7 ms·
Faking votes on Hacker News
- pg 18y agoNot cool. We deliberately don't put that much effort into security, because this is a community based on trust, not a bank. And by choosing to publish this rather than e.g. simply sending me an email about it, he's inviting people to do this.
- erlanger 18y agoHilarious. The head of "Hacker News" is mad because his news has been hacked.
- sgrove 18y agoIt was an interesting manipulation of the system, but as pointed out it's a dangerous slope. A community based on trust will sour very quickly if a lot of these tricks pop up. Sharing the trick is entirely reasonable: small hacks like this are something to be proud of, given that you've acted in a reasonable way (e.g. contacted the site and informed them before telling others, not actually using it game the system, etc.) Could have gone that way. Didn't.
- erlanger 18y agoHackers should know how to secure their own website. Between this and the JS injection hack (from the same fellow), it's clear that security is porous at best.
- bad_user 18y agoAs a kid I never understood why some of the kinds made it a hobby to trash the sandcastles built by the others. It was an interesting phenomenon to watch :) Maybe they thought that if they wanted to, they can do better, but they never did.
- erlanger 18y agoOr maybe it's a cop-out to say that you didn't care about your sand castle's security in the first place. If you knew of a way to keep it from getting knocked over, you'd use it.
- run4yourlives 18y agoBeing an asshole is just that - being an asshole. It doesn't really involve anyone else.
- unalone 18y agoKnow who knocks over a sand castle? A dick. I'm sick of security. I wish we could make things without worrying about the myriad ways there are to destroy a thing? What did xach have to gain by doing this experiment that he would have lost by emailing PG quietly, beyond the childish feeling of destroying a good thing?
- tptacek 18y agoWhere do you work, erlanger? Let's have a look.
- dha 18y agoWhat? It's bad for security bugs to be exposed to the public rather than to have people silently exploit them?
- alanthonyc 18y agoHe didn't necessarily say he was mad. He did say it wasn't cool - which is a fact. What xach did wasn't cool, although perhaps inevitable on a public site.
- aswanson 18y agoNot hilarious if we start getting swamped with budding script kiddie attacks. This is a nice community, it would be great if we didn't start attracting that type of attention.
- tlrobinson 18y agoHilarious, if you consider the only definition of "hacker" to be someone who breaks into or otherwise exploits computer systems. Obviously that's not the definition we use here. If you haven't figured that out by now, perhaps this isn't the place for you.
- erlanger 18y ago> If you haven't figured that out by now, perhaps this isn't the place for you. God forbid anybody here should have a sense of irony.
- tlrobinson 18y agoErr, that's my point, it's not ironic if you don't use your definition of "hacker".
- pg 18y agoIt was the way he did it. If he'd just sent me an email about this hack I'd have been amused and grateful.
- publius 18y agoReally though, this is such a simple attack you'd think that it would be protected against. Any argument about "trust" is irrelevant due to the frustratingly simple way this system has been gamed. Usernames, that's it? I'm surprised this didn't happen sooner.
- dag 18y agoSo the community is based on trust yet you don't trust the community with information on how the community functions.
- JoelSutherland 18y agoThe code for HN is open source: http://arclanguage.org/ http://arclanguage.org/ This is not how the community functions however. The community functions by being made up of a group of people who believe in courtesy. It is not vulnerable to any sort of software hack, instead it is vulnerable to the slow drift towards thoughtlessness.
- lsb 18y agoHuh? You can download the source code for HN, and you can infer how voting happens from Firebug. Where's the lack of trust part?
- dag 18y agoThat's kind of the point, nothing was said that wasn't already public available information, yet people got angry at Xach for saying it. The lack of trust is not trusting the community not to abuse an explained hack, and the whole is made dumb by the fact that anyone can figure out the hack for themselves even if it wasn't explained to them.
- shadytrees 18y agoAs much as this was done irresponsibly, is a fix planned for this? CSRF is, by now, a widely investigated field of web application development; most of the mystery is gone. To borrow a term from The Old New Thing, it's one of the taxes everybody has to pay.
- agotterer 18y agoI think a lot of people are missing the point here. Sure what he did wasn't "cool" since it deceived users who are part of a community that is based on trust and responsibility. But he found a potential exploit and instead of using it irresponsibly he brought it to the attention of the community. Maybe the right thing would have been to contact PG. Maybe he takes lessons from the Windows world of bugs... If it's not made public for exploitation, it may never get fixed. In my opinion this should be looked at as a learning experience for web developers. We need to take these issues/exploits into account when building websites. I'm pretty sure PG accounts for XSS attacking, no? If we trust each, shouldn't we trust each other enough not to post malicious code? Unfortunately it just doesn't work like that. Security by obscurity is never the answer!
- tlrobinson 18y agoXSS, yes. CSRF, no, or at least not completely. You still need to know the user's username, which is better than it could have been. This was a CSRF attack, which is mostly unrelated to XSS.
- tptacek 18y agoYou're adding to the drama. Just let it go.
- AndyKelley 18y agoyou should fix it instead of making excuses
- joshu 18y agoTrust, but verify.
- jonshea 18y agoDon’t trust. Just verify.
- comster 18y agoI think using the excuse of "trust" for having security holes is not justified.
- ajju 18y agoWell done, you proved two things: 1) that you can write script that does an http get and 2) that you should not be trusted. Was that a net gain for you?
- critic 18y agoFor the record, I'm not xach. I just saw this on Programming Reddit. Edit: link http://www.reddit.com/r/programming/comments/854w0/faking_votes_on_hacker_news/ http://www.reddit.com/r/programming/comments/854w0/faking_vo...
- ajju 18y agoOK. I direct my comment at xach (since I can't edit it any more).
- ericwaller 18y agoIt's worth having a link to http://en.wikipedia.org/wiki/Cross-site_request_forgery http://en.wikipedia.org/wiki/Cross-site_request_forgery Something to think about for your own applications
- r11t 18y agoI fell for the trickery(admittedly my mistake for trusting an unknown website) and submitted my user name, expecting to receive a graph like the page promised. However, as pg already pointed out it was totally uncool not notifying him before making it public. I am in the support of full but responsible disclosure. So maybe he could have published it after informing pg and the issue was taken care of.
- dag 18y agoTaking it public is a fix. Now that this information is public none of us will give out our usernames to external websites, thus ending the problem. In effect Xach's could decide between emailing someone hoping they fix the problem, or just fixing it. I found this whole event funny. I'm also amused that people reacted as negatively to this prank as middle managers at my old $MEGACORP job would.
- silencio 18y ago> none of us will give out our usernames to external websites Maybe so, but in the case of Twitter, not many people seemed to learn their lessons - and there people were giving away their usernames and passwords. > decide between emailing someone hoping they fix the problem, or just fixing it But you do not know if a vendor will fix the problem as soon as you report it to them, even if they already have a past history of not caring. the balance here is responsible disclosure: maybe it's a big enough issue or maybe the right person noticed that your problem will get fixed when you first let them know..in the event you feel you are ignored though, go public. best of both worlds. > I found this whole event funny. I don't think it's funny or angering. It's probably educational, as more people learn what CSRF is and it's probably a little annoying in that not as many people are discussing responsible disclosure, but there's not much to get angry about. Votes? big deal....
- critic 18y agoNow that this information is public none of us will give out our usernames to external websites, thus ending the problem. Correct me if I'm wrong, as I'm NOT a web guru, but I think there are three ways to get the user names, and it's enough if this only works in some cases: (1) Brute force (look at who's currently active on the site) (2) Look at browser history (HN users have to constantly look at their own profile to check for replies, and the URL contains their user name) (3) Send whatever request the browser sends to HN normally, and gets the user name embedded in the page. Again, I don't know enough about browsers/JS/HTTP/HN to know if any of the above would work. I'm just saying I'm not sure that explicitly giving out your user name is required for this. Edit: typos
- gojomo 18y agoYou wouldn't necessarily need someone to volunteer their username to make this work. This unfixed and ancient (2002!) browser vulnerability leaks information, via the styling of 'visited' links, about other URLs you've visited: http://seclists.org/bugtraq/2002/Feb/0271.html http://seclists.org/bugtraq/2002/Feb/0271.html In many cases, the only person who will have visited all of... http://news.ycombinator.com/threads?id=USERNAME http://news.ycombinator.com/threads?id=USERNAME http://news.ycombinator.com/submitted?id=USERNAME http://news.ycombinator.com/submitted?id=USERNAME http://news.ycombinator.com/saved?id=USERNAME http://news.ycombinator.com/saved?id=USERNAME http://news.ycombinator.com/user?id=USERNAME http://news.ycombinator.com/user?id=USERNAME ...is USERNAME. So another exploit -- still sneaky but not quite fraudulent, and not especially unique to HN -- would be to design an offsite page that does one or both of (1) greets HN users by name upon their visit; (2) logs which of some chosen set of HN users has visited the page.
- tlrobinson 18y agoTrue. You'd still need to brute force USERNAME, but it's much faster to do that in JavaScript than issuing a million HTTP requests.
- gojomo 18y agoIf by 'brute force' you mean 'iterate through all legal usernames', I hadn't even thought of that! I would expect someone instead to pick the leaderboard, or some other extant set of names (eg: Google [site:news.ycombinator.com inurl:user]), and just iterate over those. (Sad aside: try that query at Google or Yahoo, and review the top 100 results. An awful lot of the usernames ranking highest are drug names.)
- tlrobinson 18y agoYeah, I meant brute force over all registered usernames. I wrote a page that used the vulnerability you mentioned to check to see if a user has visited any of the top 100,000 websites: http://tlrobinson.net/misc/history.html http://tlrobinson.net/misc/history.html (it seems to be broken now though) and it can churn through 100,000 tests in a few seconds.
- run4yourlives 18y agoWhat's really stupid about all this is that I give fellow users on this site a little bit of trust because I know that many times, they would like advice or help with their projects, or conversely, they have stumbled on something I can learn. So I don't worry too much about giving my user name out, or entering it into other HN members' apps. I did it, and I'm not worried about it really. It's not like run4yourlives is my bank id or anything. What bothers me about the whole thing though is that I've now had it confirmed that HN is too big to trust anymore. Whereas before, there was a sense of kinship with people here - none of whom I've ever met - I now have to worry that some of them are just losers looking to exploit my trust. That's worse than off topic posts and low quality comments really. It's an attack on the fabric of the community, and the value of the users. It's clear now that I must treat HN as I would treat reddit or digg or any other room full of potential idiots; people who would much rather exploit trust than build it. Sad but inevitable I suppose.
- YuriNiyazov 18y agoWell, I think that a room full of idiots is an overstatement. An occasional idiot sure, but even that's beside the point - before this supposed decline of the community, you wouldn't have posted your credit card and social security numbers in the comments, no matter how much trust you placed here.
- run4yourlives 18y agoEveryone has the potential to be an idiot. Broken windows and all...
- chairface 18y agoI don't feel like any trust was violated by xach in showing us this exploit. He clearly wasn't trying to be malicious, so I frankly don't understand all of these people who are so upset about this. It sounds like a lot of pointless whining. Frankly, if anybody has violated our trust, it's whoever wrote this exploitable code. When I use a site, especially an open source one claimed to be written by good programmers, I expect it to be protected from well-understood exploits. And pg, as the caretaker of the code (and its likely author), needs to do some talking about how "not cool" running easily exploitable code is and take some responsibility.
- asdflkj 18y agoSome context: http://www.reddit.com/r/programming/comments/67gu9/take_the_arc_challenge/c032kur http://www.reddit.com/r/programming/comments/67gu9/take_the_...
- tptacek 18y agoAm I wrong, or is this just saying HN is CSRF-able? There are commerce apps that are still CSRF-able. And this is a comparatively clumsy attack, since there's no trivial way to get your username blindly.
- tlrobinson 18y agoYes, I think it's considered CSRF, but indeed it's not as bad as it could have been, since it still requires you know the username of the logged in user. It's also nowhere near as bad as the state of the Twitter API and apps, which require a username and password. People don't think twice about providing unlimited access to their Twitter account to random websites. Hopefully the OAuth API will fix that. @pg: I think one solution would be to reject any vote requests with a Referrer header other than news.ycombinator.com
- tptacek 18y agoReferer is totally insecure. If all it is is votes, I say the right solution is "let it go".
- tlrobinson 18y agoAFAIK, checking the Referer header actually works for preventing CSRF because you can't modify it for the types of requests that work cross domain, i.e. loading <img>, <script>, etc tags, or posting forms.
- tptacek 18y agoYour assumption here isn't crazy, but it depends on the browser, and you shouldn't rely on it.