5 ms·
I've been consistently attacked by ShadowServer who have the following sponsors, Akamai, APNIC Foundation, Arctic Security, AusCERT, Avast, Backblaze, Ca
by kittikitti 19d ago
I've been consistently attacked by ShadowServer who have the following sponsors,
Akamai,
APNIC Foundation,
Arctic Security,
AusCERT,
Avast,
Backblaze,
Canadian Center for Cyber Security,
CERT.AT,
CERT.br,
CERT.LV,
CIRA,
CIRCL,
Craig Newmark Philanthropies,
CSIRT.LI,
CSIS Security Group,
DFN‑CSIRT,
Digital Trust Center,
EURid,
HelseCERT,
ICANN,
Identity Digital,
KPN,
Mastercard,
NASK (CERT.pl),
NCSC Ireland,
NICS,
Nihon Cyber Defence,
Nucleus Security,
Orange Polska,
Precursor Security,
Protect.ngo,
Public Interest Registry (PIR),
Red Hat,
SURFcert,
SWITCH,
Team Cymru,
Trend Micro,
Trivest AG,
Tucows,
Verisign,
VulnCheck,
I don't care what they say they're doing, I hate how corporations can act with impunity with these types of things while everyone else would get a felony for it.
- bmenrigh 19d agoCalling vuln scanning from a non-profit a felony is a bit of a stretch. Many for-profit companies do similar vuln scanning and then threaten companies with security "scorecards". That is borderline extortion.
- FabCH 19d agoIf the non-profit was walking down the road and rattling everybody’s door lock to see which are unlocked, and having a look around the windows to see if any are open, would that be a crime? Because that is exactly what all of these vulnerability scanning companies are doing, and all of us sort of just… let them.
- bmenrigh 19d agoIf the neighborhood was constantly being canvased by criminals checking doorknobs, so your concerned neighbor went over to your house to check your doorknob, and then let you know if you accidentally left it open, would you also accuse your neighbor of being a criminal trying to break in?
- FabCH 19d agoYes. I have personally done this before, the correct sequence of moves is: 1. Call your neighbor, ask for permission. 2. Check the door 3. Lock the door If you don’t have their phone number, you are not on good enough terms to touch their lock.
- bmenrigh 19d agoThis is why the checking doors / neighborhood analogy isn't a good one. Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments. Security is too intertwined to stand by and say other people's vulnerabilities aren't your problem.
- FabCH 19d agoIt is a good analogy because thieves stealing from one house successfully gives them resources and incentivizes them stealing from the same area again. And even if you remove the analogy, ShadowServer means good, but good intentions doesn’t necessarily make their action moral or legal. Yes, compromised servers can be used by hackers as means to commit crimes. But when these groups scan the entire internet, they do cause harm as well, as shown in the original linked article. Much less harm than a black hat, but they still waste time and resources from innocent third parties. It’s fair to ask if the harm they cause is worth the good they do.
- 9x39 18d ago> It’s fair to ask if the harm they cause is worth the good they do. Researcher disclosures, even with POCs, have moved the industry to action incumbents would have rather buried. I’m thinking of CPU and memory exploits, and stuff like log4j, as examples. Frontier AI is enabling the cyber arms race more than anything past, and certainly more than some bot slowly crawling web servers for old vulnerabilities. If we’re talking harm, it should be in the broader context of internet history, imo.
- driverdan 19d agoReport it https://www.cisa.gov/reporting-cyber-incident https://www.cisa.gov/reporting-cyber-incident