Live data from Hacker News

CyanogenMod.com hijacked. Transition to CyanogenMod.org

cyanogenmod.org

101–110 of 113 posts

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#101
post #96

Cyanogenmod devs need to get PGP keys and start using cryptographic signatures like now. The guy never would have been able to impersonate in the first place if they were doing this, and now it's even more important that the @cyanogenmod.com domain is directing to a different mail server.

Not sure if that's the case. Most people he was impersonating himself to probably don't know enough to find and check PGP signatures; especially since most email does not come with PGP signatures, the lack of a signature is not something that would cause anyone to bat an eyelash.

If he prominently announced on his sites "DO NOT accept anything without a cryptographic signature as authentic", it is likely to have worked. It's not like the targeted victims had not visited Cyanogen's site or done any research before.

And at worst, a policy of signing all emails makes it so he can't be framed; someone can't alter mails and claim they were sent in that state, and if this guy thought he was going to be caught and went into the mail server to try and plant the evidence so that when the deals fell through the real Cyanogen was still on the hook, he wouldn't be able to reproduce a valid signature and one would say "Cyanogen was obviously framed, as he would never certify a deal in an email without a cryptographic signature".

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#102
Ideas will be stolen. I know this is a hotly debated topic, and I agree with the raw idea != actionable idea, yadda^3.

I cannot emphasize enough to developers and to startups: all war is about money, all business is about money. When you get to the point that you are making money, you are in business... and all business is war (imo). If you go in thinking like that (not freaked paranoia, but strategic defensive development), you will avoid a lot of this trauma.

I feel for you guys, I've been there.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#103
post #96

Earlier quoted context omitted.

Not sure if that's the case. Most people he was impersonating himself to probably don't know enough to find and check PGP signatures; especially since most email does not come with PGP signatures, the lack of a signature is not something that would cause anyone to bat an eyelash.

If he prominently announced on his sites "DO NOT accept anything without a cryptographic signature as authentic", it is likely to have worked. It's not like the targeted victims had not visited Cyanogen's site or done any research before. And at worst, a policy of signing all emails makes it so he can't be framed; someone can't alter mails and claim they were sent in that state, and if this guy thought he was going t…

How would have they distributed the keys? I can easily upload a key with an arbitrary id and username to any public keyserver. You have to actually check that you trust the key by utilizing the web of trust.

Alternatively, you could use SSL certificates, but since the attacker controlled cyanogenmod.com, he probably could have social-engineered the CA to issue him an email certificate.

Trust is hard.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#104
Seems the guy who stole the domain is trying to undo his damage and possibly hand the domain back (likely due to the negative attention this is bringing him). He posted this to his Twitter account a few minutes ago:

"we've already had this conversation. The DNS was changed in preparation to hand the domain back to Steve. You all jumped the gun." https://twitter.com/MrADeveci/status/268837555129167873

"DNS propagation can take 72 hours. The domain was transferred about an hour ago. It was transferred to another UK registrar." - https://twitter.com/MrADeveci/status/268881716876300288

UPDATE: Seems he really has handed the domain back now?: http://www.cyanogenmod.org/blog/domain-situation-has-been-re...

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#105
post #94

Wow, this thread is pretty interesting, in which you can see the owner of the .com domain convincing someone to donate $500 a month to what they thought was the cyanogenmod team: https://store.n2acards.com/helpdesk/viewticket/moderator/cod... And in the thread, he mentions that Swappa is doing the same thing, $500 a month plus $10 per device sold, though there's no way to verify if that's true. Swappa claims to donat…

It seems that previous owner of the .com domain has handed it back to Cyanogenmod already (probably due to the unwanted publicity):

http://www.cyanogenmod.org/blog/domain-situation-has-been-re...

They will stay with the .org domain though, and have the previous .com domain redirect to it.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#106
post #13

Does anybody know how this "rogue" webmaster took undue advantage of the CyanogenMod brand? The Facebook post states something about referral deals with community sites. Any idea what that would mean in practical terms? Just curious.

According to the conversation linked to by CM member koush[1], in one instance he approached a CM distributor requesting a 'contribution': "Hi, we noticed that you are selling these cards with CyanogenMod builds. We do not however seem to have any agreements in place for this and feel it's only fair that you start contributing to the CyanogenMod project to continue selling your products." [1] https://twitter.com/kous…

[deleted]

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#107
post #80
post #40

Earlier quoted context omitted.

There is, so far as I've discerned, an automated bot running that changes submission titles to the HTML title of the URL. No human intervention, no human judgment.

That's not true; tis all humans; but as far as I'm concerned that's the ultimate compliment to their speed and lack of bias.

I wouldn't call "no human judgment" a compliment...

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#108

And the .org domain is already #1 in the Google search results for CyanogenMod.

It's the #1 on Bing and DuckDuckGo as well, though interestingly you can still see links in the .com in both Bing and DuckDuckGo results, but Google has eliminated the .com completely from their results.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#109
post #46

Why are large parts of the android custom ROM community unprofessional and immature? I always shiver a little if I have to dive into xda-forums, but this takes it to the next level. Puts all the actual hard working developers in a bad light.

Any volunteer organization risks running into this at some point. --You generally don't have any sort of contract because you're not paying anyone.

I used to help run a convention, and one year the person who had designed the program book decided he deserved compensation and demanded a similar amount of money to let us use the design. We were left with only a couple of days to come up with a new design.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#110

Earlier quoted context omitted.

How did it happen so quickly?

If search engines are indexing your site with any regularity and you kill all your DNS records I'd say it's not terribly surprising to have your domain removed. That combined with the new .org being an exact match for a "cyanogen" search would probably do it.

It looks more likely that someone form the search team browses HN or uses Cyanogen (very likely) and they intervened and updated the index manually. I am sure google has a back-end to do stuff manually.
Post reply on HN