Live data from Hacker News

Still standing

blog.4chan.org

41–50 of 71 posts

Re: Still standing

#41
post #10

they were clearly focused on purchasing hardware over writing secure code

I agree. It is interesting how much they focus the hardware servers in the article. I'd be more interested knowing which package was vulnerable?, was it a known exploit?, and what systems were/are in place to alert on vulnerable dependencies?. Instead they are focused on the new servers just taking too long and not enough money because of advertiser pressures.

They do mention their OS being out of date. One possible interpretation is they are using packages provided by a Linux distro, and getting up to date may have required a full OS update.

If that's were case, it would be easy to see how they might want to tie their OS upgrade to a hardware refresh rather than taking servers offline for a reinstall.

Re: Still standing

#42
post #10

they were clearly focused on purchasing hardware over writing secure code

I agree. It is interesting how much they focus the hardware servers in the article. I'd be more interested knowing which package was vulnerable?, was it a known exploit?, and what systems were/are in place to alert on vulnerable dependencies?. Instead they are focused on the new servers just taking too long and not enough money because of advertiser pressures.

According to a Firebase video [0], the outdated and exploited package was called GhostScript.

[0] https://youtu.be/XNratwOrSiY?si=dxfD8Y7-wfOi0XcJ

Re: Still standing

#43

Earlier quoted context omitted.

Just in case you're not citing that old debunked free speech trope ironically, please see: "Don’t Use These Free-Speech Arguments Ever Again" by First Amendment expert Ken White ( https://www.theatlantic.com/ideas/archive/2019/08/free-speec... ).

I have no idea what you are talking about, and I am unable to read the article as it is behind a paywall.

https://archive.is/iZC4v

Hopefully, that works. It's the first time I've done an archive like that. It works for me, but it always did because I'm using the Bypass Paywalls Clean add-on in Firefox https://gitflic.ru/project/magnolia1234/bpc_uploads

Re: Still standing

#44

Earlier quoted context omitted.

Just in case you're not citing that old debunked free speech trope ironically, please see: "Don’t Use These Free-Speech Arguments Ever Again" by First Amendment expert Ken White ( https://www.theatlantic.com/ideas/archive/2019/08/free-speec... ).

I have no idea what you are talking about, and I am unable to read the article as it is behind a paywall.

[deleted]

Re: Still standing

#45
post #9

being starved of money for years by advertisers, payment providers, and service providers Given the language in this announcement that lays blame at everyone else's feet except the people responsible for maintaining the platform, I'm pretty sure that no lessons were learned, and that the security is not likely to improve beyond whatever bandaids that were needed to address this hack.

Get real. Companies with infinitely more money, staff, and robust security practices are hacked every day. The only difference is they put out a vague generic corpospeak statement whereas this one admitted it was caused by a skeleton crew on a shoestring budget getting caught out. Given the nature of their user base and how many others would love to see 4chan go down, if things were as bad as you imply then hackers w…

Source?

I have never heard of a bank’s core mainframes being hacked in the last decade (outside of pen tests), even for mid size banks outside the global top 100.

Re: Still standing

#46
post #42
post #10

Earlier quoted context omitted.

I agree. It is interesting how much they focus the hardware servers in the article. I'd be more interested knowing which package was vulnerable?, was it a known exploit?, and what systems were/are in place to alert on vulnerable dependencies?. Instead they are focused on the new servers just taking too long and not enough money because of advertiser pressures.

According to a Firebase video [0], the outdated and exploited package was called GhostScript. [0] https://youtu.be/XNratwOrSiY?si=dxfD8Y7-wfOi0XcJ

Fireship is the channel name - firebase is the product he initially had based his channel off

Re: Still standing

#47
post #16

>One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files. Wow, this is a pretty incredible level of incompetence. Server-side SWF exploits are easily mitigated, unless they are using some sort of server-side SWF interpreter, which is absolutely not needed if you implement client-side Ruffle (or just require people to instal…

You can always volunteer to help "the incompetents".

Re: Still standing

#48

Earlier quoted context omitted.

Get real. Companies with infinitely more money, staff, and robust security practices are hacked every day. The only difference is they put out a vague generic corpospeak statement whereas this one admitted it was caused by a skeleton crew on a shoestring budget getting caught out. Given the nature of their user base and how many others would love to see 4chan go down, if things were as bad as you imply then hackers w…

Source? I have never heard of a bank’s core mainframes being hacked in the last decade (outside of pen tests), even for mid size banks outside the global top 100.

What are you talking about? There are massive breaches of huge companies who should be doing better all the time.

In 2017: > More than 40% of the population of America was potentially impacted by the Equifax data breach.

In 2022: > In September 2022, Optus experienced a major data breach that exposed the personal information of millions of customers

That's just 2 off the top of my head.

Re: Still standing

#49
post #16

>One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files. Wow, this is a pretty incredible level of incompetence. Server-side SWF exploits are easily mitigated, unless they are using some sort of server-side SWF interpreter, which is absolutely not needed if you implement client-side Ruffle (or just require people to instal…

It seems that you're thinking about the SWF content in terms of playback, which is not what they were doing. They were looking inside the bundles for ZIP files and malware (4chan users to shove horrible things into the files they upload), and extracting metadata from the SWF. We'll never know the exact details unless they share the source code. It is possible to write a secure SWF parser, but I think they decided to stop supporting this relic instead.

> Ruffle

Yes, they used that. Take a look at the board.

Re: Still standing

#50

Earlier quoted context omitted.

I have no idea what you are talking about, and I am unable to read the article as it is behind a paywall.

https://archive.is/iZC4v Hopefully, that works. It's the first time I've done an archive like that. It works for me, but it always did because I'm using the Bypass Paywalls Clean add-on in Firefox https://gitflic.ru/project/magnolia1234/bpc_uploads

So, you can yell "fire" falsely and cause a stampede?

Alex Jones would like a word with you.

Post reply on HN