Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

121–130 of 196 posts

Re: The fake browser update scam gets a makeover

#121
post #82
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

Doesn't the article talk about how they're adding centralized KYC?

Re: The fake browser update scam gets a makeover

#122
post #83

Earlier quoted context omitted.

I really think Monero in particular deserves way more criticism for their practice. Bitcoin is one thing, Monero is created for and marketed towards cybercriminals, you don't need to be a communications expert to get that premise. I haven't seen it used once for any legitimate purpose. Atleast with Bitcoin and Ethereum you can get buy some legitimate things like VPNs or NFTs https://arstechnica.com/information-techno…

So Tor and I2P also should be criticized? IMO, something being away enough from the government that it starts to get abused shows how secure/private it is.

Tor and I2P allow the free flow of information, which is a net good for society. Monero allows the free flow of money which is a net negative; it effectively destroys the rule of law because those with enough money can freely commission crimes that benefit them.

Re: The fake browser update scam gets a makeover

#125
post #43

Earlier quoted context omitted.

According to the following blog post, it uses a web API exposed by the Binance Smart Chain (BSC) platform: https://labs.guard.io/etherhiding-hiding-web2-malicious-code... This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4... Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BS…

Sounds like we should poison this vector (and IPFS) by uploading copyrighted movie torrents to this free storage system. For a change we’d be doing good.

Your plan is to DOS a system because someone abused it?

Re: The fake browser update scam gets a makeover

#126
post #16

So the attack goes: 1) compromise some site to serve arbitrary JS 2) have it serve simple JS that requests other JS that contains the real malicious payload. And the reason for this two-step architecture is to make it convenient to change the real payload. And the problem is where to host the real payload. The first idea was Cloudflare, but Cloudflare keeps taking that sort of thing down. So now they host it "on the…

According to the following blog post, it uses a web API exposed by the Binance Smart Chain (BSC) platform: https://labs.guard.io/etherhiding-hiding-web2-malicious-code... This diagram show the full flow of the attack: https://miro.medium.com/v2/resize:fit:1400/format:webp/1*by4... Because reads from blockchain are "free" (meaning, there is no cryptocurrency payment required to read data from the smart contracts on BS…

For the Blockchain reads, someone still needs to host a JSON-RPC server. Most of hosting is commercial SaaS (Infura, QuickNode, LlamaNodes) but Binance provides a free endpoint for better adoption of their chain.

This free endpoint has many abuse protection mechanisms, as free services need (see: Cloudflare). However until today no one was hosting any malicious web payloads.

It's just matter to add a new abuse rule by BNB Smart Chain team to take this down.

Re: The fake browser update scam gets a makeover

#127
post #73
post #72

Earlier quoted context omitted.

lol > In response to questions from KrebsOnSecurity, the BNB Smart Chain (BSC) said its team is aware of the malware abusing its blockchain, and is actively addressing the issue. The company said all addresses associated with the spread of the malware have been blacklisted, and that its technicians had developed a model to detect future smart contracts that use similar methods to host malicious scripts. Earlier in th…

Anybody can spin up a mirror node, even on the mostly centralized BSC. This is just a misunderstanding. Every public blockchain works this way afaik. I've even made a site for hosting webpages on Optimism: https://newgeocities.com The real discussion imo is that blockchain node operators should be pressured to respond to concerns about unwanted content. There's no reason they can't coordinate on filters in the same w…

Running a BNB Smart Chain full node requires 16 TB fast NVMe disk. "Anybody" cannot do it.

Re: The fake browser update scam gets a makeover

#129
post #78

Earlier quoted context omitted.

The suffocating irony of this forum being called "Hacker News" when it is filled with comments like this never fails to amaze me. A truly unimaginative bunch.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

Well, you are - and I mean this with as little offense as possible - only entertaining the blockchain from a likely incredibly privileged position. Consider people living under an oppressive regime. Things you are considering perfectly normal, like freely living as a homosexual, may be a punishable offense and illegal for its citizens. "Illegal nonsense" uses of the blockchain may be live-saving privacy for them.

Re: The fake browser update scam gets a makeover

#130
post #82

Earlier quoted context omitted.

Preserving privacy, reliable transactions with no, i repeat, no bank or govmnt involvement, no kyc. No/low fees (on some currencies), public immutable databases...

Somehow I'm living day to day without needing to think about being associated with a service I am paying for. I totally get your point about minimizing interference, but there is absolutely no way anyone thinks Monero is a good solution to this problem who isn't involved in some shady business.

Monero is used everyday by people living under oppressive regimes.
Post reply on HN