Live data from Hacker News

FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

pcmag.com

41–50 of 66 posts

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#41
post #40

Would this be a news if it was not owned by FBI director? Do we really expect the FBI director to be responsible for this? He probably outsourced it to some company. This is an inflammatory headline.

it’s absolutely news worthy. we do (and absolutely should) have higher expectations of the head of one of the most powerful organizations in the world. said organization that goes after malicious actors makes it even more newsworthy.

Said organization has nothing to do with this e-commerce website.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#42
post #40

Earlier quoted context omitted.

it’s absolutely news worthy. we do (and absolutely should) have higher expectations of the head of one of the most powerful organizations in the world. said organization that goes after malicious actors makes it even more newsworthy.

Said organization has nothing to do with this e-commerce website.

Sure, but they do after hackers like the ones attacking Based Apparel.

I wouldn't hire a doctor either that has food poisoning every two weeks.

I wouldn't hire a security guard that gets held up often.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#43
post #33

Earlier quoted context omitted.

If you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.

My issue with this style of verification is more that it normalises running commands right in the terminal. Commands that come from place you kind of trust. And poof at some point it will contain some nefarious code. Instead of using a package manager (the curl to bash variant) or running these commands in a container/vm.

Agreed, this is the first thing I thought of too. Don't teach people to paste unknown commands into their terminal!

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#44
post #10
post #7

Earlier quoted context omitted.

It wouldn't be Chinese. It would be Russian.

To paraphrase Hickam's dictum, a phone can have as many sources of malware as it damn well pleases.

The topicality of this deep-cut joke is incredible.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#45
post #21

Oh, I also got one: https://wiki.archlinux.org/index.php?title=Special:CreateAcc... > To protect the wiki against automated account creation, we kindly ask you to answer the question that appears below (more info): What is the output of: LC_ALL=C pacman -V|sed -r "s#[0-9]+#$(date -u +%m)#g"|base32|head -1 Wait, they really do that...

If you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.

Then write and highlight exactly that! ( e.g. "Never copy or execute code you do not understand! This is only for people who already know what will happen! Confirm:")

Forget about teaching people bad patterns. It's annoying when others assume everyone experiencing something under the same context and considers the same things as them.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#46
post #42

Earlier quoted context omitted.

Said organization has nothing to do with this e-commerce website.

Sure, but they do after hackers like the ones attacking Based Apparel. I wouldn't hire a doctor either that has food poisoning every two weeks. I wouldn't hire a security guard that gets held up often.

Never trust a skinny chef.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#48

For people that can't grok the title and the article like me: - BasedApparel.com is a website owned by a person that happens to be the FBI director now. (he owned it before he became the director if it matters) - The website BasedApparel.com was hacked and the hackers added a malicious click here to verify you are human section that tried to have you download a malicious payload if you were on macos.

> he owned it before he became the director if it matters All the more reason that those who "serve" in the government should be required to divest of their business interests. The traffic such a site would get due to the tribalism prevalent in US politics makes it a fat target, and potentially a national security threat.

This is not good. What it achieves, is that the quality of people who assume office sinks even lower than it is today, since anyone with a modicum of competence, would never divest a business for a low paid, public job.

On the other hand... you _do_ have a point here. Care must be taken to make sure that the persons business does not profit by the PR and media exposure related to the position they are taking.

I don't know how to do this. Maybe someone else runs their business at arms length? Maybe tracking the revenue and profit to catch sudden upward swings?

And adding to this, it should of course be completely illegal for politicians, US and other nations, to profit from insider trading.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#49

Earlier quoted context omitted.

> he owned it before he became the director if it matters All the more reason that those who "serve" in the government should be required to divest of their business interests. The traffic such a site would get due to the tribalism prevalent in US politics makes it a fat target, and potentially a national security threat.

This is not good. What it achieves, is that the quality of people who assume office sinks even lower than it is today, since anyone with a modicum of competence, would never divest a business for a low paid, public job. On the other hand... you _do_ have a point here. Care must be taken to make sure that the persons business does not profit by the PR and media exposure related to the position they are taking. I don't…

I disagree. I think the caliber of public employee, and their integrity, would be much higher if they were "only" allowed to collect their salary.

No state employee would be allowed to run a business like this while employed where I live (sapphire-blue New England state FWIW). Government positions are fairly, but not extravagantly, compensated, prestigious and come with excellent benefits. They should not be an avenue for accumulation of riches. It clearly does not work well and we're not getting the country's best.

Re: FBI director's Based Apparel site has been spotted hosting a 'ClickFix' attack

#50
post #33

Earlier quoted context omitted.

If you can't understand that command before pasting it in your terminal, then you probably shouldn't be editing the Arch Linux wiki.

My issue with this style of verification is more that it normalises running commands right in the terminal. Commands that come from place you kind of trust. And poof at some point it will contain some nefarious code. Instead of using a package manager (the curl to bash variant) or running these commands in a container/vm.

Arch Wiki's core content is instructions of what commands to run right in the terminal.
Post reply on HN