Live data from Hacker News

4chan Sharty Hack And Janitor Email Leak

knowyourmeme.com

941–950 of 1001 posts

Re: 4chan Sharty Hack And Janitor Email Leak

#941
post #922

Earlier quoted context omitted.

That’s not what the stats show. WordPress powers 43% of websites today. Shopify, Wix, and Squarespace together only account for 11%. https://w3techs.com/technologies/overview/content_management

Here's their "10 popular sites using Wordpress" - microsoft.com - It's not wordpress, probably home grown - wordpress.org - This one's a freebie - digicert.com - Using Adobe Experience Manager, per script includes - wordpress.com - Another freebie - mozilla.org - No, using a homegrown CMS: https://github.com/mozilla/nucleus - nih.gov - It's using Drupal, per a meta generator tag - forbes.com - No real for or against…

Most of those do in fact seem to use WordPress for part of their site:

* microsoft.com – uses WP at devblogs.microsoft.com

* digicert.com – may be a false positive, they link to files at /wp-content/ URLs, maybe they used WP in the past and kept the URLs?

* mozilla.org – uses WP at blog.mozilla.org

* nih.gov – uses WP at directorsblog.nih.gov

* forbes.com – can’t tell, my ad blocker breaks their cookie consent screen

* archive.org – uses WP at blog.archive.org

* nginx.org – uses WP at blog.nginx.org

* ebay.com – may be false positive?

We end up with 2/10 potential false positives, and one unknown (and even then, those are huge sites, who knows if they’ve got WP hiding under some deeply-buried subdomain).

I agree with you that Microsoft and TechCrunch probably aren’t FTPing their files in, but even if we assume that only 50% of WordPress sites are doing so, that’s still more websites than the next 10 competitors, combined!

If you think about it, this makes sense: do you reckon your local small businesses have a TechCrunch-level web presence, or are they using GoDaddy? Now consider that there exist many more local businesses than TechCrunches.

Re: 4chan Sharty Hack And Janitor Email Leak

#942
post #934

Earlier quoted context omitted.

Well, everyone who wanted to join was able to do it. Constant media attention informed everyone and the dog about it.

Sure, everyone who wanted to join, could. That doesn't mean that the same kind of people want to join orstick around. Even sites like Twitter and Facebook have pretty different userbases, despite being pretty similar.

I guess I should set the reference point.

I remember the time when normal internet users who visited imageboards simply couldn't figure out what was happening, and went back to normal sites (sometimes in disgust). There were no tourist guides written by journalists for the general public. Big forums had informational topics teaching users who “internet trolls” are (starting a short period when any argument which someone didn't understand, or pretended to, was automatically called “trolling”). Someone who used imageboard slang on a regular site was seen as an underage idiot (and certainly looked like one to outsiders), and could find that his accounts with “original” passwords no longer belonged to him (because internet was serious business). Oh, and if someone wrote a post praising some politician, no one needed an explanation that it was a satire that made fun of people believing in “supporting our candidate”.

Compared to that, and after 15+ years, 4chan public is pretty normal, even if it is not exactly the same as on some other site.

Re: 4chan Sharty Hack And Janitor Email Leak

#943

Earlier quoted context omitted.

That checks out. Years ago I noticed a vulnerability through the photography board. You'd upload your pictures, and 4chan would display all the EXIF info next to the post. 4chan's PHP code would offload that task to a well-know, but old and not very actively maintained EXIF library. Of course the thing with EXIF is that each camera vendor has their own proprietary extensions that need to be supported to make users ha…

> Just with a bunch of extra features hastily grafted and grown organically, but never dealing with the insane amount of technical debt. This describes probably 95%+ of the entire software world, from enterprise, to SaaS to IoT to mobile to desktop to embedded... Everything seems to be hastily thrown together features that barely work and piles of debt that will never get fixed. It's a wonder anything actually even w…

> If cars (the non-software parts) were made like this

The critical software parts of cars (non user-facing entertainment systems gripes aside). Think engine control modules, ABS, etc.

This stuff is mission critical and almost always works. I think about that a lot.

Re: 4chan Sharty Hack And Janitor Email Leak

#944

Earlier quoted context omitted.

> Then some morons connected them to the internet for no good reasons. Bad engineering at this point. To be fair, we could have had good car OS, good smartphone OS. But we didn't because everyone wanted to have their own pie castle. Imagine a smartphone that was actually useful. Or a car OS that supports you with repairs. Possible, but not wanted by manufacturers.

Use a proper RTOS kernel with a good UI layer, and see all the developers complain loudly because they can't use the latest mobile phone stacks on that robust platform. Sony boots a RTOS Linux system on their cameras in 3 seconds flat, and the firmware is arguably mission critical for that camera. It can be done for an infotainment system.

> Sony boots a RTOS Linux system on their cameras in 3 seconds flat, and the firmware is arguably mission critical for that camera. It can be done for an infotainment system.

Is stuff like this documented anywhere? This is one software topic I find endlessly fascinating but can't find any resources on.

Re: 4chan Sharty Hack And Janitor Email Leak

#945

Earlier quoted context omitted.

And the Zizian murder cult sprang out of the bay area rationalist community and trans rights advocacy, what's your point?

You say this like the rationalist community and 4chan edgelords aren't two circles with an incredible amount of overlap.

> You say this like the rationalist community and 4chan edgelords aren't two circles with an incredible amount of overlap.

They are not.

Rationalists are the crowd that would attract typical Bay Area tech yuppies. Which is something that 4chan seems to despise with passion and makes merciless fun on.

Just go on /g/ (the technology board) and see any mentions of bay area, rationalists, or tech companies/startups. If you believe there is a significant overlap, then they surely are hiding it really well there by mercilessly mocking everything related to any of those topics.

Re: 4chan Sharty Hack And Janitor Email Leak

#946
post #260

Earlier quoted context omitted.

Aka how Facebook originally launched (.edu-only) Social network culture is a multipart problem: 1. You need quality posters 2. You need to provide value to those posters 3. You need to remove low-quality posts attracted by site growth Any system that creates the above will be successful. The rub is that the humans behind (1) are free agents, with little incentive to stick to the site once (2) fails. Hence rapid Digg-…

You forgot problem 4: You need to provide your VC ownership a profitable exit. This plays off problem 3. Growth-focused social media platforms don't want to remove anything but the noisiest noise, because there's still a pair of monetizable eyeballs behind most sources of noise. In fact, if you can be particularly noisy, you generate drama, which makes the platform emotionally salient and thus stickier. How this appl…

> Growth-focused social media platforms don't want to remove anything but the noisiest noise, because there's still a pair of monetizable eyeballs behind most sources of noise. In fact, if you can be particularly noisy, you generate drama, which makes the platform emotionally salient and thus stickier.

This depends if a platform is building for quality or quantity.

There are a number of things HN could do tomorrow that would substatially drive engagement, but lower quality.

Granted, VC funding requires growth-at-all-costs, which tends to remove quality as a long term option.

> Digg collapsed because they replaced the entire website with something completely different. They didn't fail to moderate the community, they just shut it down.

Eh, as someone on it at the time, Digg's userbase collapsed before the redesign.

This roughly tracks with my memory: https://www.reddit.com/r/explainlikeimfive/comments/3bzibi/c...

I remember the HD-DVD/Blu-ray encryption key episode especially being an 'Oh, you're a square, not one of the cool kids' community moment.

Re: 4chan Sharty Hack And Janitor Email Leak

#948

Earlier quoted context omitted.

That checks out. Years ago I noticed a vulnerability through the photography board. You'd upload your pictures, and 4chan would display all the EXIF info next to the post. 4chan's PHP code would offload that task to a well-know, but old and not very actively maintained EXIF library. Of course the thing with EXIF is that each camera vendor has their own proprietary extensions that need to be supported to make users ha…

> Just with a bunch of extra features hastily grafted and grown organically, but never dealing with the insane amount of technical debt. This describes probably 95%+ of the entire software world, from enterprise, to SaaS to IoT to mobile to desktop to embedded... Everything seems to be hastily thrown together features that barely work and piles of debt that will never get fixed. It's a wonder anything actually even w…

To be fair, a car isn't accessible to 8 billion+ people at any given second. That's the scary part about the internet now. You can't just have a fun little garden and only have to protect the veggies from rabbits. Them gnawing on your lettuce is your biggest issue. Now, you have to protect your veggies from essentially professional armed raiders who either burn your garden to the ground for lolz or a cryptocoin ransom.

In this day and age, like... is anything secure at this point? You say hastily... but even the biggest "walls" get breached, constantly. Just claiming hastily to feel better about your own glass walls is just as bad.

Re: 4chan Sharty Hack And Janitor Email Leak

#949
post #857

Earlier quoted context omitted.

> but outsourcing that decision to a reddit mouth-breather whose only qualification for moderating is that he showed up to r/whatever back in 2013 before anyone else is not the way to detect those differences. Spez once compared these people to a landed gentry; they are not unlike domain squatters. Notably, 4chan is basically identical in this regard. I’ve been banned from /lit/, /trv/, and /his/ for posts that the j…

You described stackoverflow. People aren't banned elsewhere because they have nothing to say, not because moderators are better. Those same mods ban for certain posts about Discord. Coincidence?

> People aren't banned elsewhere because they have nothing to say, not because moderators are better.

I don’t understand what you mean.

Re: 4chan Sharty Hack And Janitor Email Leak

#950
post #81

Earlier quoted context omitted.

Sure, if you slap Basic Auth with "admin:admin" on phpMyAdmin in 2025, you're asking for it. But a Basic Auth password with 256 bits of entropy is just as resistant to brute force as AES-256 (assuming the implementation is sound and TLS is used). It's not the protocol that's insecure, it's usually how it's deployed.

Only if it's only accessible via proper TLS (otherwise it's easy to read the user/pass with MITM as basic auth doesn't encrypt the user/pass). If there is no throttling/rate-limiting/banning then this setup allows for a lot of attempts, wether brute-force or dictionary.

"a lot of attempts" is doing a LOT of heavy lifting here.

If your password was a set of random letters (both upper and lower case) and numbers and 20 characters long, then even if you could attempt 1,000 logins/second (a very high number for an online attack), it would take a whopping 2,232,000,000,000,000,000,000,000 years.

If you could do 1,000,000 logins/second, an absolutely absurd number for an online attack, that only takes 3 zeros off that number.

Post reply on HN