Live data from Hacker News

Instagram's URL Blackhole

medium.com

41–50 of 52 posts

Re: Instagram's URL Blackhole

#41
post #30
post #18

Earlier quoted context omitted.

Serve it with content-type set to text/plain and browsers won't try to render it. You can try a random html file on github. If you click raw it'll get rendered as text.

This assumption has unfortunately led to countless security issues, at least in the past. The nosniff header (see https://developer.mozilla.org/en-US/docs/Web/HTTP/Reference/... ), was created because of this and should be added. While this probably works, you should also add a restrictive CSP (using the sandbox directive). Forcing the download (via Content-Disposition header) would likely be even better, but it is a…

Replying to this comment because though it's vague in specifics it reads as authoritative and knowledgeable. In reality, it confuses/conflates multiple things.

Serving HTML source as text/plain is safe. No browser capable of understanding CSP is going to be at risk of anything that CSP would actually protect against in this case.

Re: Instagram's URL Blackhole

#42
With default uBlock Origin filters on mobile Firefox, all Medium blogs show up as a blank page. Which in this day and age is akin to saying that the page is utterly broken.

Re: Instagram's URL Blackhole

#43
post #12

Earlier quoted context omitted.

But it's rated 4.4 stars! I'm guessing it hoovers your contacts and tries to get you to sign up for the IAP subscription.

The meta these days is bundling dodgy SDKs which turn the device into a residential proxy, which then gets sold on to the highest bidder. Mostly AI companies, whose desire to scrape literally everything has driven demand for that type of malware into the stratosphere.

Surely that doesn’t work very well on iOS devices unless you’re actively holding the location api open or something, which would be noisy.

Re: Instagram's URL Blackhole

#45
post #32
post #31

At this point it must be intentional that there's always something uncanny about these fake pages. That google logo is so old that if I see it I immediately know to get out of there. So I find it fascinating how there's always the odd typo, the old logo, the impossible combination of iPhone needing an antivirus, etc and I refuse to believe is incompetence.

Entirely intentional because they want to filter out anyone who can see how scammy it looks, so they don't waste their time. This is bulk spam stuff. If they are actually targeting you, it will look very real.

Is there a common guide that all scammers follow ?

Many people also claim this is the real reason behind grammatical errors in nigerian prince email scams.

Re: Instagram's URL Blackhole

#47

I want to thank you dear poster and author, I feel genuinely refreshed reading a short interesting post sans status quo topic. Waiting for the next part!

Right? It's so short and...just ends. Been too fatigued reading essays on just about everything. I loved this one.

Strangely enough I enjoyed this abrupt ending, too. The lack of typical "It's not the end — it's just the beginning!" turned out surprisingly refreshing.

Re: Instagram's URL Blackhole

#48
Blackhole is the name of one of the services used in display-time malicious content filtering.

I’m guessing the urls in that db were either generating a ton of backend load, so they were pushed to devices, or perhaps are customized on a per user basis for some reason

Re: Instagram's URL Blackhole

#49
post #29
post #15

Earlier quoted context omitted.

Almost unbelievable that they allow this - except of course they do, because scamware makes a ton of money via in-app purchase, and Apple gets 30%, so of course they do. I'm sure people will come out of the woodwork now to white knight for Apple and spin this somehow. But anything that offends their business model can be removed in minutes, while software that by its title violates the App Store rules is just here in…

I'm pretty sure that one made it through the review for some reason, you don't typically see these apps in the App Store.

there's a ton of these apps. if you turn off your adblock, use your iPhone for a bit and click a few ads, you'll find a bunch.

Re: Instagram's URL Blackhole

#50
post #15
post #6

Ironic the Apple App store allows a "phone antivirus" to exist.

Almost unbelievable that they allow this - except of course they do, because scamware makes a ton of money via in-app purchase, and Apple gets 30%, so of course they do. I'm sure people will come out of the woodwork now to white knight for Apple and spin this somehow. But anything that offends their business model can be removed in minutes, while software that by its title violates the App Store rules is just here in…

Quite an unhinged take.

The claim that malware "makes a ton of money" for Apple definitely needs a citation. I certainly don't believe it.

Obviously, Apple understands that the reputational damage from malware is more costly than any cut they might get from the miniscule sales of it. Apple might be evil (for some definition of "evil"), but they're not dumb.

Occam's Razor and Halon's Razor are aligned here. Apple would prefer this app not exist, but somehow it slipped through the review.

Post reply on HN