Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

171–180 of 196 posts

Re: The fake browser update scam gets a makeover

#171
post #84
post #80

Earlier quoted context omitted.

seems like "blockchain" has nothing to do with it... they could just host the file on a server they do control. "Blockchains" aren't magic.

It's not magic but it is a radically different pricing model: pay once, host forever. I see it as a massive bet on storage prices continuing to decrease.

or pay never and host it on the infected website

Re: The fake browser update scam gets a makeover

#172
post #30

Earlier quoted context omitted.

It’s been great for gambling, cybercrime, and enabling the drug trade practically since its inception.

I really think Monero in particular deserves way more criticism for their practice. Bitcoin is one thing, Monero is created for and marketed towards cybercriminals, you don't need to be a communications expert to get that premise. I haven't seen it used once for any legitimate purpose. Atleast with Bitcoin and Ethereum you can get buy some legitimate things like VPNs or NFTs https://arstechnica.com/information-techno…

Today you are on the right side of the fence. You buy things that are permitted so its all good. I wonder if you would keep the same opinion, once that changes.

But lets hope for our sake, we never get there.

Re: The fake browser update scam gets a makeover

#173
post #145

Earlier quoted context omitted.

Out of interest, why cant VPNs, Tor or cash be used for CSAM? My intuition is that those 4 have more or less the same use cases.

You ain't good at sarcasm (obvious one)

He's right. There's no reason, for instance, that CSAM media can't go on the blockchain as a block - and then everyone plays plausible deniability because the "blockchain is immutable". The internet is written in ink, the blockchain is written in unwashable graffiti that many people are taking pictures of to save their own copy of it at any given time.

Re: The fake browser update scam gets a makeover

#174
post #5

Yet again the crypto crap has proven its utility for doing shady shit.

Yep, and you can bet the government will continue using that as an excuse to bludgeon it with more regulation.

Good. It's bigger now than it ever should have been, and it'll reap what it has sown for it. It should have been a technology on the down-low, it should have been a technology that purposely purported not to attract attention, it should have been a technology that volatility shouldn't have been its primary feature.

Cryptocurrency would have been good, as a technology, if its infrastructure didn't purposely embrace grifters and skepticism.

Re: The fake browser update scam gets a makeover

#175
post #139

Earlier quoted context omitted.

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

Out of interest, why cant VPNs, Tor or cash be used for CSAM? My intuition is that those 4 have more or less the same use cases.

I'm pointing out a longstanding inconsistency on HN. Every think-of-the-children argument against cryptocurrency also applies to many privacy-focused tools. The loudest commenters in the HN community are anti-censorship, but they espouse the belief that anyone against censorship of money must be a criminal.

Re: The fake browser update scam gets a makeover

#176
post #146
post #139

Earlier quoted context omitted.

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

Besides the payment processor I use allowing these things afaik(but that might be an EU vs USA thing): isn't the point of blockchain that everything is immutable and a full history of every transaction is kept? That means that if your wallet(or w/e you use to pay) is ever connected to you as a person, everyone will know what "morally questionable or financially risky" things you did in the past, which unless you don'…

I have two answers, one snarky.

Answer #1: relax, they already know everything about you. With every interaction in society, you leave some combination of name, email, address, purchase history, security-camera footage, license-plate footage, IP address, cell-tower history, credit-card number, Venmo likes, etc. The history of a unit of digital currency certainly helps fill in gaps. But whoever "they" are to you, they already know.

Answer #2: No single tool is a one-size-fits-all answer to privacy. TCP/IP needs TLS for transport-layer privacy, DNSSEC and TLS certs for authenticity, VPNs and Tor for protection against traffic analysis, throwaway accounts to segregate one's personal workstreams, and so on. The privacy of the internet results from an ever-evolving collection of tools.

Bitcoin is TCP/IP for money. It's a pipe that allows transfer of value from one place to another -- that's it. It doesn't provide anonymity, but unlike centralized payment-processing systems, it allows the creation of tools on top of it that could provide a practical level of anonymity. A Bitcoin mixer, for example, is comparable to a VPN.

Note that if VPNs or TLS were invented today, rather than decades ago, the Hive Mind would be demonizing them as tools for criminals and/or the kind of person none of us admits to being (purchasers of porn, etc.). We take a lot of internet privacy tools for granted, mostly because we're accustomed to them, but also because they were grandfathered before September 2001.

Re: The fake browser update scam gets a makeover

#177
post #17

I'm just happy to finally see a practical use case for Blockchain technology.

Lol you don’t need blockchain, you need a host that doesn’t take down malware payloads. A floppy disk is sufficient technology if cached behind a CDN

in 2023 blockchains are ubiquitous and floppy disks are not

Re: The fake browser update scam gets a makeover

#178
post #87

Earlier quoted context omitted.

to be clear the caveat has a caveat - the centralized control you're talking about is through public (privately hosted) APIs. anyone running a node on the chain can still send and receive whatever they want. unless the majority of the chain chooses to black list addresses, then you have a hard fork because the nodes don't have a consensus on the protocol (open vs black listing).

I don't see how this changes my point? Yes, on the chain you can send and receive any data you want. But if all you want to do is to exchange meaningless data, you don't need a blockchain for that. An in practice, there was no hard fork, and yet Moxie's NFT was "removed" from opensea and from the metamask wallet. Sure, someone with a full client can still see the NFT and _techinically_ all the data is there.. and yet…

just launder it differently. the blocking mechanisms cannot discern.

forget about mixers. just launch an NFT or ordinals collection, buy it first with your clean KYC’d coin, pump it with your dirty coin, and sell your clean coin to whoever is buying - the audience or your dirty coin address

now you just have more clean coin, if you even want govbucks then you can get that on an exchange with no issue now

Re: The fake browser update scam gets a makeover

#179

Good ol' Krebs and Schneier ..either way too late to a scam, or ignoring other scams, or ineffectual regardless. What about those fake "download here" Adword buttons that have been a scourge of the web for the past decade or longer infecting untold millions of computers with malware. When will anyone bring that up.

Not sure if it's exactly the same thing as what you just mentioned, but I did write recently about criminals using paid Google ads to get their links for popular software downloads show up before even the first organic search result. And it includes the right icons and branding, and people click and are brought to a site that looks an awful lot like a site Microsoft might use to let you download Teams, and you get an…

Are people at Google even manually reviewing any of this? They have so many people there you would imagine it's not an impossible thought.

Re: The fake browser update scam gets a makeover

#180
post #18

Earlier quoted context omitted.

>I'll never understand why the default stance on HN is always javascript bad. I am a web dev, and I agree that JS on the web is bad for pages that should be just documents like a news webpage or wiki page. JS makes sense for applications like a video game, video/audio/level/text editor, or some internal app that your company trust, but for random untrusted document pages JavaScript is a detriment, even if we only con…

You're a web developer but your mental map of the web consists of "documents" on one end and "applications like a video game, video/audio/level/text editor(s)" on the other? You haven't in your career, stumbled across web (sites/apps) that sit somewhere on the spectrum between the extremes of "document" vs "app"? It strikes me that there's a fairly even distribution between those two points - even if we discount all…

Most links we opened daily are to read stuff not to interact with stuff, either read documentation, read news, read some social media page. Those pages should be readable without scripting but for some reason they do not load at all without JS.
Post reply on HN