. Finding flaws in code people thought was secure is a pentester's job, and it's a completely dif…
I agree, but my point is the people who hired the developers probably don't even know what a pentester is.
https://news.ycombinator.com/item?id=12309035 is informative. For what it's worth, it changed my mind on the matter.