Live data from Hacker News

The fake browser update scam gets a makeover

krebsonsecurity.com

181–190 of 196 posts

Re: The fake browser update scam gets a makeover

#181
post #73

Earlier quoted context omitted.

Anybody can spin up a mirror node, even on the mostly centralized BSC. This is just a misunderstanding. Every public blockchain works this way afaik. I've even made a site for hosting webpages on Optimism: https://newgeocities.com The real discussion imo is that blockchain node operators should be pressured to respond to concerns about unwanted content. There's no reason they can't coordinate on filters in the same w…

Running a BNB Smart Chain full node requires 16 TB fast NVMe disk. "Anybody" cannot do it.

Again, that's for a validator node. If you're running a mirror that's not taking part in making new blocks, you don't need the speed, just enough space. It may not be always synced to the latest block but it should work.

I believe there's other requirements for BSC validators too, like staking a bunch of BNB.

Re: The fake browser update scam gets a makeover

#182
post #78

Earlier quoted context omitted.

The suffocating irony of this forum being called "Hacker News" when it is filled with comments like this never fails to amaze me. A truly unimaginative bunch.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

i like the Gridless Compute [0][1] project. check them out. crypto is not all just crime and environmental destruction IMO.

[0] https://news.rublex.io/gridless-uses-mining/ [1] https://africancrypto.com/gridless-enables-cheap-renewable-e...

Re: The fake browser update scam gets a makeover

#183
post #30

Earlier quoted context omitted.

It’s been great for gambling, cybercrime, and enabling the drug trade practically since its inception.

I really think Monero in particular deserves way more criticism for their practice. Bitcoin is one thing, Monero is created for and marketed towards cybercriminals, you don't need to be a communications expert to get that premise. I haven't seen it used once for any legitimate purpose. Atleast with Bitcoin and Ethereum you can get buy some legitimate things like VPNs or NFTs https://arstechnica.com/information-techno…

you can do the same with XMR. for example Mullvad accepts XMR and BTC.

Re: The fake browser update scam gets a makeover

#184
post #150

Earlier quoted context omitted.

Very over the top, but bear with me. For example: if your community of plugin developers cannot produce secure(ish) plugins, then it's probably time to get rid of the plugin system altogether. "Plugins endanger our users, we no longer allow them." Being a player that powers a vast part of all websites, gives a responsibility. Taking up that responsibility includes making unpopular decisions. While "getting rid of the…

Do what Chrome has done and continually improve plugin security. Plugins should ask for permissions. Would require an overhaul of WP though.

That, and/or a sandbox model where plugins cannot escape a sandbox.

And/Or a setup where a plugin's runtime is isolated from main WP and other plugins and it can only communicate with WP over a tiny and very much hardened API.

so many possibilities. This problem has been solved mostly. Just not for PHP (that I know) and certainly not for WP.

Re: The fake browser update scam gets a makeover

#185
post #119
post #80

Earlier quoted context omitted.

seems like "blockchain" has nothing to do with it... they could just host the file on a server they do control. "Blockchains" aren't magic.

Blockchains - that is, the communities that use them - are at least theoretically committed to immutable permanent records of everything that happened. By design, if you tried to "retroactively" edit the contents of the blockchain, you would break the whole thing. So if the blockchain hosters stick to their avowed principles and system design, they can't remove your exploit code without taking down their whole system…

In fact the blockchain cannot be broken because it is a chain. Compare it to git commits. If you would hack away one commit in the middle, the whole system would change. The other commits are comparable to any other transaction (ledger) that happened anywhere. As far as i understood, 'in blockchain' =='carved in stone' .

Re: The fake browser update scam gets a makeover

#186
post #155

Earlier quoted context omitted.

> It seems like they (like Cloudflare, or a regular hosting service) are opening themselves up to all sorts of risks by serving arbitrary content. That's pretty much any website that accepts user input or integrates with an external service. I could post a base64-encoded malware to HN too, it would just get caught a lot faster (wasn't this a real thing on reddit?). I think the trick here is that it doesn't look out o…

Yes, but the HN can easily remove offending content. How do you remove something from blockchain?

The gateway can remove it or otherwise change it since it's a middleman.

Re: The fake browser update scam gets a makeover

#187

Earlier quoted context omitted.

No absolute guarantee of forever.

I guess there are some ways the ethereum network can cease to exist, when that happens there are probably bigger things to worry about

Ethereum network doesn’t serve on 80 or 443

Re: The fake browser update scam gets a makeover

#189
post #119

Earlier quoted context omitted.

Blockchains - that is, the communities that use them - are at least theoretically committed to immutable permanent records of everything that happened. By design, if you tried to "retroactively" edit the contents of the blockchain, you would break the whole thing. So if the blockchain hosters stick to their avowed principles and system design, they can't remove your exploit code without taking down their whole system…

In fact the blockchain cannot be broken because it is a chain. Compare it to git commits. If you would hack away one commit in the middle, the whole system would change. The other commits are comparable to any other transaction (ledger) that happened anywhere. As far as i understood, 'in blockchain' =='carved in stone' .

If people actually follow the rules they claim they do then yes. In practice once you ask them to put their money where their mouth is people make an exception. Again see the Ethereum DAO incident.

Re: The fake browser update scam gets a makeover

#190
post #139
post #78

Earlier quoted context omitted.

Could you give some other concrete, practical examples of use cases for cryptocurrencies instead of the passive-aggressive snark?

You can generate this list yourself. Take your favorite payment provider (PayPal, Stripe, whichever bank provides your Visa/MasterCard, etc.), and look at their terms of service. Enumerate all the prohibited usages. From that list, delete illegal activities, of course. The remaining items on the list are your practical examples of use cases. It's roughly the set of things that are legal, but that big corporations hav…

> But hey, Bitcoin can also be used for CSAM, unlike VPNs, Tor, or cash, which is why the HN cognoscenti condemns it.

Straw man much?

Post reply on HN