Live data from Hacker News

“I will slaughter you”

daniel.haxx.se

91–100 of 265 posts

Re: “I will slaughter you”

#91

> That code is used to root and exploit people. That comment made me think and I realized the following. Open-source code like curl is inevitable when a society gains internet [1]. It's not Daniel's fault. If anything is to blame, blame the internet and human nature on a grand scale [2]. [1] If he wouldn't have made it, someone else would. If no one else would, then people would've done it privately. Some of that cod…

Uh... I mean, you don't really think that person has an accurate understanding of what actually happened? Because I'm having a hard time trying to imagine that. It's not that there aren't any vulnerabilities in curl that can be exploited that way, but I struggle to think of situation where curl would have been an actual culrprit. Also, it sounds like he thinks curl is something purposefully malicious.

On the matter of "inevitability of progress": yep, I even think it applies to much bigger extent. I just don't see how is this connected to the troubles of the-victim-of-curl guy.

Re: “I will slaughter you”

#92

> That code is used to root and exploit people. That comment made me think and I realized the following. Open-source code like curl is inevitable when a society gains internet [1]. It's not Daniel's fault. If anything is to blame, blame the internet and human nature on a grand scale [2]. [1] If he wouldn't have made it, someone else would. If no one else would, then people would've done it privately. Some of that cod…

off point

> if there is a 1 in a 500 million chance that something could happen based on a small piece of text, it means that at Twitter, it happens every day.

really interesting, do you remember what interview/who the employee was or anything?

Re: “I will slaughter you”

#93

The general demeanor of that person, some of the lingo used like "rooting" or "federal server hijacking", the fact that in the screenshot he's using some text editor with ads in it to browse the offending code combined with the fact that he doesn't know what Curl is (if he did he wouldn't have sent this e-mail) screams "script kiddie" to me. I'm not sure whether this person is actually responsible for a multi-million…

I thought that the ads are from Daniel's email client. Not that it detracts from your point.

Re: “I will slaughter you”

#94
post #12

This feels to me like a person with some sort of mental illness or breakdown and delusions of grandeur and persecution. Their explanation doesn't make much sense. If I were Daniel, I wouldn't respond any further.

He already responded by revealing the email and real name of the person, presumably without consent, aka doxxing.

as I understand he assumes that it is actually a throwaway account and fake name.

Re: “I will slaughter you”

#95
>As an open source maintainer since over twenty years, I know flame wars and personal attacks and I have a fairly thick skin and I don’t let words get to me easily. It took me a minute to absorb and realize it was actually meant as a direct physical threat. It found its ways through and got to me. This level of aggressiveness is not what I’m prepared for.

Posting this is just an open invitation for people to send you more threats.

Re: “I will slaughter you”

#96
post #75

Earlier quoted context omitted.

Yeah, I agree. In his place, I either would have done nothing, or, maybe made a police report (not that I'd expect the police to actually do anything at this stage). Generally speaking, the less you antagonize someone whose first exchange with you is "I will slaughter you," the better, IMO.

I once tried to have a conversation with a women who tried to drive me and my bicycle off the bus lane (where she shouldn't be driving in the first place); and shouted "fuck off you pissy little cunt" to me. For some reason I thought that if I explained my perspective, she would understand. It ended up with a broken back wheel (she kicked it) and a damaged phone (she took it out of my hand when I wanted to take a pic…

A sad sentiment of giving up, but I think it is premature to abandon your approach. I think it may be worth trying for that small-ish fraction (call it 10%?) of people who can be talked back from their anger. Those are good conversations to have for both parties, and worth trying to have, even if it results in failure 90% of the time.

That said, I think the real lesson for you is: don't make yourself more vulnerable (e.g. letting her touch you or your stuff) if you decide to try to start a conversation!

It also points to a theory I've been considering about personhood, and how people like your driver lady is in a mindstate where, in her mind, you're not a person. It's a very, very dangerous situation, because if they don't think you're a person, then there is nothing immoral about saying or doing anything to you, including violence.

Re: “I will slaughter you”

#97

This reminds me of the OK city manager threatening Centos developer - https://www.theregister.com/2006/03/24/tuttle_centos/ Although in that case the city was not actually hacked. It looks like this person actually got hacked by someone using curl and he is complaining that curl made it possible. I wonder if he knows anything about the people who wrote the actual exploit(s).

A bit like the time the scientology lawyers were desperate to find out who was running that server at 127.0.0.1 that had all their files on it, and really really wanted to find the person who was using the 'majordomo" login so that they could depose them

Re: “I will slaughter you”

#98

There are two things wrong here: The person saw some exploit with curl headers, which damaged their life. That's upsetting, even if the email is misdirected, because Daniel just provided the infrastructure, and did not cause the specific abuse. What is wrong is the threat to life. The second thing that is wrong is to respond to the second email by doxxing the author to the public. The second email showed that the thr…

[deleted]

Re: “I will slaughter you”

#99
post #66

Earlier quoted context omitted.

He already responded by revealing the email and real name of the person, presumably without consent, aka doxxing.

That isn’t doxxing. You have no expectation of privacy if you send a threatening letter to another person.

And you base that on what? At least where I live I can't even record a phone conversation without informing the other party, much less divulge it...

Re: “I will slaughter you”

#100
post #91

> That code is used to root and exploit people. That comment made me think and I realized the following. Open-source code like curl is inevitable when a society gains internet [1]. It's not Daniel's fault. If anything is to blame, blame the internet and human nature on a grand scale [2]. [1] If he wouldn't have made it, someone else would. If no one else would, then people would've done it privately. Some of that cod…

Uh... I mean, you don't really think that person has an accurate understanding of what actually happened? Because I'm having a hard time trying to imagine that. It's not that there aren't any vulnerabilities in curl that can be exploited that way, but I struggle to think of situation where curl would have been an actual culrprit. Also, it sounds like he thinks curl is something purposefully malicious. On the matter o…

Oh, the statement just made me pause and think that's all.

> but I struggle to think of situation where curl would have been an actual culrprit.

I agree, I think it's much more likely that there was a 2 stage type of exploit where curl was used to download the second stage locally on the machine. That's at least how curl (or wget) is used on hackthebox.eu (where everyone hacks boxes for fun).

Post reply on HN