Live data from Hacker News

So this guy is now S3. All of S3

chaos.social

1–10 of 522 posts

Re: So this guy is now S3. All of S3

#5
Solution is also on the works like use /.well-known/, so this is more like funny, rather than a big problem.

Key to trick was to have bucket named "xrpc" and store a file there: https://s3.amazonaws.com/xrpc/com.atproto.identity.resolveHa...

There is also another funny thing in the image, the user posting about is sending one from "retr0-id.translate.goog", which is odd. Somehow he has got https://retr0-id.translate.goog/xrpc/com.atproto.identity.re... to redirect to his page, and gotten that handle as well.

Re: So this guy is now S3. All of S3

#8
This is why mastodon , webfinger and ACME uss .well-known uri prefix. .well-known is reserved and you can't e.g. make a bucket named .well-known

It's funny the bluesky devs say they implemented "something like webfinger" but left out the only important part of webfinger that protects against these attacks in the first place. Weird oversight and something something don't come up with your own standards

Re: So this guy is now S3. All of S3

#10
Without understanding all the context, why not just serve files directly from your smartphone? You can approve your own contact list and share keys.

Yes, of course bandwidth is a concern, but then again there should be our way to monetize, and that's entirely possible using direct payments which already exist.

A little bit of cashing, CDN, and your phone as the initial file server. Tag a photo or video has shared.

Really it's just an RSS feed and CDN.

Post reply on HN