3 ms·
If an automated service is pulling the top 100 domains from CF and naively trusting them, why can't it also pull the categorization information that's right the
by arcfour 11mo ago
If an automated service is pulling the top 100 domains from CF and naively trusting them, why can't it also pull the categorization information that's right there and make sure none of the categories are "Malware"??? Who would write something like that? It's absolutely believable that the top 100 domains could contain malware domains...because of the nature of botnets and malware.
That's PEBCAK.
- 8organicbits 11mo agoPeople make mistakes. Security engineers need to understand what sort of mistakes people are making and mitigate that risk. Brushing it under the rug as silly users making mistakes doesn't protect anyone.
- monerozcash 11mo agoThe automated services using this for security-related purposes are presumably built by "security engineers", if they're making mistakes like this they're obviously woefully underqualified.
- Uehreka 11mo agoMany people are woefully under qualified, we need to have a working society anyway.
- monerozcash 11mo agoYeah, I'm not sure that baby-proofing everything as proposed here is going to result in a working society. If we expected airplanes or cars to be able to be safely operated by people with zero understanding of how such vehicles work, nobody would be getting anywhere. You eventually reach a level of stupidity and/or incompetence after which trying to alter the product to coddle those users becomes counterproductive.
- wolf550e 11mo agoAlmost nothing is built by security engineers, including security features of security products at security companies.
- arcfour 11mo agoI'm a security engineer, I have built things like this, and I made the original comment. A lot of my job revolves around developing automation for security needs. Also, many of the top 100 domains serve user-generated content (like AWS/S3). Blindly trusting anything from them just because they are big is so woefully misguided it boggles my mind; I seriously doubt that anyone is actually doing what is described in the article.
- huflungdung 11mo ago[dead]
- 8organicbits 11mo agoIdk, I have done security audits for startups and small tech companies. They won't have a security engineer on staff and are "moving fast and breaking things". I've seen things much more misguided than this.
- arcfour 11mo agoI just finished working at a small company like what you are probably describing. It was...horrific. But I try not to think about that anymore!
- wombatpm 11mo agoTrue masters of security realize all software is flawed, and therefore write none.
- vacuity 11mo agoUse none, too.
- charcircuit 11mo agoWhy not include them? What's wrong with have the most resolved domain being the top domain. I think it's interesting to know the actual most resolved domain, than the top of some editorialized list.
- arcfour 11mo agoAs discussed in the article, threat actors are using a botnet to game the system by repeatedly issuing queries for the domains; the list is intended to represent the top 100 domains resolved by legitimate users (and legitimate bots, I assume), not just "who can make the most queries to CloudFlare for a domain".
- charcircuit 11mo agoSo why not get rid of "gamed" requests? Why would gaming it be fine as long as your domain isn't malware related?
- arcfour 11mo agoWhy not just disqualify these obviously not in the top 100 domains that are cheating and also host malicious content which has the same effect...??
- deleted 11mo ago[deleted]
- heresie-dabord 11mo agoFrom TFA: "We should have two rankings: one representing trust and real human use, and another derived from raw DNS volume." (citing Mr Greenland)