Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

141–150 of 196 posts

Re: The fake browser update scam gets a makeover

#141
post #94

Earlier quoted context omitted.

I would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.

In an ideal world, native apps shouldn't be able to compromise your whole system.

And how would that ideal world come to pass?

Hell, we even tried applets!

Re: The fake browser update scam gets a makeover

#142
post #56

Earlier quoted context omitted.

I would argue that a world that didn't have JS would make these types of attacks more common, not less common. Because in that world, people would have to download desktop apps for everything, which would make people used to downloading desktop apps from random Web pages, which would make malware easier to distribute. In fact, we don't have to imagine that world: it was the world of the late 90s.

That's a very real problem, but one would hope that package managers would be a lot more widely adopted in that counterfactual world. Maybe that's a naive hope.

Desktop software runs with fewer protections than web applications. So unless everyone is planning on becoming SELinux experts tomorrow, the web still makes sense for a lot of stuff.

Hence why exploits like these are always about getting software installed onto the host rather than being 100% JS.

And before anyone says “but package managers solve this problem”, no they don’t. There have been numerous cases of compromised software leaking into office repositories. It happened with a Ubuntu package were an attacker hacked the upstream repository. It’s happened with npm. Browser extensions from Google and Firefox repos are frequently a source for Trojans. Android and iOS have lots of apps that appear to be free torches or other such utilities but are actually just harvesting all your data. Just because a software package is published to an official repository, it doesn’t make that package safe.

Re: The fake browser update scam gets a makeover

#143
post #139
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

Out of interest, why cant VPNs, Tor or cash be used for CSAM? My intuition is that those 4 have more or less the same use cases.

Re: The fake browser update scam gets a makeover

#144
post #78

Earlier quoted context omitted.

The suffocating irony of this forum being called "Hacker News" when it is filled with comments like this never fails to amaze me. A truly unimaginative bunch.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

I’m biased because I work on payments at Solana Labs, but IMO international payments is the most promising so far.

AFAIK there’s nothing competitive with sending an international payment of any amount in half a second for a tiny fraction of a cent in fees.

For example, Visa recently expanded their pilot of USDC settlement to include Solana, citing its speed and low fees: https://usa.visa.com/about-visa/newsroom/press-releases.rele...

They refer to it as “modernizing cross-border money movement” and I think that summarises the potential pretty well!

Re: The fake browser update scam gets a makeover

#145
post #139

Earlier quoted context omitted.

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

Out of interest, why cant VPNs, Tor or cash be used for CSAM? My intuition is that those 4 have more or less the same use cases.

You ain't good at sarcasm (obvious one)

Re: The fake browser update scam gets a makeover

#146
post #139
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

Besides the payment processor I use allowing these things afaik(but that might be an EU vs USA thing): isn't the point of blockchain that everything is immutable and a full history of every transaction is kept? That means that if your wallet(or w/e you use to pay) is ever connected to you as a person, everyone will know what "morally questionable or financially risky" things you did in the past, which unless you don't care about that will still cause you to be really careful using your money on these type of things(honestly: even more careful than right now probably).

You could be careful to not leak your wallet address of course, but if we'd truly be a cashless society without decentralized currency you'd want to buy your groceries with it too, or order computer parts. What prevents these shops you buy from from having a security issue and leaking your wallet address? You could have a separate wallet per shop, but you need to get money into it somehow which can be traced as well(because it's the blockchain).

Note: I'm not an expert on blockchain/crypto, there might be ways to mitigate this, I'm just legit curious as to how this would be solved in a world like this.

Re: The fake browser update scam gets a makeover

#147
post #99

Earlier quoted context omitted.

Or alternatively, you can pursue security through compartmentalization. My VM for random browsing has JS enabled, but if I'm hacked, the attacker will not get access to any files. Also the VM is destroyed when the browser is closed.

What’s the threat model here? Javascript sandbox escapes are extremely rare these days (subjectively they happen less frequently that image or video codec bugs).

Apart from js escapes, you are protected even if you run random executables from the Internet, or any untrusted software in general. More reasons: https://forum.qubes-os.org/t/how-to-pitch-qubes-os/4499/15

Re: The fake browser update scam gets a makeover

#148

Earlier quoted context omitted.

Somehow I'm living day to day without needing to think about being associated with a service I am paying for. I totally get your point about minimizing interference, but there is absolutely no way anyone thinks Monero is a good solution to this problem who isn't involved in some shady business.

Monero is used everyday by people living under oppressive regimes.

Wasn't able to find a single article mentioning use under opressive regimes. It does seem to be the most popular ransomware crypto now though so there is that

Re: The fake browser update scam gets a makeover

#149
post #54
post #35

I get that the angle of BNC here generates views (and outrage and haha blockchain bad). But the real story is "WordPress websites still hacked in masses". WordPress, somehow, cannot manage to turn themselves into a secure and tough system. It remains a prime target, it's installations get hacked by the thousands and it's causing real harm at that. (Yeah, yeah, I know the users, admins, plugins, themes and hosted are…

Being one of the biggest publishing softwares naturally attracts all of that: more publicity/cases, uninformed users, incentive and a probing/persistence ecosystem for hackers,. I have to host a few dozen WordPress sites for customers and the ones that got hacked were all backtracked to: enumerating usernames, and some had their password equal that. You could blame WordPress for not being more strict rejecting those…

Being one of the biggest publishing softwares gives a giant responsibility to prevent this.

I am convinced this responsibility isn't taken up by the community or by organisations behind it, seriously enough. Simply because the current status continues to be abysmal. I have many practical ideas how many issues could be solved, most are put forward and put down almost monthly in the community.

The current status is resignment: "well, we are big and this is how things are". No! Things could be better, more secure etc. But for that, things do have to change.

Re: The fake browser update scam gets a makeover

#150
post #35

I get that the angle of BNC here generates views (and outrage and haha blockchain bad). But the real story is "WordPress websites still hacked in masses". WordPress, somehow, cannot manage to turn themselves into a secure and tough system. It remains a prime target, it's installations get hacked by the thousands and it's causing real harm at that. (Yeah, yeah, I know the users, admins, plugins, themes and hosted are…

To be fair, WordPress core has gotten better. The bigger problem is that there are many WordPress plugins, and many of the plugins can't even pretend to be related to being secure. Until developers are widely taught how to develop secure software, the problem will just keep moving around. We can't make software development environments where it's impossible to create a vulnerability, and we will never convince users…

Very over the top, but bear with me. For example: if your community of plugin developers cannot produce secure(ish) plugins, then it's probably time to get rid of the plugin system altogether. "Plugins endanger our users, we no longer allow them."

Being a player that powers a vast part of all websites, gives a responsibility. Taking up that responsibility includes making unpopular decisions. While "getting rid of the entire plugin system" is probably a bridge too far (it would kill WP instantly) the system needs overhaul (same for hosting, same for themes), badly. There is an intermediate solution, I am sure¹.

But the starting point must be "our community cannot handle the power we give it, so let's find a solution for that".

¹ I refrain from concrete examples here, bc HN tends to spiral into discussions on why random potential solution X will never work. I want to keep this on a higher level.

Post reply on HN