Live data from Hacker News

CyanogenMod.com hijacked. Transition to CyanogenMod.org

cyanogenmod.org

51–60 of 113 posts

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#52
post #34
post #3

It seems a nice idea, buying the CM.com domain and donating it to the project. Wonder if this sleazeball had a change of heart, or was he planning on embezzling referral traffic the whole time?

I read: And due to the small size (and lack of funds), the CyanogenMod.com domain was bought by a third-party back in 2009 and donated to CM, when CM was a much smaller project and had no online presence besides XDA. I must be missing something (and speaking from a US perspective), but was $10 really unattainable in order to secure a domain? Three years worth would have been $30-ish dollars now. Genuinely curious wha…

I might have missed something, but it's not clear to me whether the original gifter is the person who hijacked the domain.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#54
post #30

I don't know what this is, but as the guy asked for money for the domains, which he didn't own, I'd think about asking the police to look into this being extortion.

I think he did/does own the domain, on behalf of cm. My best guess is that cm wasn't incorporated, so a human body had to own it. The human body then went full asshat.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#55
post #47

I'm mixed on whether this is a good way to handle reporting something like this to the public. On the one hand, they didn't release the guy's name, which is completely and entirely appropriate, and I commend them for doing so. On the other hand, giving so many details—many of which are not relevant to the public, and probably were not intended for the public—gives this PSA somewhat of a "well, screw you too" vibe. I…

Tell us the name of this rogue. I don't want to ever do business with the person, but how to know?

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#56

As of right now (4:34 EST) cyanogenmod.com redirects to cyanogenmod.org

Yup, I have the same thing. Is this a(nother) change of heart from the owner? Or did ICANN intervene that quickly? I find it hard to believe its the later.

I'm guessing a change of heart from the owner once things went public.

As you say, it's unlikely that there would be any intervention that quickly.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#57
post #47

I'm mixed on whether this is a good way to handle reporting something like this to the public. On the one hand, they didn't release the guy's name, which is completely and entirely appropriate, and I commend them for doing so. On the other hand, giving so many details—many of which are not relevant to the public, and probably were not intended for the public—gives this PSA somewhat of a "well, screw you too" vibe. I…

Keep in mind CyanogenMod is a community project, not some business or startup. Public and private are a bit more relative under those terms.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#58
post #30

I don't know what this is, but as the guy asked for money for the domains, which he didn't own, I'd think about asking the police to look into this being extortion.

The ownership is in question. This guy bought the domain in its early days and "donated" it to the project. Does he own it? What if he paid for its continued registration? Does CM own it under trademark? Given the nature of how CM got started, I doubt there was a formal agreement between the parties.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#59
post #40
post #22

The title was NOT sensationalist, and the change here is a loss of information. They aren't "transitioning" to a .org, their domain was stolen. the .com shouldn't be trusted at this point, as it has apparently been taken over by some rogue former-team-member. edit: thanks to the mod that fixed it :)

There is, so far as I've discerned, an automated bot running that changes submission titles to the HTML title of the URL. No human intervention, no human judgment.

This seems easy enough to test. Someone just needs to put up a page which changes the in-page TITLE to something new for every hit, and then let someone submit it. Then see if it changes, and what it changes to, and when. Then work backwards from the server logs to see who or what is doing it.

If it's a bot, you could have some random gunk in there, and it would flip over automatically. If it's human, they might not accept a (hex|base64|...) encoding of some magic number. Of course, said human could also read this, know what was going on, and modify their behavior accordingly.

Tricky.

Re: CyanogenMod.com hijacked. Transition to CyanogenMod.org

#60
Cyanogenmod devs need to get PGP keys and start using cryptographic signatures like now. The guy never would have been able to impersonate in the first place if they were doing this, and now it's even more important that the @cyanogenmod.com domain is directing to a different mail server.
Post reply on HN