Live data from Hacker News

Pwned or Bot

troyhunt.com

51–60 of 89 posts

Re: Pwned or Bot

#51
post #45
post #26

I'll be a contrarian: I like it. Is it a black and white silver bullet one call destroys 'em all solution? Not even close. But, like he states in his article; from a "defence in depth" its another strong signal. Are you a bad guy just because you have a weirdo email (which I do)? No. Are you a bad guy just because you use tor? No. Are you a bad guy just because you're trying to make a purchase during an extreme surge…

> you're going to jump through a lot more hoops than someone with an ancient email and a residential ip address. I understand this kind of reasoning. At the same time I see a potential to snowball. This will encourage people to move away from weird addresses. Which will make it an even more effective filter and will justify stricter measures. So more people will move away. Etc.

Thats a really good point. I'm working through this space right now so I'm kind of myopic to stuff like this.

I use a self hosted VPN (digiOcean); but under duress, I'd be a jerk to me. tbh; most sites are, lol. I've given up youtube and google because I am reCaptcha'd to death...

To your actual point, I don't think it would be a deal killer per se in implementation. Weirdo@Weirdo.com isn't blocked because they show up in troys list of known emails.

Fakebook@Weirdo.com is suspicious in this model because it has not been seen before.

Re: Pwned or Bot

#52
post #40
post #36

Earlier quoted context omitted.

What do you have to do to get banned? I've seen people getting banned temporarily but I haven't heard of anyone getting banned permanently.

If you don't like somebody on Facebook you can report them for offensive content. I posted something that some asshole facebook friend didn't appreciate and they dug through my facebook feed and found one image that was borderline (somebody in politics in their drawers) and sent in a complaint to facebook. Got my account banned for a first strike. Same douche could have sent in more complaints and facebook would have…

What if my boss or neighbour didn't post anything that's against the TOS?

Re: Pwned or Bot

#53
post #40

Earlier quoted context omitted.

If you don't like somebody on Facebook you can report them for offensive content. I posted something that some asshole facebook friend didn't appreciate and they dug through my facebook feed and found one image that was borderline (somebody in politics in their drawers) and sent in a complaint to facebook. Got my account banned for a first strike. Same douche could have sent in more complaints and facebook would have…

What if my boss or neighbour didn't post anything that's against the TOS?

They absolutely have, just gotta dig.

Remember the wave of people being in hot water over tweets sent in 2008?

Re: Pwned or Bot

#54
post #40

Earlier quoted context omitted.

If you don't like somebody on Facebook you can report them for offensive content. I posted something that some asshole facebook friend didn't appreciate and they dug through my facebook feed and found one image that was borderline (somebody in politics in their drawers) and sent in a complaint to facebook. Got my account banned for a first strike. Same douche could have sent in more complaints and facebook would have…

What if my boss or neighbour didn't post anything that's against the TOS?

It's not about what's against the ToS, it's about getting the monkeys who review the reports to judge that it's against the ToS. Given their working conditions, they have little incentive in making an accurate determination and may just be pressing buttons at random, so spamming enough reports will eventually yield a ToS violation even on perfectly clean content.

Re: Pwned or Bot

#55
post #37
post #24

Earlier quoted context omitted.

I mean how can Facebook check government ID if it is legit? ( not how to photoshop ID. )

You generally can't actually check the government databases directly, but you can still determine this. First, companies can catch most fraudulent documents simply by looking at the document (eg. are the fonts all correct, does the checksum on the MRZ add up, does the data in the MRZ match the data on the face of the document, does the data on the document match previously collected data about the individual, etc.) S…

> eg. are the fonts all correct, does the checksum on the MRZ add up, ...

Is that hard?

A quick googling shows websites that will generate a California driver's license for virtually no money, so I'd assume with decent programming skills should be able to put together a generator.

See eg https://www.verif.tools/en/dl_ca/

Re: Pwned or Bot

#56
post #37

Earlier quoted context omitted.

You generally can't actually check the government databases directly, but you can still determine this. First, companies can catch most fraudulent documents simply by looking at the document (eg. are the fonts all correct, does the checksum on the MRZ add up, does the data in the MRZ match the data on the face of the document, does the data on the document match previously collected data about the individual, etc.) S…

> eg. are the fonts all correct, does the checksum on the MRZ add up, ... Is that hard? A quick googling shows websites that will generate a California driver's license for virtually no money, so I'd assume with decent programming skills should be able to put together a generator. See eg https://www.verif.tools/en/dl_ca/

That's the easy part. Checksum algorithms are public knowledge.

Re: Pwned or Bot

#57
post #25

Earlier quoted context omitted.

I wonder how many pwned email and password pair still match. Crooks can take control of these pwned accounts and pretend to be trustworthy.

It depends on the risk. I have an account that was pwnd (with the same password) but there is no risk to me as there isn't anything useful in that account (not even a DoB, Address or even a Name.) Worse case, someone changes the password and locks me out. Then I'll create another account as it's not a big deal.

The point would not be that it's a threat to you (though it may be), it's that compromised accounts (like one you don't care about) are a threat to an ecosystem that can't identify whether a "user" is a human or a bot.

That is, your compromised account could be used in an attack and it would look like a human.

Re: Pwned or Bot

#58
post #40

Earlier quoted context omitted.

If you don't like somebody on Facebook you can report them for offensive content. I posted something that some asshole facebook friend didn't appreciate and they dug through my facebook feed and found one image that was borderline (somebody in politics in their drawers) and sent in a complaint to facebook. Got my account banned for a first strike. Same douche could have sent in more complaints and facebook would have…

What if my boss or neighbour didn't post anything that's against the TOS?

Your question contains the implicit assumption that "TOS" is some bright shining line that everyone, from all posters, to all of the AIs and humans analyzing whether something conforms, completely agrees with. Therefore, "just don't break the TOS" is a reasonable solution.

This is manifestly and obviously false, in numerous ways. I don't even need to cite capriciousness, cultural differences, or potential political bias; even ignoring those things, it simply isn't and can not ever be a bright shining line.

This is even before we consider that TOSs have been known to retroactively change. YouTube just made such a change; doesn't affect whether the videos are removed but the retroactively changed the monetization standards, with large effect. "Just don't break the TOS" is a non-starter in such an environment.

Re: Pwned or Bot

#59
This feels a lot like email providers assuming that if you're running your own mail server, you must be spamming people.

This depends on the lack of use of good tools like FF's relay to anonymize accounts. I mean, HIBP is great, but Troy is self-consciously not interested in handling subaddressing, which would improve his service and its (mis)use in detecting "humanness".

Re: Pwned or Bot

#60
I think the problem bot vs real-person needs to be solved by the governments. Every government doing its own thing to tackle this wouldn't work, it would be great if they created an open-source project/standard that they implement. Alternative would be using bank accounts which is actually what Scandinavian countries do (e.g. in Sweden it is Bank ID) to verify that you are a real person.

All these methods of trying to recognize government ID pictures and etc. just seem very inefficient and not accurate enough for wide-spread use.

Unfortunately, not many governments are well-run to manage such solutions.

Post reply on HN