Live data from Hacker News

Deleting System32\curl.exe

daniel.haxx.se

31–40 of 136 posts

Re: Deleting System32\curl.exe

#31

Earlier quoted context omitted.

You can't just disable this 'feature' from Vodafone? I'm in the UK and my ISP doesn't do this. I'm not sure why you would want your ISP interfering with your traffic like this. To me, it seems like a dealbreaker.

All UK ISPs do. It's very annoying trying to access sci-hub

>All UK ISPs do.

Not all of them. I’m on Zen, no filters as far as I’m aware, sci-hub works fine. Libgen is fine. Torrent sites that the ‘main’ ISPs block come up just fine, too.

Edit: some of the ISPs that do seem to land on this URL (note http) –

http://www.ukispcourtorders.co.uk

whois shows BT (large ISP and telco) as the owner.

Re: Deleting System32\curl.exe

#32
post #9

Earlier quoted context omitted.

Two xx's. That's almost as bad as three, and surely heuristically naughty.

It could also be to do with the word “hack” because https://hackmii.com/ is blocked too

Good thing there is no shake shack in the UK.

Re: Deleting System32\curl.exe

#33

Earlier quoted context omitted.

There are people responsible for the security of Windows systems in some organisations that do not understand their job. They look into their AV solution and it says vulnerable file detected on $x systems and they instruct their IT department to remove the file.

Indeed. Whole companies such as Crowdstrike exist just to sit in between automated tools and heavy-handed action based on tool output.

Ive been actually impressed by Crowdstrike product (I guess)

Ive tested a two or three years old Chrome version with JIT compiler vulnerability and guess what - on empty Linux vm it managed to escape chrome and execute code

Meanwhile on Windows with Crowdstrike Chrome just showed some error message about mem. access

Im not sure who handled that attack - was it Windows or Crowdstrike, but eitherway Ive been impressed

Re: Deleting System32\curl.exe

#34

Earlier quoted context omitted.

You can't just disable this 'feature' from Vodafone? I'm in the UK and my ISP doesn't do this. I'm not sure why you would want your ISP interfering with your traffic like this. To me, it seems like a dealbreaker.

All UK ISPs do. It's very annoying trying to access sci-hub

No, they don't all do that. Those kind of blocks are mostly confined to a handful of the larger ISPs, and especially the mobile providers. I've yet to manage to find something my current ISP blocks, for example. Might well be they block something, but none of the "usual suspects" that I'm willing to test (e.g. Pirate Bay, Sci Hub)

Re: Deleting System32\curl.exe

#35

Earlier quoted context omitted.

You can't just disable this 'feature' from Vodafone? I'm in the UK and my ISP doesn't do this. I'm not sure why you would want your ISP interfering with your traffic like this. To me, it seems like a dealbreaker.

All UK ISPs do. It's very annoying trying to access sci-hub

Andrews and Arnold doesn't do any filtering.

Re: Deleting System32\curl.exe

#36
post #12

Vodaphone blocks this site for being “18+ content”, I guess because of “hacking” or something? There’s no explanation or option to report a false positive and they want you to put in credit card details to confirm your age to unlock it (I don’t need tips to get around this or anything, I can just connect to another network or use a VPN)

Probably the xx in the domain. In the UK where 20% of the internet is blocked – it's surprising you haven't experienced this before. Call your service provider and tell them you want access to adult material.

> Call your service provider and tell them you want access to adult material.

That must be one awkward call.

Re: Deleting System32\curl.exe

#37
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

They deserve to not be allowed to restore their system to normal? > The people who deleted or replaced the curl executable noticed that they cannot upgrade because the Windows update procedure detects that the Windows install has been tampered with and it refuses to continue. This policy makes absolutely no sense.

Since the policy is going an extra mile preventing something rather than simply not caring, it probably does make sense. Just in a way that's not trivial to anticipate.

Re: Deleting System32\curl.exe

#38
Is there a windows equivalent of "chmod 0000 /file/to/be/made/unavailable" ? Even that seems pretty brutal but at least it's easily reversible if you discover that "oh I needed that to download the vendor patch that will _actually_ fix the problem"

Re: Deleting System32\curl.exe

#39

Earlier quoted context omitted.

>(I don’t need tips to get around this or anything, I can just connect to another network or use a VPN) A better solution would be to tell Vodafone to switch off the censorship on your service.

The best solution would be the remove whatever stupid law allowed for that kind of censorship in the first place. As a bonus, if the UK puts up a better fight against this stuff it'll make it harder for it spread. Any nation where people have a vote should be strongly rejecting that crap.

I'm happy for an ISP to be allowed to carry out as much censorship as it wants, provided it makes that known. They definitely shouldn't be forced to, though — in the general case — and I don't think anyone's demonstrated that they have been so in this case.

Re: Deleting System32\curl.exe

#40
post #2

People who delete system binaries due to whacky CVEs deserve a broken system. I don't even know who else to blame for this.

They deserve to not be allowed to restore their system to normal? > The people who deleted or replaced the curl executable noticed that they cannot upgrade because the Windows update procedure detects that the Windows install has been tampered with and it refuses to continue. This policy makes absolutely no sense.

curl is used to download files… if it is missing, Windows presumably won’t be able to download something. If they just go for it anyway, the system could end up in some undefined state.
Post reply on HN