Live data from Hacker News

Someone bought 30 WordPress plugins and planted a backdoor in all of them

anchor.host

361–368 of 368 posts

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#361

Earlier quoted context omitted.

Wealth odd distribution doesn't scale by definition. A malicious actor can possibly bribe some other actors, but they can't bribe them all. At large, the infosec nightmare should be society governed by corrupted plutocrats ruling pauperized populations through threat, lies and planned scarcity. We know how to write software with very few bugs just as sure as we know how to structure societies with very few corrupted…

> we know how to structure societies with very few corrupted people We do?

Sure. Their are plenty of theoretical way to do it, and even example of small communities that have put them in practice.

Looks very similar to the situation of proved correct code: it just never reached mass adoption and fail to win at scale when crappier alternative can propagate faster and occupy the ecological niche, that can then alter the ecosystem in ways that makes even less likely the most sound approach could gain enough traction and momentum to scale.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#362

Earlier quoted context omitted.

> we know how to structure societies with very few corrupted people We do?

Sure. Their are plenty of theoretical way to do it, and even example of small communities that have put them in practice. Looks very similar to the situation of proved correct code: it just never reached mass adoption and fail to win at scale when crappier alternative can propagate faster and occupy the ecological niche, that can then alter the ecosystem in ways that makes even less likely the most sound approach cou…

I'm doubtful. Which small communities that did this are you referring to? And is the thing that made them successful something that's just hard, or is it something innate to their being very small?

If it's the latter, I don't think that checks out; I interpreted "we know how to build societies that don't do this" as "we know how to build large-scale human systems that avoid these trends; systems that could exist at scale on earth today".

Otherwise the claim just ends up being "we know how to do this if we start tabula rasa" (fun thought experiment, can't happen) or "we know how to do this if we get rid of 99.9% of the population and go back to village-scale economies" (not worth it, and the process of getting there would be exploited).

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#363

Earlier quoted context omitted.

> What problems are solved by financial sovereignty? It's right there in the name. Some people believe that their assets should not be freezable or restricted by the whim of their local government-of-the-week. Cryptocurrencies have obviously solved this problem quite well or people wouldn't be complaining about how it has enabled more cybercrime (specialists, include cyber criminals, are often quicker to adopt trends…

Inability to evade the justice system is not something that most people would agree is a problem; quite the opposite. The rule of law is the thing that allows you and I to live in such relative splendor. If you remove the ability for courts to operate you will not be in a libertarian utopia, you will be a dystopian free for all where there is no one to uphold contracts or stop people from doing what they like when th…

> The rule of law is the thing that allows you and I to live in such relative splendor

Speak for yourself, I grew up in poverty. I also said nothing about Libertarianism and did not endorse it; Please do not inject your biases, patronize or turn this into a straw man. Do you want to actually address my argument?

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#365

Earlier quoted context omitted.

> the number of bugs and hacks observed are far enough from the desired value of zero Zero is not the desired number, particularly not when discussing "hacks". This may not matter in current situation, but there's a lot of "security maximalism" in the industry conversations today, and people seem to not realize that dragging the "security" slider all the way to the right means not just the costs becoming practically…

I know a lot of security researchers will disagree with this notion, but I personally think that security (& privacy, I'm going to refer to both as "security" for brevity here) are an overhead. I think that's why it needs to exist * and be discussed* as a sliding scale. I do find a lot of people in this space chase some ideal without a consideration for practicality. Mind, I'm not talking about financial overhead for…

You're not wrong. The entire cybersecurity industry is a joke. You cannot play defense forever. You can only dig a bunker so deep, walls so thick, and areas so compartmentalized, before you have dug your own tomb and suffocated inside of it, or opened up a backdoor by tunneling through to the other side of the planet.

It's called cyberwarfare for a reason. After mounting a defense, you're expected to stage an offense to proactively eliminate threats and deter future intrusions by fear of response. The only countries that understand this are Israel, Iran, Russia and China. The rest of us are content to burden ourselves with enduring global cyber-siege forever and acting like we're anything other than livestock building our own pens around us.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#366

Earlier quoted context omitted.

> utility of the product falling down to 0. Today a bank really sent me a legitimate email about trying their new site. Went over, it was their site alright, logged in with correct username and password - poof, instantly blocked for suspicious access (from my usual home machine), call helpline to fix. Now that's safe ... and useless. But safe.

Reminds me of repl.it, which perma-blocked my newly created account before I even had a chance to type in e-mail verification code; in fact the notice about account block came before the one-time e-mail verification code. I still wonder what did I do wrong (support isn't responsive). But it's true that we're both safe from having a user/vendor relationship now.

This happens to me when I inherit phone numbers previously flagged for fraud, then try to sign up for new services. My email is clean (I'm not a fraudster) but they ban me on sight based on association with a bad number since I never bother with the transfer process.

I always have to deal with this for the first year after changing carriers.

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#367
post #142

Earlier quoted context omitted.

> This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. Mythos will most likely not be the main thing that changes the infosec world, but AI in general will. Maybe in a few years or…

IMO the thing that AI will change is the type of target. It's reasonable to assume that if you launch a website for a small business nowadays - sure, you'll get phishing attempts, port scans, attempts to submit SQL injections into your signup forms, etc. But you won't get the equivalent of a sophisticated actor's spear-phishing efforts, highly customized supply chain attacks on likely vendor data, the individualized…

Imo hacking

Re: Someone bought 30 WordPress plugins and planted a backdoor in all of them

#368
post #142

Earlier quoted context omitted.

> This is a perfect illustration of what cracks me up about the hyperbolic reactions to Mythos. Yes, increased automation of cutting-edge vulnerability discovery will shake things up a bit. No, it's nowhere near the top of what should be keeping you awake at night if you're working in infosec. Mythos will most likely not be the main thing that changes the infosec world, but AI in general will. Maybe in a few years or…

IMO the thing that AI will change is the type of target. It's reasonable to assume that if you launch a website for a small business nowadays - sure, you'll get phishing attempts, port scans, attempts to submit SQL injections into your signup forms, etc. But you won't get the equivalent of a sophisticated actor's spear-phishing efforts, highly customized supply chain attacks on likely vendor data, the individualized…

imo hacking
Post reply on HN