And yet everything is open source and easily auditable. Most likely OP got pwnd and clearly is unable to understand sarcasm. You all really think that hotio snuck a crypto miner in somehow with all clearly open source code - and not a single person but OP noticed for years?
With the SSH/NPM supply chain attack, we all live in fear now. It just need one very smart person to deploy such hack. I'm not saying hotio did something, all I am saying that with new information, we all should check our deployment. Along with OP I'm affected, where I never have exposed the docker to world ever. So we should not deny the possibility of something off here.
Untitled topic
41–50 of 53 posts
Re: undefined
#42Earlier quoted context omitted.
Brand new account, 7 different comments on this post, all aggressively trying to discredit it. A bit suspicious, don't you think?
Nope. How else are they supposed to make comments if they didn't have an account here yet? I had to create this account just to answer you—is that suspicious too?
No, but if you were to make 6 more comments under the same post all saying the same thing in an overly confident and aggressive tone, it would be.
Re: undefined
#43Earlier quoted context omitted.
Nope. How else are they supposed to make comments if they didn't have an account here yet? I had to create this account just to answer you—is that suspicious too?
> I had to create this account just to answer you—is that suspicious too? No, but if you were to make 6 more comments under the same post all saying the same thing in an overly confident and aggressive tone, it would be.
Re: undefined
#44Earlier quoted context omitted.
Nope. How else are they supposed to make comments if they didn't have an account here yet? I had to create this account just to answer you—is that suspicious too?
It’s a fair observation. Their comments are extremely high confidence (failing to recognize that accidents and supply chain attacks do sometimes happen) and because they are new and posting frequently in the same thread, their account shows the signs of a bot/disinfo campaign (which does happen on HN).
Re: undefined
#45Re: undefined
#46Earlier quoted context omitted.
Lack of a tagged stable/release version with libtorrent 2.0 for one.
is there a final/stable release with it? also: is that really such a dealbreaker?
Probably not a dealbreaker for most but it might be hindering Bittorrent v2 adoption.
Re: undefined
#47Earlier quoted context omitted.
I never have exposed this container to the world ever, and my server do report the existence of such binary. That is the reason based on CPU usage I suspect that mining never triggered. > ps -ef | grep netservlet > root 3708105 3665360 0 08:06 pts/2 00:00:00 grep netservlet
that's just grep showing you your own grep process lol. you can do ps -ef | grep foobarbaroof and get the same thing...
My bad.
Re: undefined
#48Earlier quoted context omitted.
It’s a fair observation. Their comments are extremely high confidence (failing to recognize that accidents and supply chain attacks do sometimes happen) and because they are new and posting frequently in the same thread, their account shows the signs of a bot/disinfo campaign (which does happen on HN).
It's a completely useless observation. Doesn't add anything productive to the topic.
Re: undefined
#49Earlier quoted context omitted.
is there a final/stable release with it? also: is that really such a dealbreaker?
It's been supported by qBittorrent since 4.4.0 released in January 2022 when built with libtorrent 2.0. The official docker images still use libtorrent 1.2 though as that is the default. Probably not a dealbreaker for most but it might be hindering Bittorrent v2 adoption.
Looking at the downloads (I'm using brew) it seems that not many people uses libtorrent2… (https://sourceforge.net/projects/qbittorrent/files/qbittorre...)
Re: undefined
#50Earlier quoted context omitted.
Brand new account, 7 different comments on this post, all aggressively trying to discredit it. A bit suspicious, don't you think?
Nope. How else are they supposed to make comments if they didn't have an account here yet? I had to create this account just to answer you—is that suspicious too?
You and anotherlogin448 have neither, but also show incredible aggression towards anyone pointing that out.
Your confidence might actually be warranted, but there's no reason for any one of us to take you on your word, and neither of you have given anything else.