Live data from Hacker News

Full-disclosure – Administrivia: The End

marc.info

31–40 of 142 posts

Re: Full-disclosure – Administrivia: The End

#31

He didn't really explain the full problem so maybe I am not fully appreciating the situation here, but this seems like a pretty big overreaction for a stupid request from some a single user.

As someone who had to deal with legal troubles when running a user facing service I can say that it's not that easy if you don't have resources (or knowledge/time) to response correctly to the legal inquiries. For example, a relatively small (by internet standards) "local" forum has a somehow dedicated (it's not their full time job) 3 man legal team that answers all the legal inquiries.

If I add one of the latest in the series of my own experiences. Once upon a time someone wanted to scam me on a website deal. We figured out who it was (it was easy, he was the owner of the domain, paid for the hosting etc.) and published the details (we were not the first, he's quite a known scammer around here, we found numerous blogposts about him). He was even featured in a local newspaper. Fast forward 5 or so years and I get a Cease and Desist letter from him (or something looking like that) that the information in my blog post is not accurate and he will sue me. I quickly see that google doesen't bring much about him nowadays, in part to people not caring for their blogs/doing redesigns and in part of him sending out "scary" letters. Of course I could fight it, I had a lot of concrete (I was told court grade by some lawyer acquaintances) proofs. But was it worth my time? My effort? My psych? No. I redacted the blog post and let it be. I don't feel good about it, because that means he will try to scam people that could'we been warned from my post. But I wagered it and left it all behind.

EDIT: grammar n'stuff

Re: Full-disclosure – Administrivia: The End

#32
What a shame; I just recently started taking on an interest in computer security and signed up for the list. In just the few weeks I was on there, I learned about a vulnerability in a device I had recently bought. I am cherishing the opportunity (which I haven't found time for yet) to walk through my first exploit!

As a newcomer I'm not really sure what John's referring to, though. Too bad...

Re: Full-disclosure – Administrivia: The End

#34

Earlier quoted context omitted.

Are you unfamiliar with the phrase he used, "straw that broke the camel's back"?

In this context, it's really a weasel term. He's functionally given no explanation.

If you care about context, read the list....

Re: Full-disclosure – Administrivia: The End

#35

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

throughtor: yes, and your post is dead on arrival.

Re: Full-disclosure – Administrivia: The End

#36
post #21
post #16

Wow, this is sad. Hope we can get more info on what was going on. Besides Bugtraq what mailing lists security wise do you follow? EDIT: Or what other general means by Twitter, Websites, Databases, Blogs etc. do you recommend?

Why would you follow any mailing lists for security in 2014? The concept of a security mailing list predates Twitter, vulnerability databases, Reddit, and blogs. But we have all those things now, and they are all better than Full-Disclosure on its best days.

Why are they better?

Re: Full-disclosure – Administrivia: The End

#37

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

throughtor: yes, and your post is dead on arrival.

interesting - is it that the account has no karma, that it's using TOR, or a combination?

Re: Full-disclosure – Administrivia: The End

#38

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

throughtor: yes, and your post is dead on arrival.

let's see... no tor, no karma

Re: Full-disclosure – Administrivia: The End

#39
post #12

It seems ironic for the end to arrive without full disclosure of why.

Yes it would seem in the vein of the list to out the 'researcher' who is being the final asshole.

What would be the point, other than nailing that person to a post and having them exposed to various forms of Internet abuse?

As you said yourself, this is just the final straw.

Re: Full-disclosure – Administrivia: The End

#40

Sites that allow anonymous postings through tor (e.g. reddit) are the last remaining voice of freedom on the Internet. It is unfortunate that HN is not numbered among those sites. Edit: I was incorrect about HN. See the comment below. I am happy to learn that I was wrong.

Hi, I'm posting this through Tor. The reason I'm able to do this is because this account is more than two weeks old. I also created this account through Tor, so HN's operators should have no idea who I am.

For example, you have done an experiment below of posting comments through tor using the newly-created account "throughtor": https://news.ycombinator.com/threads?id=throughtor

If you turn on "showdead" in your profile, you'll see that account has a bunch of dead comments. Those comments are dead because the "throughtor" account is less than two weeks old, so HN's system automatically kills them since they're posted through tor. Once two weeks elapse, you'll be able to post comments and they won't be struck down. (Two weeks is the time it takes for the "new account" status to wear off.)

This is a spam prevention technique, and it's necessary in order to drastically reduce the amount of work moderators have to do to filter spam.

So, anyone who wants to post anonymously on HN should open up Tor Browser and create an account right now, and save it for a rainy day sometime in the future.

Remember not to use the same password as your regular HN account, because you'll give your identity away if you do. In addition to the fact that there's nothing stopping any server from logging every password across every service, HN also stores passwords as unsalted SHA-1, so two identical passwords on two different HN accounts will be stored as the same hash in the database, making it trivial to detect your real identity.

At least, unsalted SHA-1 was the case as of arc3.1, which is now several years old. Kogir probably changed it to something more sane in the meantime. But I highly doubt anyone will be able to break into HN's server running BSD anyway, so the unsalted SHA-1 isn't really a concern. This is just a reminder that every piece of information you provide is a piece of information that can be used to determine your identity.

And if you use this information to create more work for HN's operators, then I will ssh into your macbook and scare the crap out of you in the middle of the night by setting your volume to 100% and using text-to-speech. But seriously, don't be lame. It's valuable that we are permitted any anonymity at all.

Post reply on HN