Live data from Hacker News

I managed to take down arbitrary posts on Hacker News

reverseengineeringtogether.wordpress.com

11–20 of 28 posts

Re: I managed to take down arbitrary posts on Hacker News

#11

"I'm bored, have dubious ethics and absolutely no restraint whatsoever, so, unsolicited, I'm going to help your site security without notice of my attack! Look what I did! Pay attention to me!" Looks like Hacker News owes this generous soul a massive debt of gratitude for all his hard work while they get familiar with U.S. Code Title 18 Section 1030, "Fraud and related activity in connection with computers."[1] [1] h…

Spot the fed was always a fun time at Defcon.

https://www.vice.com/en/article/ypw4wb/when-the-fbi-found-ou...

Re: I managed to take down arbitrary posts on Hacker News

#12

"I'm bored, have dubious ethics and absolutely no restraint whatsoever, so, unsolicited, I'm going to help your site security without notice of my attack! Look what I did! Pay attention to me!" Looks like Hacker News owes this generous soul a massive debt of gratitude for all his hard work while they get familiar with U.S. Code Title 18 Section 1030, "Fraud and related activity in connection with computers."[1] [1] h…

If you ignore all the arrogant remarks from the post the take away is: relatively unsophisticated attacker can tank posts, harm users reputations and alter the state of the HN home page. It's not good, given the influence of HN in the community.

Re: I managed to take down arbitrary posts on Hacker News

#13
post #12

"I'm bored, have dubious ethics and absolutely no restraint whatsoever, so, unsolicited, I'm going to help your site security without notice of my attack! Look what I did! Pay attention to me!" Looks like Hacker News owes this generous soul a massive debt of gratitude for all his hard work while they get familiar with U.S. Code Title 18 Section 1030, "Fraud and related activity in connection with computers."[1] [1] h…

If you ignore all the arrogant remarks from the post the take away is: relatively unsophisticated attacker can tank posts, harm users reputations and alter the state of the HN home page. It's not good, given the influence of HN in the community.

It's unclear whether there was any effect at all.

Re: I managed to take down arbitrary posts on Hacker News

#14

"I'm bored, have dubious ethics and absolutely no restraint whatsoever, so, unsolicited, I'm going to help your site security without notice of my attack! Look what I did! Pay attention to me!" Looks like Hacker News owes this generous soul a massive debt of gratitude for all his hard work while they get familiar with U.S. Code Title 18 Section 1030, "Fraud and related activity in connection with computers."[1] [1] h…

Spot the fed was always a fun time at Defcon. https://www.vice.com/en/article/ypw4wb/when-the-fbi-found-ou...

Spot the paranoid or the gullible is a lot easier since Defcon isn't remotely on the radar of any federal agency, and the notion was only invented to increase interest and credibility. You seriously believe FBI Special Agents would attend Defcon? They have jobs.

edit: the 2015 FOIA request proved this. An FBI researcher pulled info off the web in 2001, no agents contacted the Vegas field office (which means no agents attended), the Vegas field office requested the case be closed, and it was. Read to me like someone in DC was playing a joke on the Vegas field office.

Re: I managed to take down arbitrary posts on Hacker News

#15
post #12

Earlier quoted context omitted.

If you ignore all the arrogant remarks from the post the take away is: relatively unsophisticated attacker can tank posts, harm users reputations and alter the state of the HN home page. It's not good, given the influence of HN in the community.

It's unclear whether there was any effect at all.

It has been flagged and still is. Not sure what kind of reputation damage it might have done if it was not caught, and the author, obviously has not been trying to hide too hard.

Re: I managed to take down arbitrary posts on Hacker News

#16
post #15

Earlier quoted context omitted.

It's unclear whether there was any effect at all.

It has been flagged and still is. Not sure what kind of reputation damage it might have done if it was not caught, and the author, obviously has not been trying to hide too hard.

> It has been flagged and still is.

We don't know why it is flagged, but we can probably guess accurately it was due to the blogger's activity in somewhat of a self-fulfilling prophesy. I suspect he can now enjoy his black hole.

> if it was not caught,

It was caught by the first HN member to comment, which isn't all that surprising. We'll have to wait while up to a few of the several dozens of HN employees get around to completing an incident postmortem, and I suspect we'll never hear anything. It's very Art of War to let the attacker continue to believe they've succeeded.

Re: I managed to take down arbitrary posts on Hacker News

#17
post #15

Earlier quoted context omitted.

It has been flagged and still is. Not sure what kind of reputation damage it might have done if it was not caught, and the author, obviously has not been trying to hide too hard.

> It has been flagged and still is. We don't know why it is flagged, but we can probably guess accurately it was due to the blogger's activity in somewhat of a self-fulfilling prophesy. I suspect he can now enjoy his black hole. > if it was not caught, It was caught by the first HN member to comment, which isn't all that surprising. We'll have to wait while up to a few of the several dozens of HN employees get around…

> It was caught by the first HN member to comment

And this is what his attack was: making legitimate users flag a legitimate article.

Re: I managed to take down arbitrary posts on Hacker News

#18
post #17

Earlier quoted context omitted.

> It has been flagged and still is. We don't know why it is flagged, but we can probably guess accurately it was due to the blogger's activity in somewhat of a self-fulfilling prophesy. I suspect he can now enjoy his black hole. > if it was not caught, It was caught by the first HN member to comment, which isn't all that surprising. We'll have to wait while up to a few of the several dozens of HN employees get around…

> It was caught by the first HN member to comment And this is what his attack was: making legitimate users flag a legitimate article.

Neither the legitimacy of the article nor that of the users' flags is in question. The flags merely draw attention to the fact that the voting was obviously illegitimate. IOW, the attacker drew attention to the attack only, and the article is flagged because of the attack, but the flagging itself is proper. So the attack caused the proper response of flagging. Not all that impressive. Preventing an illegitimate article composed entirely of Lorem Ipsum from being flagged off the front page would be impressive.

Re: I managed to take down arbitrary posts on Hacker News

#19

Earlier quoted context omitted.

Spot the fed was always a fun time at Defcon. https://www.vice.com/en/article/ypw4wb/when-the-fbi-found-ou...

Spot the paranoid or the gullible is a lot easier since Defcon isn't remotely on the radar of any federal agency, and the notion was only invented to increase interest and credibility. You seriously believe FBI Special Agents would attend Defcon? They have jobs. edit: the 2015 FOIA request proved this. An FBI researcher pulled info off the web in 2001, no agents contacted the Vegas field office (which means no agents…

I met almost a dozen folks at DC this year who introduced themselves to me as working for a federal agency...

Re: I managed to take down arbitrary posts on Hacker News

#20

Earlier quoted context omitted.

Spot the fed was always a fun time at Defcon. https://www.vice.com/en/article/ypw4wb/when-the-fbi-found-ou...

Spot the paranoid or the gullible is a lot easier since Defcon isn't remotely on the radar of any federal agency, and the notion was only invented to increase interest and credibility. You seriously believe FBI Special Agents would attend Defcon? They have jobs. edit: the 2015 FOIA request proved this. An FBI researcher pulled info off the web in 2001, no agents contacted the Vegas field office (which means no agents…

Of course, if you can't beat em, join em. The NSA actively recruits during that conference, in plain site.

https://www.theverge.com/2012/8/1/3199153/nsa-recruitment-co...

Post reply on HN