Live data from Hacker News

Project Euler Humble Return

projecteuler.net

121–127 of 127 posts

Re: Project Euler Humble Return

#121
post #74

You can list what problems you've solved by showing an image generated for you. Ex) https://projecteuler.net/profile/daguava.png But you can also use this to quickly test the status of accounts. For example, I was able to find Euler is an admin account by trying https://projecteuler.net/profile/euler.png It tells you it's admin in the image, why? Edit: Wonder if they're exposing some vulnerability with the HTTP 300 M…

Is there any reason why you're intentionally not using the email denoted on the news page?

Re: Project Euler Humble Return

#122
post #94

Earlier quoted context omitted.

I think you're confusing "exploit" and vulnerability. An info leak is a vulnerability. Period. And yes. You completely went around their request, and made this info public without their consent. Actions like this are THE reason the relationship between vendors and security researchers is strained. There's a SPECIFIC reason it's considered common courtesy to wait until a vulnerability is patched before public disclosu…

> if you did this to a site I owned, especially without my consent, I'd be very motivated to contact the proper authorities and pursue civil remedies. Actions like this are THE reason the relationship between vendors and security researchers is strained.

Excuse me? You want to be able to launch an attack, unprovoked, against a server you don't own, without permission, and you want the owner to be cool with that?

You want the owner to be cool with you disrupting business, causing untold financial damage?

PEOPLE like you are the reason that relationship is strained, and the reason the CFAA was written in the first place.

So please do keep "pen-testing" sites you down own without anyones permission, I'm sure you'll end up with a great life that way.

Re: Project Euler Humble Return

#123

Earlier quoted context omitted.

> if you did this to a site I owned, especially without my consent, I'd be very motivated to contact the proper authorities and pursue civil remedies. Actions like this are THE reason the relationship between vendors and security researchers is strained.

Good grief, Americans and threatening to sue anything that moves.

First of all, how do you even know I'm an American? Nothing in my post, my bio, or anything mentions that, so that's quite a sweeping generalization, and baseless assumption.

Secondly, why are "non-americans" cool with breaking other peoples shit without permission?

Re: Project Euler Humble Return

#124
post #74

You can list what problems you've solved by showing an image generated for you. Ex) https://projecteuler.net/profile/daguava.png But you can also use this to quickly test the status of accounts. For example, I was able to find Euler is an admin account by trying https://projecteuler.net/profile/euler.png It tells you it's admin in the image, why? Edit: Wonder if they're exposing some vulnerability with the HTTP 300 M…

Is there any reason why you're intentionally not using the email denoted on the news page?

No the original commenter, but is PE looking for any maintenance help? I certainly don't mind doing things like issue tracking, documentation, etc.

Re: Project Euler Humble Return

#125

Earlier quoted context omitted.

Not if you make security your number one goal from the beginning. But "letting the community rewrite the site" would be very complicated, especially on a niche website such as Project Euler, where a lot of its users are opinionated and would probably take a long time to reach consensus on anything.

If security were really your "number one goal", then you would not create a site at all.

Number two after availability, then.

Re: Project Euler Humble Return

#126
post #38

Haven't they been wrecked once before this most recent incident? I find it concerning that folks are so eager to rush back into a warzone when they know it's not safe. Piling onto a recovering website after a cyberattack is akin to running back into a field where landmines were found. Maybe somebody was able to remove a landmine or two, but wouldn't it be wiser to just walk around it?

Except that as long as you use a unique password, and don't give any details that you don't mind falling into the wrong hands, there is absolutely no risk . Unlike, for example, actual mines.

I use a unique password and even a burner email, and a phone number that I update every 8 weeks for my banking website.

It's taken blood, sweat and tears to save up 20k (a lot for me) and even though I have a secure authentication scheme for the website, I worry about it getting hacked all the time.

"...there is absolutely no risk"

You have no idea! There's little practical risk in people getting access to my (fictional) ProjectEuler account, but there is absolutely some risk into returning to the same scam twice. Say they exploit PE again and are able to extract more than just password and email, maybe they find a way to get more info about the user's browser, or cookies, or SOMETHING. Anybody foolish enough to continue to navigate to projecteuler.net will suffer the consequences. They'd be better off never returning.

I know the response to this will be, "Oh, you can't possibly expect people to just abandon services that are compromised once" but I absolutely don't expect people to do that. I do it, because my security is worth it to me. Others don't, and this is the sort of thing that happens.

We've no way to really isolate what happened to projecteuler, and no way to now what kind of nasty code got injected into the pages.

Re: Project Euler Humble Return

#127
post #22
post #14

Earlier quoted context omitted.

That's not nice. It's also plainly false. Lots of people love Project Euler.

Like me. And I would like to help but I know almost nothing about penetration testing. :(

Exactly. Source code would help a lot. It's an education site that's extremely amateur in nature. It belongs as open source.
Post reply on HN