Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

111–120 of 196 posts

Re: The fake browser update scam gets a makeover

#111
post #64

Earlier quoted context omitted.

Ironic that even this blockchain still had some centralised aspects: “In response to questions from KrebsOnSecurity, the BNB Smart Chain (BSC) said its team is aware of the malware abusing its blockchain, and is actively addressing the issue. The company said all addresses associated with the spread of the malware have been blacklisted, and that its technicians had developed a model to detect future smart contracts t…

IIRC blacklisting in this manner is basically just a suggestion - it's saying, "hey, in the opinion of Binance, these adresses are bad. Don't do business with them". If the majority of nodes in the network comply with the blacklist, then it works. But at any point, someone who runs a node (or nodes) can choose to ignore the blacklist. It's only centralized if the majority of people running BNB Smart Chain decide to t…

I'm no blockchain expert but I don't think you need a majority. The majority relates with the financial incentives of following the longest chain, but ultimately you can configure your node to "disbelieve" any block breaking the blacklist and carry on with like-minded nodes in a fork.

Re: The fake browser update scam gets a makeover

#112
post #91

Earlier quoted context omitted.

I use Monero to donate to FLOSS software projects and as a way of paying friends without surveillance capitalism demanding I tell them what my private transactions are for. If these aren't "legitimate purposes" then there no point in engaging in this conversation. Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever but I'd rather not engage with companies that seek to demand an e…

> Maybe you're happy with being subject to corporate panopticons of Venmo/Cash App/whatever Get this, I've never used either of these services before. And the even crazier part is that if I did, they wouldn't know what I'm giving my friends money for anyways. And lastly, just use cash if your decision making is being opressed by the surveillance capitalism. Monero serves no purpose that hasn't already been fullfilled…

> just use cash if your decision making is being opressed by the surveillance capitalism

This is morally equivalent to:

- "just send a letter through the post if you don't like EU's chat control"

- "just read the newspaper if you don't like Google's Federated Learning of Cohorts"

I'd like to believe we can get the benefits of 21st century tech without giving up our privacy to get it. Thanks to Monero that belief is a reality. You're welcome to stick with cash and the pony express if you like, but it's not a great look painting everyone who disagrees with your values as a criminal.

Re: The fake browser update scam gets a makeover

#113
post #83

Earlier quoted context omitted.

I really think Monero in particular deserves way more criticism for their practice. Bitcoin is one thing, Monero is created for and marketed towards cybercriminals, you don't need to be a communications expert to get that premise. I haven't seen it used once for any legitimate purpose. Atleast with Bitcoin and Ethereum you can get buy some legitimate things like VPNs or NFTs https://arstechnica.com/information-techno…

So Tor and I2P also should be criticized? IMO, something being away enough from the government that it starts to get abused shows how secure/private it is.

Ironically Tor is mostly funded by the US government. 80% in 2012. They are still a significant donor however I'm not sure if the percentage is still so high.

Re: The fake browser update scam gets a makeover

#114

Every time I read about the Binance Chain, it involves a scam. Is there anything created on it that isn't that sees "wide" use in the crypto space?

I don't mean this as a particular defence of Binance chain per se - and I realise I'm not directly answering your question either - but pedestrian everyday usage of no special note would, by its very nature, go entirely unremarked, certainly by any 'news' source. It's only ever the dramatic heists, the hackings, thefts, etc, that drive reported media. Therefore, the fact that "every time [you] read about" it, it invo…

I get what you're saying. Media bias towards certain headlines. I was extremely active in the crypto scene for many years (participating in Polkadot auctions, ETH domain names, NFT card games, DAI repo auctions, de-fi apps etc) and have never seen a legitimate use-case come out of BSC at all (they were always scam coins) and was wondering if anyone else has felt the same or had any evidence proving otherwise.

Re: The fake browser update scam gets a makeover

#115
post #46
post #43

Earlier quoted context omitted.

Sounds like we should poison this vector (and IPFS) by uploading copyrighted movie torrents to this free storage system. For a change we’d be doing good.

Shoot don't even need a movie, just a picture of Mickey Mouse

or CSAM

Re: The fake browser update scam gets a makeover

#116
post #16

So the attack goes: 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload. And the reason for this two-step architecture is to make it convenient to change the real payload. And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the…

> 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload.

So… https://joshcsimmons.com?

Re: The fake browser update scam gets a makeover

#117
post #2

The quality of full screen takeover pages seems to have dramatically risen recently. My family members, who don’t know the Escape key exists, accidentally click one from a banner ad every week now taking them to a page like examplefoobar38561.cloudfront.net and the use of elements that imitate browser or OS chrome (generally imitating Windows Defender or similar) has reached near perfection. All browsers should have…

Obv the solution is to just pick a really wacky desktop ui theme that the h4x0rs won’t guess to imitate :p

/s

Re: The fake browser update scam gets a makeover

#118
post #36

Earlier quoted context omitted.

This isn't that complicated. Like everything else in life it's a matter of trust and awareness, not really that technical. I'll never understand why the default stance on HN is always javascript bad .

Your browser is a platform that downloads and runs arbitrary code on your local hardware. "JavaScript bad" doesn't capture the nuance I read in people's comments here, but history shows that JavaScript is a gaping maw of security nightmares.

Modern browsers are what have removed the nuance. Please tell me what about the Web API for JS is truly dangerous.

Native apps and programmable documents (PDFs and spreadsheets for example) are the real security nightmare.

The danger on the web lies squarely with easily fooled idiots visiting shady sites.

Re: The fake browser update scam gets a makeover

#119
post #80
post #73

Earlier quoted context omitted.

Anybody can spin up a mirror node, even on the mostly centralized BSC. This is just a misunderstanding. Every public blockchain works this way afaik. I've even made a site for hosting webpages on Optimism: https://newgeocities.com The real discussion imo is that blockchain node operators should be pressured to respond to concerns about unwanted content. There's no reason they can't coordinate on filters in the same w…

seems like "blockchain" has nothing to do with it... they could just host the file on a server they do control. "Blockchains" aren't magic.

Blockchains - that is, the communities that use them - are at least theoretically committed to immutable permanent records of everything that happened. By design, if you tried to "retroactively" edit the contents of the blockchain, you would break the whole thing. So if the blockchain hosters stick to their avowed principles and system design, they can't remove your exploit code without taking down their whole system.

Of course in reality most blockchain folk are grifters who will happily compromise their principles as soon as you credibly threaten their pocketbook - see the Ethereum DAO for the clearest example. Still, it's funny to force them to admit it.

Re: The fake browser update scam gets a makeover

#120
post #36

Earlier quoted context omitted.

Your browser is a platform that downloads and runs arbitrary code on your local hardware. "JavaScript bad" doesn't capture the nuance I read in people's comments here, but history shows that JavaScript is a gaping maw of security nightmares.

Modern browsers are what have removed the nuance. Please tell me what about the Web API for JS is truly dangerous. Native apps and programmable documents (PDFs and spreadsheets for example) are the real security nightmare. The danger on the web lies squarely with easily fooled idiots visiting shady sites.

For me personally it isn't as much "danger" as annoyance. Most of the web is hidden behind piles of modals, dickbars, autoplay videos, etc. Almost none of that happens without javascript. But don't dismiss those fools, they're inside sensitive networks around the world.
Post reply on HN