Live data from Hacker News

Wikimedia narrows down the app sendin 90M requests to a pic of flower

phabricator.wikimedia.org

101–105 of 105 posts

Re: Wikimedia narrows down the app sendin 90M requests to a pic of flower

#101
post #14

> it is a popular chat/social media mobile app used in India Indians of Hacker News, what are the likely candidates?

Considering that this seems to have been code accidentally left in while copy pasting from a tutorial, it's very hard to say, without doing the exact same investigation the Wikimedia team did. There are a lot of apps that have launched in India around that time frame with huge numbers of users thanks to nationalistic rhetoric. They are terrible apps, but they are made in India terrible apps, and that apparently is en…

> They are terrible apps, but they are made in India terrible apps, and that apparently is enough to get a large following in India of late.

That's awesome!

Every app has to start somewhere. I mean, even ISRO started by transporting rocket parts on bikes, and now has a satellite around Mars.

https://www.indiatimes.com/technology/science-and-future/fro...

Re: Wikimedia narrows down the app sendin 90M requests to a pic of flower

#103
post #64

Earlier quoted context omitted.

Nope. Starting from Android 10, unless an app has explicitly allowed user certificates (and no-one reasonably does, it's all behind a flag), you will not be able to MITM it. You may inject your certificates as much as you want. The only option is to have a device on which you have root access, which can push system certificates with adb. This pretty much only means the android emulator these days.

I don’t use Android so I wasn’t aware of that. But that’s a completely separate concern from cert pinning which does not hinder decrypting third party connections at all. Edit: after looking into this a bit, this is pretty nuts. How do enterprises inject certificates now?

re enterprise injection:

They don't. It's been made increasingly clear that allowing certs roots to infect unrelated apps is a Bad Thing. MDM profiles etc presumably allow internal certs to be deployed, but those are hopefully limited as countries, let alone companies, have attempted to use those mechanisms to spy on millions of people.

Re: Wikimedia narrows down the app sendin 90M requests to a pic of flower

#105
post #51

Earlier quoted context omitted.

Are you not tempted to just block the requests from these devices, and let the manufacturer take the loss? I imagine serving all those requests is costing real money.

It's not a TOS violation. It did cause us some ops pain at one point (they were getting hit with > 50,000rps concentrated in certain locations). But one of the reasons Cloudflare can operate our service is we have 3.2 million customers who are doing all sorts of stuff. We get so much stronger from that great variety of traffic.

Right. I'm sure you can explain more but I've read due to peering agreements and the like having a lot of one-directional traffic can be a good thing.
Post reply on HN