GL sent me this statement. For the record, I didn't publish vulnerable systems, I published stores that have malware. --- Willem, GitLab has opted to remove the list of servers that you posted in your snippet. GitLab views the exposure of the vulnerable systems as egregious and will not abide it. While GiLab reserves the right take further action, up to and including termination ( https://about.gitlab.com/terms/ ), w…
Did you ask them for permission to publish a private communication? Probably not, bad of you! - Github/-lab is for projects imho and not a publishing platform. Why don't you publish it on your blog or something? All power to Github/-lab, kick out such stuff!
GitHub censored my research data
111–120 of 206 posts
Re: GitHub censored my research data
#112I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. Most of the owners probably barely know the Googles from the Facebooks, so even if you email them saying 'you have this JavaScript thing that's bad' they won't understand and will blow you off. OP doesn't go into details of how they check the stores, but I'd assume they have some sort of script as they chec…
Aren't they actively running malware as a result of their own laziness not to upgrade their Magento[1] Site?
This malware is being used to steal customer credit cards (at the very least) - perhaps identity theft as well. They are the very agents of 3rd-party hackers. This list[2] should be sent to the proper authorities and have the stores closed immediately.
Customers who have made purchases at these stores can and should be looking at lawsuits.
If you're going to run a 3rd-party solution for your ecommerce needs and patches have long been made available, you patch. If you can't even do this one simple thing - you get run off the internet for criminal negligence.
[1] https://magento.com/ [2] https://www.magereport.com/page/about
Re: GitHub censored my research data
#113Earlier quoted context omitted.
Not if you want to update it. Also, Pastebin has some shady practices. One example: they offer HTTPS support as a premium feature.
I am sorry, but I fail to see how offering https support as a premium feature could be considered "shady".
Re: GitHub censored my research data
#114Earlier quoted context omitted.
I am sorry, but I fail to see how offering https support as a premium feature could be considered "shady".
All web traffic should be encrypted, regardless of purpose. This increases the work that nation-state level adversaries must do to effectively spy on the population. And it's cheap and easy to do these days.
BUT! the point here is the op claims this is a shady practice to provide https to their paying customers.
A shady practice is if they take your personal information and sell it to another without telling you. Shady is when companies lie to their customers.
And this situation is not.
Re: GitHub censored my research data
#115Isn't pastebin the correct site to post lists like this?
Not if you want to update it. Also, Pastebin has some shady practices. One example: they offer HTTPS support as a premium feature.
Re: GitHub censored my research data
#116Earlier quoted context omitted.
> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?
Sites will always continue to carry malware. Naming and shaming without looking at all the parties involved is a crude and ineffective way of changing things. Change the browser, change the payment system, educate the user by using plugins, propose enhanced security methods in ECMAscript. Write about how easy it is to make missteps on the net. These are all alternatives which might help in a more permanent fashion.
There is nothing a client can do when the server is compromised.
Re: GitHub censored my research data
#117Earlier quoted context omitted.
> I'm kind of with Gitlab on this one, just publishing a list of broken sites isn't going to help them get fixed. So the malware should be allowed to continue stealing credit card numbers just because the site owners don't know any better? Is that really a position you wish to defend?
No I don't agree that it should be allowed to continue, but how is naming&shaming people going to fix anything? Nothing is going to come of this, other than maybe some other hackers will see them as weak targets. Do you expect this list to be read on prime time CNN or something? People who want to buy something online aren't going to search through GitLab to check if the site has been hacked (maybe they should though…
Re: GitHub censored my research data
#118Earlier quoted context omitted.
All web traffic should be encrypted, regardless of purpose. This increases the work that nation-state level adversaries must do to effectively spy on the population. And it's cheap and easy to do these days.
It's not a question if its easy to do or not. Yes I prefer an encrypted connection over one that is not. BUT! the point here is the op claims this is a shady practice to provide https to their paying customers. A shady practice is if they take your personal information and sell it to another without telling you. Shady is when companies lie to their customers. And this situation is not.
Re: GitHub censored my research data
#119Like wut