9 ms·
Hacker News Security
- deleted 6y ago[deleted]
- andrewnicolalde 6y agoWow! That PRNG post from 2009 was a wild ride! Totally worth a read: https://news.ycombinator.com/item?id=639976 https://news.ycombinator.com/item?id=639976
- y42 6y agoThis is fun to read. Are there ressources where you can read stories like that, how people discovered security flaws?
- andrewnicolalde 6y agoYou can usually find these sorts of stories in vulnerability writeups. Perhaps not as detailed as this one but it's definitely a category of blog.
- xjwm 6y agoNot a ton of stories, but there's some good exercises on how to exploit flaws in real world crypto on: https://cryptopals.com/ https://cryptopals.com/
- MattGaiser 6y agoI pity he who must check the security logs tomorrow as this rises.
- barbs 6y agoAre you suggesting there's some sort of security issue currently? Only asking because I noticed I was logged out of HN recently and don't remember logging out myself.
- toomuchtodo 6y agoIncreased rate of pen testing by interested readers due to this post.
- MattGaiser 6y agoWhat toomuchtodo said.
- SubiculumCode 6y agoIf you want more bugs, make more commits.
- maxbond 6y agoI have had nothing but good experiences reporting bugs to HN. HN doesn't work quite like any other web app I've ever audited. It's an interesting challenge.
- snazz 6y agoWasn't the last publicly-released version of Arc even stranger, with everything being a GET request and links containing a URL parameter that corresponded to a Lisp closure? I'd be interested in hearing some more up-to-date information about how HN is hosted and works today.
- ComputerGuru 6y agoYeah, that's no longer the case. If your url predated the gc run or was from before a restart, you would get a server 500 message.
- voodootrucker 6y agoHow are those closures identified uniquely? I'm not super familiar with lisp, but I do get closures and memory addresses and am suspicious.
- maxbond 6y agoThis was the case when I was poking at Hacker News. I think it may still be the case to some extent. Here's an example of an HN password reset link: hxxps://news.ycombinator.com/x?fnid=<long-random-value>&fnop=passwd-reset `fnid` identifies a closure. Presumably there's a hashmap of `fnid` values to closures in memory. It used to be that this was how any action on the site was represented. I poked around for a minute though, and it's evidently not the case for upvotes any more: hxxps://news.ycombinator.com/vote?id=<integer>&how=up&auth=<long-random-value>&goto=<return-url>
- snazz 6y agoThey had to stop using GET requests for upvotes after this issue: https://news.ycombinator.com/item?id=3742902 https://news.ycombinator.com/item?id=3742902 I'm interested in whether the password reset link is a potential issue still.
- geekamongus 6y agoKinda bummed you didn't use security.txt for this.
- kogir 6y agoHard to use something before it exists. Back when I created this we wanted to publicly credit people who had helped us out and this seemed like a good way to do so.
- deleted 6y ago[deleted]
- eganist 6y agoFair, but now that we have a standard-ish pattern, there's value in embracing it; quite a number of others have done so as part of their vulnerability disclosure programs. https://securitytxt.org https://securitytxt.org
- baby 6y agoit's kind of hard to take your comment seriously when HN is completely out-dated in terms of web standard. I will never forget how they rolled the [-] button (after a decade of people asking for it and using browser extensions to have it) next to comment on the _right_ side instead of the _left_ side (like reddit). EVERYONE complained, yet they were like "we will take your feedback into account for the next upgrade in 10 years"
- deleted 6y ago[deleted]
- kevindeasis 6y agodang is pretty good at moderating comments and fixing bugs too when you report it to him or if he sees it in your comment
- arkadiyt 6y agoYC also has their own security page, covering all non-hackernews software: https://www.ycombinator.com/security/ https://www.ycombinator.com/security/
- rshnotsecure 6y agoIt has always struck me as strange there is no 2FA function on HackerNews along with no real delete function. Also some of us have noticed for a while Hacker News is hosted differently than the rest of YCombinator. While YCombinator uses AWS, which makes sense, Hacker News uses a small San Diego firm called M5 Computer Security. They have commented on here from time to time. M5 Computer Security, also known as Cloud 5 Hosting and a few other names, has popped up on other forums too. The IPs that are owned by them (at least according to WHOIS) wind up holding very strange other websites that aren't say hosting customers (like how to weld underwater, how to get a foreign visa, etc). Some of their name servers also hold data for websites that are definitely not supposed to be there, like the regional government sites of a foreign country (could be part of the Sea Turtle DNS attack we have thought [1]). Also for a security company they seem to have strangely out of date websites [2]. Copyright 2003? A few weeks ago we wound up calling the FBI's Cyberstorm hotline after we saw something weird with a government in the United States that traced back to M5 and American Internet Services, LLC (they often appear alongside M5 in the hosting records). A week later I had someone from DHS interview me at length (they just showed up at the door) for about 30 minutes. They seemed to be around organized crime, but near the end of the conversation it was mentioned "well they also do a lot of Department of Defense stuff". Uh oh. This seems to be true as they mention it on one of their websites actually [4]. Hopefully someone a few months from now will pick up the case and find out / connect to one of the many other DNS mysteries out there. [1] - https://blogs.cisco.com/security/talos/sea-turtle-keeps-on-swimming https://blogs.cisco.com/security/talos/sea-turtle-keeps-on-s... [2] - https://www.m5computersecurity.com/audit-private.php https://www.m5computersecurity.com/audit-private.php [3] - www.htleng.com [4] - https://www.m5hosting.com/about-us/data-centers/san-diego-lightwave-data-center https://www.m5hosting.com/about-us/data-centers/san-diego-li...
- person_of_color 6y agoWow. What's going on here? Is this a front for an intelligence agency?
- Bucephalus355 6y agoTheir employee list is...strange. According to LinkedIn, all of their employees are also CEOs of their own other companies? One of their VPs has been both CEO of a lighting firm since 2014 or something, and also full time at M5 Hosting for a decade? Likely Scenario: M5 is a front company. There just isn't enough care put into the websites / marketing, and not enough evidence on LinkedIn, to suggest this is a real business staffed by people who are working on stuff full time. And a hosting company definitely needs people full time...
- chacha102 6y agoI find it impressive that the last recorded entry was in 2017. Over 3 years, and given the security-centric nature of the audience, I'd imagine if there were more flaws we'd see them reported. Sometimes building some simple is the best way to build something secure.
- borski 6y agoHey, it me!
- btown 6y agoSurprising not to see a PGP public key here for secure submissions... unless that’s no longer advised?