Earlier quoted context omitted.
Can you please elaborate how it is "asking for it" if we assume the basic auth password is reasonably complex and kept as safe as, say, the SSH login credentials of the same server?
You shouldn't be logging in to a server via SSH using a user+password combo, instead use a public/private key combo which is considerably more complex and can't effectively be bruteforced like a user+password. Most web servers don't really come with any built in defense against brute force attempts vs Basic Auth gates, so unless you've set something up to protect it, someone with enough time will eventually get in.
4chan Sharty Hack And Janitor Email Leak
461–470 of 1001 posts
Re: 4chan Sharty Hack And Janitor Email Leak
#462Earlier quoted context omitted.
ive always wondered, is there a way to use technology on a board style wesbite to enforce a higher quality culture? i toyed with the idea of requiring an org email similar to Blind except it could be a school email too, the hope being that after verification you are fully anon still just now with write privileges and that it would somehow lead to better quality discussions and engagements
Aka how Facebook originally launched (.edu-only) Social network culture is a multipart problem: 1. You need quality posters 2. You need to provide value to those posters 3. You need to remove low-quality posts attracted by site growth Any system that creates the above will be successful. The rub is that the humans behind (1) are free agents, with little incentive to stick to the site once (2) fails. Hence rapid Digg-…
This plays off problem 3. Growth-focused social media platforms don't want to remove anything but the noisiest noise, because there's still a pair of monetizable eyeballs behind most sources of noise. In fact, if you can be particularly noisy, you generate drama, which makes the platform emotionally salient and thus stickier.
How this applies to 4chan is vague since 4chan isn't exactly a growth platform. Moot's VC ownership was his mom's credit card[0] and his exit was "panic selling to hiroyuki because Hollywood actors' lawyers are breathing down my neck". Hiroyuki himself is incredibly sketchy. As far as I can tell, he bought 4chan mainly because 2channel got rugpulled by his domain registrar[1], after 2channel also had a massive data breach. Funny how history repeats.
Anyway, imageboard ownership being a fractal mirror of the incestuous bullshit going on in big tech and far-right politics aside, once a social network or forum becomes big enough to be 'known', it tends to stick, because moving off those platforms is a collective action problem. So between you holding your friends mutually hostage and the drama from letting the dumbest idiots post on your site, you've created a powerfully addictive socialization substitute that can be manipulated to make people do whatever. Quality posters and value don't matter; in fact, once you're established you want the quality level to go down.
Digg collapsed because they replaced the entire website with something completely different. They didn't fail to moderate the community, they just shut it down. It'd be like if tomorrow Facebook said "we're not doing user posts anymore, we're just going to have a bunch of comment sections for videos from legacy media outfits". Everyone would leave immediately because there's no more mutual-hostage-taking by your friends.
[0] This is not to be confused with Canvas, a similar imageboard platform also started by Moot that lasted like a year.
[1] If you believe the guy who stole the domain, the data breach rendered 2channel unable to pay domain hosting fees. That being said, the guy who stole the domain is also the owner of 8chan and a huge QAnon nutter, if not Q himself, and stealing your client's website because they ran out of money is an extremely malicious move.
As far as anyone knows, hiroyuki got the money to buy 4chan from Good Smile Company. Yes, the people who made Nendoroids.
Re: 4chan Sharty Hack And Janitor Email Leak
#463Earlier quoted context omitted.
No, you'll need servers and enough network capacity to handle the load, an understanding and supportive hosting provider, a law degree or enough money to pay somebody with one to keep you out of court/jail/prison, a network of degenerates to provide traffic and content and/or a copy of the existing 4chan content, a stomach of steel to deal with the content moderation duties, and a moral compass so warped you think ho…
>a copy of the existing 4chan content 4chan's content is ephemeral. Most of it is gone every few days.
Re: 4chan Sharty Hack And Janitor Email Leak
#464Earlier quoted context omitted.
> bodybuilding.com Obligatory post about the dumbest argument to ever be had online [0]. It’s so good, the Wikipedia entry [1] has a section devoted to it. [0]: https://web.archive.org/web/20240123134202/https://forum.bod... [1]: https://en.wikipedia.org/wiki/Bodybuilding.com
For the record this is an example of the "Fencepost error" where the last item in a range gets double counted as the first item in the next range and is incredibly common in dyscalculia (the math version of dyslexia) as people will have "visual number lines" in their head that cover ranges of numbers but the ends get double counted, so there will be a 10-20 number line then a 20-30 number line. I suspect TheJosh had…
Re: 4chan Sharty Hack And Janitor Email Leak
#465Earlier quoted context omitted.
Sure, if you slap Basic Auth with "admin:admin" on phpMyAdmin in 2025, you're asking for it. But a Basic Auth password with 256 bits of entropy is just as resistant to brute force as AES-256 (assuming the implementation is sound and TLS is used). It's not the protocol that's insecure, it's usually how it's deployed.
Only if it's only accessible via proper TLS (otherwise it's easy to read the user/pass with MITM as basic auth doesn't encrypt the user/pass). If there is no throttling/rate-limiting/banning then this setup allows for a lot of attempts, wether brute-force or dictionary.
Re: 4chan Sharty Hack And Janitor Email Leak
#466Re: 4chan Sharty Hack And Janitor Email Leak
#467Re: 4chan Sharty Hack And Janitor Email Leak
#468I feel too many people conflate /pol/ with the whole website. I enjoyed browsing through sfw boards like /tg/ (tabletop media), /ck/ (cooking) and /fit/ (fitness). I had long discussions about the SW sequels on /tv/ back in 2015-19. The readership was surprisingly diverse and the anonymity lead users to provide more focused replies. With bodybuilding.com gone, the blue boards felt like the last bastion of the old int…
> bodybuilding.com Obligatory post about the dumbest argument to ever be had online [0]. It’s so good, the Wikipedia entry [1] has a section devoted to it. [0]: https://web.archive.org/web/20240123134202/https://forum.bod... [1]: https://en.wikipedia.org/wiki/Bodybuilding.com
Re: 4chan Sharty Hack And Janitor Email Leak
#469Earlier quoted context omitted.
Note, some of these are associated with the far right. > fren later came to prominence on sites such as 4chan and the subreddit /r/frenworld as a dog whistle used by far-right white nationalists and fascists to refer to each other https://en.m.wiktionary.org/wiki/fren
Why does that matter?
Re: 4chan Sharty Hack And Janitor Email Leak
#470Earlier quoted context omitted.
Aka how Facebook originally launched (.edu-only) Social network culture is a multipart problem: 1. You need quality posters 2. You need to provide value to those posters 3. You need to remove low-quality posts attracted by site growth Any system that creates the above will be successful. The rub is that the humans behind (1) are free agents, with little incentive to stick to the site once (2) fails. Hence rapid Digg-…
I would say that reddit quality has declined a huge amount, but people won't leave because there's a huge network effect. Nobody will join a reddit clone that is 95% functionally the same because there's nobody there. Every community that tried to migrate off reddit to a reddit clone has failed. As an example of why reddit is so bad now (aside from the obvious moderation issues) about 1-2 years ago, reddit added a bl…