10 ms·
RedditStorage
- Vexs 11y agoWell there's some pretty amusing abuse. I recall there was a botnet a while back that got it's commands from a subreddit as well. Quite brilliant actually- who would suspect reddit as a command server?
- dragontamer 11y ago> who would suspect reddit as a command server Everyone who used IRC as a command server from years past. It turns out that things useful for human communication tend to be useful for computer communication. Usenet, Email... hell... I'm sure BBS would have been used if modems were popular enough back in the day.
- hippich 11y agoactually, i personally witnessed C&C based on BBS :)
- dragontamer 11y agoSounds like a blogpost you should share with everyone :-)
- nissehulth 11y agoFidonet, in some obscure distributed echomail area? :)
- hippich 11y agoNo, actual BBS with software running, processing uploaded files, and software running on machines calling in at night. It was proof of concept and not malicious, but rather fun exercise :) It was too long time ago, the only thing I remember now is that BBS software was ProBoard, and bot was spread via demo .exe file using fidonet echo :)
- cmdrfred 11y agoEvery time I see an api for sending and receiving any type of file or text, I think botnet/building a secret chat system on top of it.
- stephengillie 11y agoCan we encode C&C commands into a blockchain?
- deleted 11y ago[deleted]
- sam_bwut 11y agoyes - its been done several times.
- SilasX 11y agoEvery time I see a service offering some resource as "unlimited", I think of using it as a free backend.
- pavel_lishin 11y agoI'm toying with the idea of building a client for Hipchat that would allow people to use encryption. Sorry, boss, the "offtopic-no-suits" room means what it says.
- mtw 11y ago"its"
- r-w 11y agoye's
- yellowapple 11y agoYe's what?
- deelowe 11y agoWelp. This won't last very long. :-)
- rndn 11y agoThere should be a contest: Who can find the most implausible data storage medium? (Rated according to various criteria such as ingenuity, reliability, max. data read/write rates, latency, storage size, costs…)
- Zikes 11y agoA stenographed image embedded in a Word document, printed and faxed to a document archive that scans and digitizes it, embeds the scan in a PDF, and emails it back to you.
- baddox 11y agoCan you make that fully automated from the end user's perspective?
- deleted 11y ago[deleted]
- Cacti 11y agoDuring this process you will lose data. A lot of data.
- iblaine 11y agoPretty sure this happens in Washington DC when bills need to be reviewed by various departments.
- Lawtonfogle 11y agoThe original image is a picture of a worker's monitor displaying some error message that IT asked for. I'm not joking either.
- prawn 11y agoHey, client of mine, you need to pay my invoice. Also, that photo you sent me won't open.
- 11y ago
- s_dev 11y agoI think this will break your ToS with reddit and result in a ban on the account. That said, I don't know. It's kinda cool though.
- pstuart 11y agoOnly in the "hacking the system part". Otherwise it's an abuse of a service. There's plenty of cheap data hosting elsewhere on the net.
- empyrical 11y agoPretty clever. If it was stored in reddit's wiki system instead of comments, it could have a revision history!
- Someone1234 11y agoShame an encryption key is REQUIRED, could be a useful way to transfer files between Reddit users. Of course the file has to be encoded, but the encryption should be an optional extra.
- tschuy 11y agoYou could always share the password, or even redistribute a modified version of the program with a hardcoded password.
- jamesjwang 11y agoThat was the idea; one of our original goals was to make a system to quickly share small files over reddit. The issue is you have to store the password for each file somewhere
- LeoPanthera 11y agoBinary files over a 7-bit medium is a very old, long-solved problem. For example, here's a base64'd tiny jpeg of me: http://pastebin.com/VTLBG3Ji http://pastebin.com/VTLBG3Ji
- exacube 11y agoI like the proof of concept, but I hate that anyone would abuse Reddit this way.
- supercoder 11y agoMore insightful than most of the comments on there.
- justintbassett 11y agoPlease don't do this . . .
- spydum 11y agodoes reddit not have some sort of posting throughput limit?
- broodbucket 11y agoIf they don't, they will soon.
- thanatropism 11y agoFor very low karma accounts, yes. After a while, not noticeably for human operators (I delete my accounts frequently; it gets annoying.)
- jakejake 11y agoThis is pretty much exactly how binary newsgroups got started. Not to be all "I thought of it first" but I had thought it would be funny to do something similar on Twitter.
- yaeger 11y agoWoah, that'd be a lot of tweets. Even reddit with its 10000 char limit per comment has loads of comment trains if you want to store a sizable amount of info that way. With twitters 140 char limit, that would be a huge amount of tweets. You'd probably run the risk of being identified as a spammer if you send that many tweets at once...
- Grue3 11y ago140 unicode characters. Which actually gives you quite a lot of space to work with.
- joshstrange 11y ago>This is pretty much exactly how binary newsgroups got started. Yeah minus the encryption (well that's not 100% true as you could post encrypted files and people do but it's less of a part of the "protocol" than it is in this example). The beauty of newsgroups is they are replicated to other NNTP servers. Distributed file stores fascinate me (I know this reddit protocol is not distributed or rather it's wholly owned by 1 entity even if the data is distributed across datacenters) and I'm very excited to see where things like IPFS [0], freenet [1], internet2 [2], etc turn out. [0] http://ipfs.io/ http://ipfs.io/ [1] https://freenetproject.org/ https://freenetproject.org/ [2] http://p2p.internet2.edu/ http://p2p.internet2.edu/
- math0ne 11y agoI've been preaching the similarities of reddit to newsgroups and IRC forever so this seems like a natural evolution to me. Probably fairly easy for reddit to shut down though unfortunately. Now if ISP's would start offering their own cached usable versions of reddit we would be getting somewhere :)
- yellowapple 11y agoAnd that somewhere would be Usenet 2.0.
- mtanski 11y agoYou could randomly spread this over various subs, that and add erasure coding. This way if a chunk or two goes missing you can reconstruct the original blob.
- SyncOnGreen 11y agoI had the same idea few months ago, I've even coded simple POC in Java which mapped submissions in subreddit to files. You could use FUSE to create virtual device and map files in mounted folder to comments. For Java I was using fuse-jna - there should be binding for Python.
- empyrical 11y agoSomeone made a reddit FUSE filesystem (I don't know if it still works though) https://github.com/ianpreston/redditfs https://github.com/ianpreston/redditfs
- kej 11y agoPresumably something like this is what's happening in /r/A858DE45F56D9BC9/
- mdadm 11y agoPossibly. Searching up some of the content on there revealed this[0], so at least some of it is (most likely) data. [0] http://a858.soulsphere.org/ http://a858.soulsphere.org/ Edit:[1] shows that this is most likely a false-positive. [1] https://www.reddit.com/r/Solving_A858/comments/24vml1/mime_type/chb5k2e?context=3 https://www.reddit.com/r/Solving_A858/comments/24vml1/mime_t...
- joefreeman 11y agoIf you had a language model (say, trained on existing comments from Reddit), you could encode the data in the comments in English, and make the abuse a little more subtle.
- guidopallemans 11y ago.. Much like how gfycat encodes their links eg.: - https://gfycat.com/JaggedIdealFrillneckedlizard https://gfycat.com/JaggedIdealFrillneckedlizard - https://gfycat.com/ThirstyAmbitiousBuzzard https://gfycat.com/ThirstyAmbitiousBuzzard - https://gfycat.com/AlertSpicyBlueandgoldmackaw https://gfycat.com/AlertSpicyBlueandgoldmackaw
- archagon 11y agoI wonder if there are any libraries that can do this? I was thinking of writing a password generator web-app that creates full diceware sentences (TheBlubberyPythonFloatedDownThePurpleFunicular == lots of entropy and easy to remember), but I'd need a decent language model for that. (And I don't feel motivated enough to write my own.)
- dragontamer 11y agoWhy not "Article Adjective Adjective Noun Adverb Verb Article Adjective Adjective Noun"? If you're making full sentences anyway, the grammar of the sentence doesn't need to change much. The vast majority of the entropy is already in the words themselves. Example sentence (generated by me, not a RNG): "the tiny hairy fish quickly paints a big scary monster". EDIT: With 10 words, each from the 252 most common words... sentences of this type would have an entropy of more than 10^24 or 2^80. I guess "articles" are pretty much "The" vs "A / An" however, so there really are only 8 words of note...
- archagon 11y agoWell, one, I'd love a more general solution where I could just say "generate a sentence with n bits of entropy" and my algorithm would spin out a sentence of the correct (arbitrary) length. (Hmm... Markov chains?) Or maybe add other mnemonic modifications, like rhymes. And two, I still need an algorithm to conjugate verbs and whatnot, though I suppose that part could just be left to the user. (You get n diceware words — make your own sentence out of them.) But that's boring! In regards to word commonality, I'm pretty sure you could in fact use something like the 5000 most common words. The people who care about this kind of stuff tend to have large vocabularies!
- jedberg 11y agoWouldn't it be funny if reddit just randomly edited the comments to break the encoding...
- aquilaFiera 11y agoThis sounds like a /u/jedberg type of thing to do.
- jedberg 11y agoI'd only do it to people I know after backing up the original. I wouldn't want someone to actually lose their files.
- aquilaFiera 11y agoOne could argue that that's their fault for giving /u/rram "root" access to their "database."
- stephengillie 11y agoInteresting idea... Since image formats already store a huge BLOB, how much more would it take to make ImgurStorage? (Ideally, it would be slightly more elegant than just renaming a zip file.)
- mdadm 11y agoThis isn't an area that I'm particularly strong in, but I think that the way that imgur compresses images[0] might have a noticeable effect on this. [0] https://help.imgur.com/hc/en-us/articles/201424706-How-does-Imgur-compress-my-images https://help.imgur.com/hc/en-us/articles/201424706-How-does-...
- dexterdog 11y agoI've run a few photo sites and one of the things I do on all wild incoming JPGs is do a minor compression on them and if that saves more than about 30% on the file size I just use the compressed version. Then anything that's been camouflaged in there gets dropped.
- deleted 11y ago[deleted]
- gkop 11y agoIf this idea appeals to you, you may also be interested in the 2009 paper Graffiti Networks: A Subversive, Internet-Scale File Sharing Model [0] by Andrew Pavlo. tl;dr: the researchers discovered that MediaWiki instances were good soft targets. [0] https://www.cs.cmu.edu/~pavlo/static/slides/graffiti-dc401-oct12.pdf https://www.cs.cmu.edu/~pavlo/static/slides/graffiti-dc401-o...
- zedadex 11y agoThe mini-saga embedded in the presentation was pretty funny > Concluding Remarks > Off probation at the end of this semester!
- zatkin 11y agoI got put on probation for redirecting my ~/.bash_history to /dev/null and removing my `finger` information with `chfn`. Universities can be pretty ridiculous with their disciplinary actions.
- pavel_lishin 11y agoWhy... why would redirecting your .bash_history to /dev/null be a punishable offense? I assume it's so they could check for evildoing on your part, but that seems like a ridiculously idiotic way of doing it.
- chillingeffect 11y agoAh so that's who those weird, mostly spammers are.... Wow.... They used me for data storage, the after school special.
- zedadex 11y agoI remember once briefly thinking how fun it'd be to do something like this, before realizing with the spam filters the way they are it'd probably be the last thing I ever did on the site. Neat proof-of-concept though
- nickpsecurity 11y agoA nice new example of what's called "parasitic storage." This kind should be easy enough to detect on Reddit's end: encrypted and binary data look very different from text. Further, if a site allows binary, it's different from crypto. The only type that's hard to filter is custom stego whose patterns look similar to normally accepted traffic. Extra true if it's a high volume site.
- yuhong 11y agoReminds me of: https://twitter.com/manzoor_e/status/604072602114605056/photo/1 https://twitter.com/manzoor_e/status/604072602114605056/phot...
- biturd 11y agohow do you get a Mac OS X GUI around this if it is written in python? Can you do the same with perl, php, and other languages? Interface Builder has always been a stumbling block for me to even begin to learn Obj-C or Swift.
- ssalenik 11y agoIt says in the readme he uses wxPython (wxWidgets). You could also use Qt as I believe both use native Cocoa underneath. You can't do everything that is possible if you were coding on Obj-C or Swift, but the stuff you can do looks native. Both have bindings in many languages.
- jamesjwang 11y agoWe used wxpython, which uses native GUI elements based on the OS. There are bindings for other a bunch of other languages too: https://www.wxwidgets.org/ https://www.wxwidgets.org/
- deleted 11y ago[deleted]
- tomphoolery 11y ago> RedditStorage uses an AES encryption algorithm which requires you to choose a password (e.g. "bunny") Some people still don't know what a password is? =D
- meesterdude 11y agoSomewhat related project i had going... https://github.com/meesterdude/reddit-rust-servers https://github.com/meesterdude/reddit-rust-servers (http://ruru.name/reddit-rust-servers/ http://ruru.name/reddit-rust-servers/ show/hide columns to see more options) I used to run the rust servers sub. I would have people post JSON posts, which i would then spider and generate a JSON DB from, and created a UI (see the gh-pages branch) to grab the JSON and present a searchable/filterable way of finding servers that are relevant to you.
- vbezhenar 11y agoI thought about creating an anonymous peer-to-peer network like BitMessage but over Twitter instead of over TCP/IP. The main benefit is that for the watching government hardware your traffic will flow to twitter, not to some suspicious computers. Of course if government can talk to Twitter, it might find out that activity, but not all governments can talk to Twitter. Another improvement might be not to send base64 abracadabra, but instead send some readable texts (autogenerated or fragments from wikipedia) and encode message as a slight deviations (typos, etc) using steganography. But it would require a lot of messages to transmit enough data.
- jamesjwang 11y agoyeah that'd probably speed things up significantly; we already ran into speed issues with PRAW in terms of how fast it can upload comments
- jamesjwang 11y agoOne of the co-creators here; as a disclaimer, we didn't mean to threaten to break reddit at all. We're amazed that someone even found this repo since we abandoned it back in January, and that it's even gotten any amount of attention. Honestly we just built this in a week over winter break cause we were bored
- Freaky 11y agoDon't use this for anything important, and certainly not with a non-unique password. Key is derived from a single SHA256 (can be brute-forced very rapidly), cyphertext isn't authenticated (can be tampered with or corrupted without anything noticing), and the padding function is broken (strips trailing NULLs, so no good for binary files).
- Goronmon 11y agoAn expected reaction from the reddit admins... http://www.reddit.com/r/programming/comments/38kn2g/redditstorage_a_cloud_storage_that_uses_reddit_as/crvx3tp http://www.reddit.com/r/programming/comments/38kn2g/redditst...
- deleted 11y ago[deleted]
- ratsimihah 11y agoYou missed the joke :(
- KeytarHero 11y agoPerhaps something like this could explain http://www.reddit.com/r/A858DE45F56D9BC9 http://www.reddit.com/r/A858DE45F56D9BC9
- lucb1e 11y agoLol, I've thought of doing this so many times on Facebook, Google+, Twitter and reddit. Seeing the amount of points this gets, I guess I should have done it. I didn't because it seemed so pointless: they'll just block accounts using this.
- vladtaltos 11y agothat is awesome in its complete disregard of reddit :) and a death sentence to itself if it gains popularity as reddit-admins will have to ban the accounts/discard the content :) so it's not that secure a storage idea... nice little engineering work though. kudos.
- gprasanth 11y agoFrom 2010: https://nealpoole.com/blog/2010/12/bit-ly-file-storage-cleverness-and-chutzpah/ https://nealpoole.com/blog/2010/12/bit-ly-file-storage-cleve...
- mihau 11y agoYeah, it can be done, but who the fuck needs that ?
- harel 11y agoWhat happens when someone uses this to pollute popular subreddits? People will get pissed off...
- scrrr 11y agoI guess they will simply block the username and delete the comments.
- diminish 11y agoCan anyone do a rough cryptoanalysis of the code? It uses AES block cipher in CBC mode with a random iv. Which attacks is this open to? First, I suspect it's lacking a secure integrity check (MAC), so is weak against chosen ciphertext attacks. def encrypt(self, plaintext): plaintext = self.pad(plaintext) iv = Random.new().read(AES.block_size) cipher = AES.new(self.key, AES.MODE_CBC, iv) return iv + cipher.encrypt(plaintext) I'm also not sure about his padding of zeros to attain the AES block size - was there a more secure padding? def pad(self, s): return s + b"\0" * (AES.block_size - len(s) % AES.block_size)
- digitalsushi 11y agoRedditStorage reminds me of a couple business models we tried out that tanked.. The first was a new business where we would go to trade shows, conventions, hell even fast food places, and just collect as many free beverages, condiments, napkins et cetera as possible. Then we'd sell them online. The other one didn't do much better. We'd go to a Lowes Tool Rental, and just rent a bunch of tools and then re-rent them out of our truck in the parking lot. They had to have them back an hour before Lowes closed for the night. Our current business model is, we go to bars and hit on people, and if we get their phone numbers, we add it to a subscription service where other people can have access to it. Honestly, I feel we're no more in the wrong than RedditStorage is.. /s