4 ms·
They could serve you javascript that exploits your browser. At the very least, they could replace that bitcoin donation address with their own. That's a tem
by robonerd 4y ago
They could serve you javascript that exploits your browser. At the very least, they could replace that bitcoin donation address with their own. That's a tempting target if nothing else.
- SquareWheel 4y agoAnd "they" isn't just your ISP. It's also that free wifi hotspot you connected to, or the hotel service, or your company's network. Even if you trust your ISP (and you probably shouldn't), there are other bad actors to be aware of.
- Aachen 4y agoIf you think you're high value enough to have someone target you specifically by getting on your LAN or gaining access to (or coercing) an upstream ISP to serve you a browser 0-day reachable only by laying in wait for you to visit an HTTP site because there is no other way in, that's not going to be for a free books website.
- robonerd 4y agoConsider that the downloads page for this site tells you to use their tor hidden service. If you open http://pilimi.org/ http://pilimi.org/ in Tor, you'll go through an exit node that could be MITMing everybody opportunistically, not targeting you specifically.
- Tepix 4y agoThis is a site asking you to commit piracy, i can totally see the some agency intercept it and replace the onion addresses with theirs so they can track everyone down.
- Aachen 4y agoIf enough people find it okay to take such extreme measures for mundane, nearly victimless crimes, I hate to think what the future will be like. In the past, hoarding exploits was considered something for the military, for national security, and even there it was a hot debate and controversial and many parties/countries wanted restrictions like time limits until it's reported to the vendor. Entering homes was a thing of warrants because we wanted to limit government overreach. Now it's okay to employ both of these for reading books without permission? If there's one of you then there's probably more. The future is bright.
- Tepix 4y agoA Man-in-the-middle attack against a HTTP website to de-anonymize people would not require a 0-day exploit. I agree that it would be an extreme measure.
- solarengineer 4y agoI can confirm this. A friend uses a government backed ISP, and he frequently receives popups announcing local government announcements.