Live data from Hacker News

Did I just win?

twitter.com

131–140 of 140 posts

Re: Did I just win?

#131

Earlier quoted context omitted.

A website is either data a browser interprets or a combo of it plus software (eg Javascript). This is compromising his software only in most technical, trolling sense. It won't affect his apps at all.

Software is data an operating system and processor interprets. He never specified apps. Besides, how would inserting the string in his apps have any different affect than inserting it into the website? This is completely within the parameters that were set (because there weren't many).

I already explained my perspective on this here:

https://news.ycombinator.com/item?id=11696750

Suffice to say, the real point is whether people can compromise his apps with something that would harm their computer. So, let's rephrase your question, "What's the difference between convincing him to post a challenge string on his website and convincing him to arbitrarily modify code of apps he distributes to users?" Obviously, a huge difference unless he's a complete idiot.

Re: Did I just win?

#132
post #47

Calling a website that happens to host static content in the same repo as its PHP source a "release of a software project" really seems like a stretch.

Why was I downvoted heavily for this, without even a single comment explaining why I'm wrong? This was a serious comment, and I still believe what I said, so it's rather rude to be treated this way.

And again, on a comment asking for someone to actually explain why they're doing this? This is really disappointing, Hacker News is usually a lot more well-behaved than this.

Re: Did I just win?

#133

Earlier quoted context omitted.

You'd have to rely on a ball of jumbled crap somewhere in the PR though - maybe if they don't wrap lines or something you could slip it in?

I'd be XORing against some existing strings in the code of the same length to obfuscate the content, with some hidden method to invoke the reverse XOR to regenerate this challenge text string.

Sure, hiding it as a basic string is easy. But hiding it in a way that a simple code review won't catch is probably a lot harder.

Re: Did I just win?

#134

Earlier quoted context omitted.

I'd be XORing against some existing strings in the code of the same length to obfuscate the content, with some hidden method to invoke the reverse XOR to regenerate this challenge text string.

Sure, hiding it as a basic string is easy. But hiding it in a way that a simple code review won't catch is probably a lot harder.

I think some array manipulation could do it if you're clever enough and don't make it obvious where all of the inputs comes from. So you'd make some particular parameters regenerate the string, and it wouldn't obviously stand out from the normal behavior.

Re: Did I just win?

#135

Earlier quoted context omitted.

You're failing to see the charm here. Social engineering is a confidence trick that exploits gaps in someone's personal trust system. Surely you are right that when he presented the challenge he had something different in mind. But that's exactly the point! The winner realized that the website itself might be a gap in the challenger's trust system; a place where he would have his guard down. Eschewing the implied par…

I not only see that: I specifically explained the expectation and how it was reframed into a new target above. https://news.ycombinator.com/item?id=11693426 Your failing to see my actual concern here. I'm one of those old-school types that rate people on impact their work has first and how clever/funny it is second. The first, expected challenge had consequences with impact. Tackling that with effort even close to su…

[deleted]

Re: Did I just win?

#136

Earlier quoted context omitted.

Oh, come on, I'll give that a troll win at best. The clear implication was subverting software users would run. Let him social engineer that one. I'd put it in a bug-fix or something Obfuscated C contest style.

This is what Social Engineering is. Asking someone to do something that they normally would do, in order to get the desired outcome.

Re your deleted comment

You suggested I "didn't get it" because trolling stuff that wins a game was the point. Actually, what made me think about impact was on website and the challenge itself:

"Backdoor Insertion Proof-of-Concept Bounty: The first time someone tricks me into inserting the string "BackdoorPoCTwitter" into a release of any of my software projects"

Whole point is assessing ability to backdoor software products. Social attack that succeeds might teach us something. The cheat teaches us nothing but is amusing. So, I certainly get it and read site before I wrote here. ;)

Note: Same page said employer's website was off limits in hacks and pentests. I assumed that meant Defuse. So, never considered website attack as in scope in first place.

Re: Did I just win?

#137
post #21

What exactly happened here? All I see is a highlighted line that seems to have already been there.

A guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects. Another guy responded "You should put this challenge on your website." The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website. GG

[deleted]

Re: Did I just win?

#138
post #99

1. Create issues for items I need fixed on my github repos. 2. Offer a $100 bounty to people who can trick me into getting some string into my projects. The easiest way to "trick" me of course is to hide it inside of a PR which fixes a real issue. 3. Find and remove the string before merging the PR. I've had one of my issues fixed for free. Rinse and repeat! Bonus Round: Stage an announcement on twitter and have some…

It's worrying that something as harmless as this comes across as a stunt with some ulterior motive. Not everything is a viral marketing campaign.

I like to suspect everything that gains attention to be a marketing campaign.

Re: Did I just win?

#139
post #114

Earlier quoted context omitted.

Aren't you the winner?

Yes, I think this counts as proof: https://twitter.com/Sc00bzT/status/731243916951994368 My win was legit, but there's no way for me to prove that. Well if this was a PR stunt then I should of @defcon or at least #defcon to get a larger audience, but in all reality I'm banned from PayPal and haven't used Bitcoin. Which is why I said I'll settle for a beer, but I should of asked for zcoin after it launches... shit now…

What is the PayPal ban about?

Re: Did I just win?

#140
post #68

Earlier quoted context omitted.

Explain please? I cannot make sense of the op's sentence in a way that advocates social engineering.

Interesting. I am not a native speaker and I cannot make sense of the op's sentence in a way you understand it. How did you understand op's sentence in the first place?

lol just saw this. Basically, I thought he was being sarcastic in saying "Clever win" and took the "It's not clever to hack something that you can socially engineer" as "It's not clever to socially engineer". Hopefully that helps.
Post reply on HN