4 ms·
>Then they determined which of the potential targets used LinkedIn or Slashdot.org, a popular news website in the IT community. So is HN. And it's ancient. Any
by digitalengineer 13y ago
>Then they determined which of the potential targets used LinkedIn or Slashdot.org, a popular news website in the IT community.
So is HN. And it's ancient. Any ideas of possible vectors to attack HN-loving engineers?
- SideburnsOfDoom 13y agoMITM on a connection to hackernews probably doesn't differ in any significant detail from MITM to facebook, linkedin, slashdot, etc.
- SideburnsOfDoom 13y agoUpdate, this sibling post claims that HN is at least a well-configured website; and so MITM attacks will be on the upper end of the normal difficulty range: https://news.ycombinator.com/item?id=7421558 https://news.ycombinator.com/item?id=7421558
- jakub_g 13y agoHN has been, for a couple months already, HTTPS-only, and it uses HSTS and disallows framing in the response headers, so that's pretty good. It wouldn't hurt though (probably) to get added to the HSTS preload lists of Chrome [1] and Firefox [2]. [1] https://src.chromium.org/viewvc/chrome/trunk/src/net/http/transport_security_state_static.json https://src.chromium.org/viewvc/chrome/trunk/src/net/http/tr... [2] https://github.com/mozilla/gecko-dev/blob/master/security/manager/boot/src/nsSTSPreloadList.inc https://github.com/mozilla/gecko-dev/blob/master/security/ma... Trusting the SSL certs is another thing though.
- shubb 13y agoWell, you could post a linkbait article that pulled in some javascript with an exploit in it. Everything here is public except the IP addresses behind the usernames.
- pbhjpbhj 13y agoI think he meant for hiding malware on the rendered pages a HN user sees - doxing most people here would probably not be so hard (especially for GCHQ).