4 ms·
Interesting how malware is essentially allowed on GitHub, seeing as the top result here has ~500 stars and has features advertised to steal much more than Disco
by DrawTR 3y ago
Interesting how malware is essentially allowed on GitHub, seeing as the top result here has ~500 stars and has features advertised to steal much more than Discord accounts. I have a recollection of downloading a program from GitHub (which has 1.4k stars right now) whose installer had an opt-out malware bundled -- I reported the repo three times, and they didn't take any action. Chocolatey team did step in and remove it on their platform, but I wonder why GitHub didn't take any action
- andreareina 3y agoThis is the other side of allowing ytdl, revanced etc (absent a legal order).
- DrawTR 3y agoI mean -- I think my main point here, and to the other commenters who are saying "I'm happy that they don't take things like this down" -- is that I think the dynamic shifts a little bit when the point of the project, the explicit reason for its creation is malicious, & the entire point of it existing on the platform is for other people to use it maliciously
- chatmasta 3y agoThe code will continue to exist regardless of whether you see it on GitHub. Script kiddies can just as easily share the source code or binary in a zip file on a forum somewhere, or even on Discord. All you'd accomplish by removing it from GitHub is adding a censorship layer where some GitHub employee or algorithm now needs to determine what's "allowed" on the site. Are you sure you want that? Even before considering the deleterious effects of censorship, it would simply be more work for everyone and unlikely to benefit anyone. Not to mention you'd lose valuable telemetry that could be used in investigations after the fact (e.g. if someone is accused of stealing photos from an ex on discord, and GitHub can positively identify them as having downloaded a malicious tool to steal Discord tokens, then investigators could subpoena GitHub for those download records). If there is a problem here, then hiding the code that exploits the problem does not eliminate it. It's Discord's responsibility to mitigate the scale of risk associated with a stolen token. A program that grabs a token on your machine probably shouldn't be able to use it to exfiltrate all the data from your Discord account. And similarly, it probably shouldn't be so easy for any program running on the machine (as a non-root user) to retrieve such a token in the first place.
- DrawTR 3y agoDoes having it on GitHub not inherently promote it as a sort of aggregator for stuff like it? Instead of having to search for a forum somewhere, they simply have to look at this cool GH topic, and there they now have ~40 options at their disposal
- hnlmorg 3y agoIt was bloody easy to find this kind of stuff before GitHub. It will continue to be easy even after GitHub closes those repos. Source: I’m old and used to source this stuff for research purposes (genuinely) long before GitHub, and social media in general, was a thing.
- ForestCritter 3y agoabusive child porn is easy to find, we should have that on a fun easy entry level site like github...it's called a slippery slope, if no moral line is drawn, where do we end up?
- chatmasta 3y agoAbusive child porn is a well defined content type that is objectively classifiable. For better or worse, so is copyrighted content (according to the rules of the DMCA claim process). "Harmful software" is a much blurrier line. Is a GitHub URL being used as a dropper in an active malware campaign? That will probably get a repository removed. Is the source code for malware published on GitHub? That's not harming anyone in its current form, just like the source code of Popcorn Time isn't pirating movies. Do you want to ban any content with a readme claiming it can be used maliciously? What if I want to publish a basic keylogger implementation for an open source cybersecurity class? Where's the line between educational content and cyberweapons? And even if it's a weapon, how do you know I don't have permission to install the keylogger on a system, like one belonging to a company paying me to pentest them?
- hnlmorg 3y agoEvery time I hear someone use the “slippery slope” argument, what they’re actually doing is making a strawman argument. I can assure you, script kiddy code on GitHub isn’t going to lead to people uploading kiddy porn on GitHub as well. The two are not in any way related, let alone one being a slippery slope for another.
- hnlmorg 3y agoIt’s a grey area between what is malicious and what isn’t. A lot of people aren’t going to agree. ytdl is a great example of that. For Google, it’s “stealing” people from their platform by allowing individuals to download content in a way that doesn’t increase engagement and ad views. I don’t personally agree that ytdl is malicious but I do understand how some could make that claim. Then what about tools that are legitimately intended for research purposes but could still be abused? The problem with freedoms is they have to work both ways: if you aren’t prepared to allow abuse of that freedom then you certainly aren’t going to allow legitimate but unpopular uses either.
- creatonez 3y agoI would differentiate 'malware implementations' from 'malware'. A hacking tool presented with its harmful features at face value, with adequate warnings, is not quite the same as an attempt at tricking people into downloading or bundling something dangerous. I believe Github makes the same distinction in allowing hacking tools. They also allow byte-reversed or zip-encrypted copies of well-known malware for the purpose of study. There's no way to keep out the bad guys while still allowing security researchers.
- DrawTR 3y agoI would understand the first definition if not for the fact that these pieces of software under the topic really don't have any legitimate usage in my opinion. Unless you're explicitly making the argument that the code is the important part (& should be kept on GitHub for the purpose of disseminating the programming methods used to create it, despite their purpose), I just think that GH is being used as a 'download link' if not an aggregator for projects like these. And, they're used for the express purpose of infecting other machines, presumably of people who are none the wiser
- deleted 3y ago[deleted]
- mtlmtlmtlmtl 3y agoI would argue that pretty much any type of malware can at the very least be used legitimately in penetration testing, and probably is.
- jrm4 3y agoI'm glad they don't? That's one of the perks of free/open source. Presuming there exists something like a provider/customer relationship for users of Discord, it's now Discord's job to step up and fix it; unfortunately years of Microsoft getting away with horrible security has cemented in our collective heads that "malware" is some abstract thing that, you know, just happens.
- rplnt 3y agoThe interesting part is Github regularly takes down software that could aid someone to break copyright of one of the few big media companies.
- WendyTheWillow 3y agoEhhh, I would hesitate before blindly believing the claims you see on these repos. It's easy to say stuff like that in a README.md, and maybe at one point it was true, but these are literally thieves, so... take it with a grain of salt.
- inspector14 3y agoEspecially considering the fact that there are discussions in the issues in these repos from the codeowners who "don't condone illegal activity" actively providing guidance on how to use the stolen data to login to victim's accounts on various services.
- matheusmoreira 3y agoI'm glad they don't. I like knowing what's out there. I get to see the source code, understand how I could be attacked and implement countermeasures.