12 ms·
Did I just win?
- Jeremy1026 10y agoTroll level = 100%
- aaroninsf 10y ago[[ obligatory reference to Betteridge's law ]]
- notatoad 10y agoBut this is actually a violation of betteridge's law. He did win.
- LeoPanthera 10y agoIt's also not a headline, so it doesn't apply anyway.
- mistercow 10y agoIt's Betteridge's Second Law: the answer to any question is "no". It really simplifies things.
- garethadams 10y agoDoes it?
- mpnordland 10y agoPolice: Are you a law abiding citizen? You: No Police: Come with me, please.
- aaroninsf 10y agoOn Hackernews, it's a headline...
- msoad 10y agoSocial Engineering is not accepted in most hacking contests.
- sinneduy 10y agoi mean, he accepted it
- TrevorJ 10y agoInteresting discussions to be had as to why this is the case. I suspect it would make it too easy.
- untog 10y agoI suspect it's just because there are too many variables. Social Engineering isn't exactly a replicable science.
- clavalle 10y agoIndividually, no, but statistically...perhaps?
- untog 10y agoPerhaps. There's also the depressing reality that you can't actually stop social engineering conclusively. A sysadmin is always going to need to have a login with administrative privileges, and they're always going to be fallible.
- clavalle 10y agoTrue. This thread has me thinking about how a controlled social engineering hacking event might play out just for the sake of education and awareness. (especially since one of my clients got hit badly with a phishing attack recently...less than a single percentage 'success' rate by the attacker but still cost them almost $100K). Tough problem.
- dragontamer 10y agoI guess a webpage is a software project...
- Vaskivo 10y agoHe has his page hosted in github: https://github.com/defuse/defuse.ca/blob/4770ad5c9d4851d40811c77b944f391aedbcf5d9/src/pages/security-contact-vulnerability-disclosure.php#L27 https://github.com/defuse/defuse.ca/blob/4770ad5c9d4851d4081...
- oh_sigh 10y agoWell, it's a PHP file. I'd consider that a software project.
- softawre 10y agoYes. What else would it be? I assume you only write leet codes in assembly?
- nilved 10y agoWhat definition of "software project" excludes Web sites?
- toast0 10y agoStatic websites are documents (although this file happened to be PHP, it looked pretty static), is a book or a word doc a software project?
- Natanael_L 10y agoUnless it is served as plaintext, I'd say it counts.
- icebraining 10y agoWell, it's not exactly plaintext, HTML is an interpreted language.
- 10y ago
- delibes 10y agoAsked a question, won a beer token. It counts.
- Aelinsaar 10y agoIt's not clever to hack something that you can socially engineer, and that should be hacking 101. Clever win.
- cpeterso 10y agoThat was the challenge. DefuseSec specifically said he would "give $100 USD to anyone who can trick me into inserting the string".
- CiPHPerCoder 10y agoThis is why you always want to define your scopes. He clearly intended for some variant of "any of my software projects that other people actually use", but failed to specify that detail. But it's nonetheless hilarious. Laughs all around.
- diminish 10y agoAnd he inserted the string into HN, and our brains - but I already forgot. Now insert that string into Linux source code, and I ll get surprised.
- deleted 10y ago[deleted]
- zerr 10y agoDepends on goals and sources of enjoyment.
- danso 10y agoHuh? Some of the most clever (and destructive) hacks involve an element of social engineering. Given that security implementations are designed to compensate for human social behaviors and instincts and limitations, social engineering is just as much a part of hacking as cryptography.
- clay_to_n 10y agoI think you read his statement backwards :) He's advocating social engineering whenever possible.
- pnathan 10y agoThat is a gem of cleverness.
- daxfohl 10y agoWhat exactly happened here? All I see is a highlighted line that seems to have already been there.
- aerovistae 10y agoA guy issued a challenge saying he'd give $100 to anyone who could trick him into inserting a certain string into any of his software projects. Another guy responded "You should put this challenge on your website." The first guy said "Good idea" and proceeded to do so, thus including the string in one of his software projects: his website. GG
- daxfohl 10y agoAh, totally didn't read the whole twitter thread. Brilliant.
- cortesoft 10y agoHe basically did this: https://www.youtube.com/watch?v=XsrU2dMBVUQ https://www.youtube.com/watch?v=XsrU2dMBVUQ
- sc00bz 10y agoThat is awesome :)
- frostymarvelous 10y agoAren't you the winner?
- sc00bz 10y agoYes, I think this counts as proof: https://twitter.com/Sc00bzT/status/731243916951994368 https://twitter.com/Sc00bzT/status/731243916951994368 My win was legit, but there's no way for me to prove that. Well if this was a PR stunt then I should of @defcon or at least #defcon to get a larger audience, but in all reality I'm banned from PayPal and haven't used Bitcoin. Which is why I said I'll settle for a beer, but I should of asked for zcoin after it launches... shit now this is all a PR stunt for "Zooko money". Anyway if anyone working at PayPal sees this and wants to hook me up by unbanning me that would be nice.
- shadykiller 10y agoBut wait, how did it happen ?
- rschuetzler 10y agoHe had him post the challenge to his website. The text of the challenge contains the string "BackdoorPoCTwitter". By including the challenge in his website, he included the string in a software project (the code for his website). This won the challenge for @Sc00bzT, who was the one who told him to make the change to his website.
- nkristoffersen 10y agoTook me a second to understand what happened. But yes, earned his $100.
- infogulch 10y agoThe offending commit: https://github.com/defuse/defuse.ca/commit/4770ad5c9d4851d40811c77b944f391aedbcf5d9 https://github.com/defuse/defuse.ca/commit/4770ad5c9d4851d40...
- kauegimenes 10y agoAnother way to win this bounty would be to share some code with the string BackdoorPoCTwitter with the same color as the page background. If he copy and paste the code it could work. ^^
- infogulch 10y agoThe only way that would work is if he committed copy/pasted code without reviewing it first, which is highly unlikely. Or at least I would hope it is, given that he's actually challenged people to do this.
- kauegimenes 10y agoYes, that`s true. But if its a big chunk of code it could work. Also, if he validated the code before copy and paste, the string would be invisible.
- infogulch 10y agoIf your final review step is anywhere before the level of staged diff, you're doing it wrong.
- Magnets 10y agoI don't really see how anyone can win this challenge (other than how already done). The guy will be super cautious of any pull requests.
- schoen 10y agoMaybe there's a way to mislead someone about the content of a pull request (e.g., a race condition in GitHub or some other UI to git, a Unicode rendering bug, a UI that hides or obscures the content of some software comments, a bug in git's merge logic, putting the code into the source of an upstream library that he pulls into his code wholesale...). I actually have another idea which I now think I should try to do, so I won't give the details here.
- 10y ago
- joemi 10y agoCan someone link to context? Without it, I don't see why this is even posted here.
- drunken-serval 10y ago@DefuseSec > I'll give $100 USD to anyone who can trick me into inserting the string "BackdoorPoCTwitter" into a release of any of my software projects. @Sc00bzT > @DefuseSec You should put this challenge on your website. @DefuseSec > @Sc00bzT Good idea, added it to this page: https://defuse.ca/security-contact-vulnerability-disclosure.htm https://defuse.ca/security-contact-vulnerability-disclosure.... @Sc00bzT > @DefuseSec Did I just win? @DefuseSec > @Sc00bzT FUCK. What's your paypal/bitcoin? [See https://github.com/defuse/defuse.ca/commit/4770ad5c9d4851d40811c77b944f391aedbcf5d9 https://github.com/defuse/defuse.ca/commit/4770ad5c9d4851d40... for commit.]
- deleted 10y ago[deleted]
- jmcgough 10y agoIf you're on mobile, scrolling up should show the context.
- angry-hacker 10y agoTwitter is horrible for having a meaningful conversation, let alone reading it.
- satysin 10y agoJust beautiful :)
- deleted 10y ago[deleted]
- anaolykarpov 10y agoWould you pay 100 usd to get on the front page of HN and who knows what other popular sites? Maybe it's just a marketing stunt
- rbobby 10y agoEven more clever...
- CiPHPerCoder 10y agoWhat exactly could DefuseSec be marketing here? Disclosure: He and I have been friends for years.
- nickpsecurity 10y agoAdvertising is always about grabbing attention. The more impressions, the more odds of sales or uptake. It's a legit consideration anytime some stunt happens in public spreading on media or social networks. Not that I think that has anything to do with this. Looks more like normal goofing around by security or hacking folks. If anything, he looses money or precious beer from it.
- anaolykarpov 10y agoHe could market himself and his site in order to increase his self branding. Even if it is a marketing stunt, it is a nice one.
- CiPHPerCoder 10y agoTaylor (@DefuseSec) is one of the organizers of the Underhanded Crypto Contest at DEFCON; it started as an open invitation to try to social engineer him so he can improve himself. It wasn't a marketing stunt, at all.
- jsemrau 10y agoI always wonder why in general there is such a distrust / avoidance of marketing in tech communities.
- eridius 10y agoCalling a website that happens to host static content in the same repo as its PHP source a "release of a software project" really seems like a stretch.
- KON_Air 10y ago>Calling a website that happens to host static content in the same repo as its PHP source a "release of a software project" really seems like a stretch. It is not even a string too.
- eridius 10y agoWhy was I downvoted heavily for this, without even a single comment explaining why I'm wrong? This was a serious comment, and I still believe what I said, so it's rather rude to be treated this way.
- eridius 10y agoAnd again, on a comment asking for someone to actually explain why they're doing this? This is really disappointing, Hacker News is usually a lot more well-behaved than this.
- j79 10y agoAn acknowledgement of the win: https://twitter.com/DefuseSec/status/730903547747819520 https://twitter.com/DefuseSec/status/730903547747819520 The offer still stands though, if you'd like to try: https://twitter.com/DefuseSec/status/730904219419443200 https://twitter.com/DefuseSec/status/730904219419443200
- dredmorbius 10y agoThis reminds me of an old folk tale of the trickster and the rich man. A king passing through a town finds a man about to be punished for fraud. He intercedes and asks what the matter is. The trickster says in his defence, "I ask people for things, and they give then to me". The king is incredulous but poses a challenge: "You must ask and receive money from the richest man in town." The trickster agrees, but being short on assets, requests a loan. The king obliges, and the trickster arranges (eliding details) to induce the town's richest resident to provide him with a wealth of goods. He returns to the king two days later with evidence in tow. The king is impressed by this demonstration, at which the trickster notes that he'd actually met the conditions 48 hours earlier when the king, wealthier than the town's richest resident, had offered him a loan. There's something to those old stories. (I'm not positive of the source but believe it's included in Idries Shah's World Tales.)
- mitchtbaum 10y agoThat seems to have worked because the king had an unmanageable level of overconfidence, whereas this worked because they already had mutual trust[0]. Advice from a friend passes easily through the "harm test" heuristic filter which takes place immediately after hearing any untrusted (doubted) person advising one to change course (and potentially other places if someone learns they need to apply it there too). By mixing in advanced machinery, our innate heuristics like harm measurement need many more dimensions of analysis. Hackers, in tune with modern machines, recognize this as a blunder since we have seen trust misused with secrets in machines before; still how can a "[s]cientist and security researcher" and "farmer and shoe-repair-man with a handheld" alike learn to recognize wider effects of their machine-enabled actions? 0: https://twitter.com/search?q=from%3ASc00bzT%20to%3ADefuseSec&src=typd&lang=en https://twitter.com/search?q=from%3ASc00bzT%20to%3ADefuseSec...
- dredmorbius 10y agoHrm. Not in Shah's World Tales, though I still recommend that as well.
- kyllo 10y agoA much lower-brow version of the same joke, from the movie Dumb and Dumber: Lloyd: I'll bet you twenty dollars I can get you gambling before the day is out! Harry: No! Lloyd: I'll give you three to one odds. Harry: No. Lloyd: Five to one. Harry: No. Lloyd: Ten to one? Harry: You're on! Lloyd: I'm gonna get ya! Harry: Nu uh! Lloyd: I don't know how but I'm gonna get ya.
- tstrimple 10y ago1. Create issues for items I need fixed on my github repos. 2. Offer a $100 bounty to people who can trick me into getting some string into my projects. The easiest way to "trick" me of course is to hide it inside of a PR which fixes a real issue. 3. Find and remove the string before merging the PR. I've had one of my issues fixed for free. Rinse and repeat! Bonus Round: Stage an announcement on twitter and have someone cleverly trick me into including the string on my website (which I was totally going to do anyway). Post clever trick to code geek social media and reap the sweet free viral marketing and hackers trying to earn a Benjamin.
- cranklin 10y agosteps 1 and 2 remind me of how Congress works
- kika 10y agoI started laughing then remembered that I live in the US for the last 5 years and started crying instead.
- dclowd9901 10y agoI was trying to figure out the actual angle here because the challenger couldn't have been that stupid. I think you've hit the nail on the head.
- reledi 10y agoIt's worrying that something as harmless as this comes across as a stunt with some ulterior motive. Not everything is a viral marketing campaign.
- Bromskloss 10y agoI like to suspect everything that gains attention to be a marketing campaign.
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- russelluresti 10y agoslow clap.
- clapinton 10y agoThis just made my day.
- goatherders 10y agoAre some of you actually arguing over whether or not the website qualifies as a "software project?" Goodness, maybe stop taking the world so literally/seriously.
- deleted 10y ago[deleted]
- drudru11 10y ago"Mostly drunk ramblings of a programmer and crypto enthusiast." Maybe we shouldn't drink and "crypto"? :-)