5 ms·
I agree. I think this publication is a net-loss for the world, for sure. People will find and use this code--people who could/would never create it themselves.
by mod 4y ago
I agree. I think this publication is a net-loss for the world, for sure. People will find and use this code--people who could/would never create it themselves.
It will be used for many reasons, but the stalking is the most obvious.
Not all of my usernames are as resistant as this one, unfortunately.
- rtev 4y agoIs it better for only malicious actors to have access to this tooling? If both teams don’t have the same tools, there isn’t a level playing field. If this wasn’t on GitHub, we wouldn’t be aware of it. However, it would certainly be circulating on underground forums. Is blissful ignorance better?
- archevel 4y agoI think the argument is more that this tool by virtue of being easily accessible creates more malicious actors. Similar to how most people wouldn't steal a locked bike, but a larger portion would steal an unlocked one. It isn't that much harder to steal a locked bike vs an unlocked one, but the threshold is just a tiny bit higher so more people will attempt it. Conversely this tool lowers the threshold for stalking, so more people, who otherwise wouldn't, will use it maliciously. That isn't the fault of the tool or its developers, but it is something to be aware of when building any tool. When you release it, it may get abused by people for bad purposes.
- rtev 4y agoAssuming your online identity is secure by obscurity is not a realistic option. If all it takes is a flashlight for everyone to become “vulnerable”, we need to just assume the light is always on. Someone handing out flashlights just highlights the bigger problem. If this truly causes worry, adopt better opsec and create generative usernames for different sites. If not, assume anyone will easily be able to link your bowel issue subreddit comments to your LinkedIn profile.
- Springtime 4y agoI feel this is similar to Firesheep[1], a browser extension from a decade ago that put cookie session hijacking into the hands of everyday users and became wildly popular until its removal. Pre-Snowden it pushed various major sites to implement HTTPS encryption, including Facebook[2]. Granted there the solution was a rather simple one but I feel it's at least worthwhile for more to be conscientious of singular identities online and what info is disclosed publicly with them. [1] https://en.wikipedia.org/wiki/Firesheep https://en.wikipedia.org/wiki/Firesheep [2] https://threatpost.com/facebook-kills-firesheep-new-secure-browsing-feature-012611/74883/ https://threatpost.com/facebook-kills-firesheep-new-secure-b...
- wruza 4y agoIf this wasn’t on GitHub, we wouldn’t be aware of it The more availability this type of tool has, the less professional its users are. As a result, while it makes easier for you to see what “they” can see about you, “they” become much more personal and bitchy than credit bureaus or ads companies who already have it. E.g. a credit bureau would never sell your comments or “private preferences” to your boss to step over you in career. It increases attack vectors enormously. Is blissful ignorance better? It is in this case, I believe. It’s like spreading free covert time-travel-enabled surveillance devices among general public. Someone will pat it onto your back just for dark fun.
- rtev 4y agoThe actual fix is to not reuse usernames. Does distributing password stuffing tools increase the ease of password stuffing? Yes. Is that the problem? No - people reusing passwords is the problem.
- wruza 4y agoIt doesn’t work retrospectively. You either start a new web life or live under a risk of accidentally exposing or linking to one of your already vulnerable accounts. Also, if we don’t raise issues like this, the next actual fix will be “don’t reuse writing styles and vocabularies on different sites”.
- rtev 4y agoI believe both are inevitable if you want to maintain an unlinked identity. Realistically, there is nothing you can do to avoid that future. The best thing you can do is choose to accept the risk or act to prevent the issue.
- wruza 4y agoThis line of thinking reminds me of a Roko’s basilisk situation. Embrace it and be prepared vs. don’t mind this nonsense and just actively stop creating/spreading it. And if it spreads enough, make it a punishable offense like hacking/piracy (e.g. via “canary” links) for it to live only in underground. I hope this project will just fly under the public radar due to non-ease of use by an average person or for a similar reason.
- true_squirrel 4y agoYou have to squint really hard to see "many reasons". Look at the list of sites it checks. Porn / fetish sites, gambling URLs, photo hosting, hobby forums, etc. It's a tool for doxxing and stalking, and little else. It's essentially like arguing that releasing open-source ransomware toolkit is beneficial. I mean, maybe it's your right, and one can make some strenuous arguments about how it helps the "defense", but really, it just makes it easier to be a terrible person on the internet.