Live data from Hacker News

On Getting Hacked

ahmeto.com

71–77 of 77 posts

Re: On Getting Hacked

#71
post #59
post #49

> TikTok deemed I should not have access to my account ever again, and X (formerly Twitter) is delaying a response to my appeal to the suspension, but I have not much hope; I reckon it's gone for good. I may have lost all the personal contacts and content from there, but on the bright side, that has taught and made me see some other things, besides the importance of being a little smarter to not blindly install exten…

Not sure why OSS is mentioned here, should just say "software". And it's always been like this (be careful).

> And it's always been like this

Not, it hasn't. The open source community was much smaller, and much more tightly knit 20 years ago, and it was intrinsically much higher-trust.

Re: On Getting Hacked

#72
post #22
post #5

> open their password manager which also might need you to authenticate, type in their master password, search for the name of the said website, copy the password, paste it in This is one way to guarantee you'll eventually fall for a phishing attack. Are we really running URL-unaware password managers in the year 2026?

>Are we really running URL-unaware password managers in the year 2026? URL-aware browser plugins for autofilling passwords can also make people _more_ susceptible to phishing . The password managers plugins sometimes not working correctly changes the Bayesian probabilities in the mind such that username/password fields that remain unfilled becomes normal and expected for legitimate websites . If that happens enough,…

Wrong. If my password manager doesn't auto-fill I'm am immediately far more wary. If I didn't have any URL matching in the password manager then I would very quickly stop paying close enough attention to the URL because I'd have to do it too frequently.

Re: On Getting Hacked

#73
post #71
post #59

Earlier quoted context omitted.

Not sure why OSS is mentioned here, should just say "software". And it's always been like this (be careful).

> And it's always been like this Not, it hasn't. The open source community was much smaller, and much more tightly knit 20 years ago, and it was intrinsically much higher-trust.

Maybe out of ignorance, but that didn't span every internet subculture.

The whitehats/grayhats have always been super paranoid.

Re: On Getting Hacked

#75
post #73
post #71

Earlier quoted context omitted.

> And it's always been like this Not, it hasn't. The open source community was much smaller, and much more tightly knit 20 years ago, and it was intrinsically much higher-trust.

Maybe out of ignorance, but that didn't span every internet subculture. The whitehats/grayhats have always been super paranoid.

Were you active on SF or Savannah 20+ years ago? Everyone knew everyone else, and it was a much higher-trust society (think Minneapolis before Somalis).

> The whitehats/grayhats have always been super paranoid.

Yeah, they were always "super paranoid," but it was about something that could, and admittedly eventually did happen--but not for many years later. I remember in the Perl community, there was a big scandal where some module was "phoning home" on install (for the sake of telemetry), which the author fixed in response to the outcry. I remember a hapless Debian contributor who, in an attempt to silence Valgrind warnings, inadvertently reduced the entropy used for keygen (after some miscommunication with OpenSSL upstream), and was unfairly accused by some of intentionally backrdooring it. That was the extent of OSS malware back then.

Then along comes Github, and lets anyone upload anything, doesn't do even the minimal vetting of forcing you to explain what your project is and why it should be on GH, doesn't make you explicitly select an OSI-approved license, lets your freely fork other people's projects and even duplicate the project's name (making it difficult to identify canonical repos). It fosters a culture of just forking whatever you want, pulling in whatever you want, uploading any codeslop, ecourages MIT over copyleft, and has gamified crap like star rankings and activity graphs.

Re: On Getting Hacked

#76
post #75
post #73

Earlier quoted context omitted.

Maybe out of ignorance, but that didn't span every internet subculture. The whitehats/grayhats have always been super paranoid.

Were you active on SF or Savannah 20+ years ago? Everyone knew everyone else, and it was a much higher-trust society (think Minneapolis before Somalis). > The whitehats/grayhats have always been super paranoid. Yeah, they were always "super paranoid," but it was about something that could , and admittedly eventually did happen--but not for many years later. I remember in the Perl community, there was a big scandal wh…

I dabbled in a lot of mid-to-late 90s scenes, especially in irc, including w00w00. We were sharing a lot of code between "trusted" members.
Post reply on HN