11 ms·
Thank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand rec
by dejanseo 8y ago
Thank you. I'm not having a good time at the moment. Anyway, the basis of my test hypothesis is that people are easily fooled by URL both by HTTPS and brand recognition (e.g. subdomain) so I conducted a survey which revealed the very real problem: https://dejanseo.com.au/trust/ https://dejanseo.com.au/trust/
Raw data: https://dejanseo.com.au/wp-content/uploads/2017/04/survey-texrixayf2f67gzehkadczhl5m.xls https://dejanseo.com.au/wp-content/uploads/2017/04/survey-te...
- moolcool 8y agoDon't listen to the haters here. The same people upvoted this article 3 days ago, and then promptly forgot about it https://news.ycombinator.com/item?id=17799083 https://news.ycombinator.com/item?id=17799083
- geofft 8y agoI think you'll find that a lot of people on this site—from lots of political leanings—believe there's a wide gulf between "This behavior is a bad idea and we should use social mechanisms like debate to discourage it" and "This behavior should be illegal and we should point the government's monopoly on violence in your face to make you stop." The flip side of the defend-to-the-death quote is that caring about someone's right to speak, even caring about that position being well-represented, doesn't mean you have to agree with what they say.
- dejanseo 8y agoThe irony...
- 3pt14159 8y agoHey man, I know how hard the hate hits when you explain something like this to a community. It happened to me here too when I talked about the mass weaponization of autonomous systems via cyber attack. One guy said I was somehow right and a crank at the same time and dismissed one of my conclusions out of hand without addressing any of the reasoning behind it. I hurt at the time, but I came to understand it wasn't really directed at me. The thing you got to realize is that many here make their livings trying to secure systems and we're finding it hopeless. The way you did what you did was fine. In terms of proving the hack you needed to violate Google's trademarks. It's in the very nature of the hack, and as far as I'm concerned, warranted given that they have a bug bounty. Now, I probably would have disclosed it to Google, Bing, etc. ahead of time, but it's your bug. You could have sold it to blackhat scammers and you didn't. For all we know this hack could have been going on for years. I think most people are confusing their anger at the situation with anger towards you. You're cool.
- dejanseo 8y agoThank you! :)
- specialist 8y agoThis was my experience working on election integrity issues. No good deed goes unpunished.
- S-E-P 8y agoFor what it's worth, I love reading about this stuff, though I specialize in InfoSec so this sort of thing is actually pretty common in our communities. You would have definitely had a much easier time with them than you are right now. But for what it's worth, this will blow over soon enough, the internet does not have the greatest memory (unless you actually did something horrendous, which you didn't)
- dejanseo 8y agoI hope so, and I also hope Chrome gets a fix for this.
- S-E-P 8y agoHopefully, but even then, it's good that you are making people more aware of just how sketchy it can get. Chrome will always have nasty exploits, because it's dealing with the flexibility of the world wide web. It's more important that we the users are aware of the tricks that attackers employ, rather than having clean solutions. I don't trust that any software is secure, and to date that mindset hasn't burned me yet!
- brlewis 8y agoI read the article, but still don't get what's Chrome-specific about this vulnerability, or what a good fix would look like. My reply to someone who proposed making the back button always go to the previous URL: https://news.ycombinator.com/item?id=17826406 https://news.ycombinator.com/item?id=17826406
- scratchnsniff 8y agoThe issue is that some web applications don't load what traditionally were discrete pages (e.g. PAJAX) with their own URLs. It's a trend you'll find in sites built to feel more like applications. Scroll the the bottom of an onion.com article and watch your URL update to the next page without a page refresh. This was done so modern sites built like this could still allow the user to navigate back and forward. It let's the site update the browsers location history and effectively what URL that back button will point to. I could imagine blocking this behavior if it points to a site off the TLD and it's sub domains. Hard pressed to figure out how they could prevent this, definitely a flaw in the trust model but probably worth the trade off.
- _bxg1 8y agoI'm willing to give you the benefit of the doubt and assume you were just unaware of how things are supposed to be done (reporting exploits to the vendors privately and waiting for the fix before going public), but man, you did a fantastically dangerous thing even if it was unintentional. I'd never condone beating up on somebody on the internet, but I dearly hope you've learned a valuable lesson here. You've put lots of people in danger of being exploited. It's not about whether or not you'd do anything malicious with it, it's about all the other people who now can because Google doesn't have a fix out there yet.
- rapind 8y agoThis is the misconception I can't stand. Where we hold individuals responsible for a product / companies defect. I thoroughly disagree with the idea that it's his fault people are vulnerable. So called responsible disclosure is just a marketing spin term. Disclosing bugs privately is a favour not a responsibility. All this does is reduce the risk of bad software decisions. It doesn't solve anything. How about free market instead? If you run a multi-billion dollar company that can be hurt by issues like this, then it's on you to make it more profitable to disclose issues privately. If you can't or refuse to do that, then you're exposing your company and your customers to risk. Enough with the shunning and the "responsibility" of individuals which expose bugs.
- _bxg1 8y agoThis is the most idiotic comment I've ever read on hacker news. "The free market"? What? What does that have to do with anything? Vendors are extremely incentivized to fix bugs and thereby maintain user trust. Google regularly pays out generous bounties for bugs that are reported properly. There are the odd cases where a bug is reported and the company denies it, sits on their hands or threatens the reporter. Those should be made public. But the author makes no mention of that having happened here, and Google is in fact the last company I would expect to behave that way.
- dejanseo 8y agoGoogle? When I brought a serious issue up in 2012 https://dejanseo.com.au/hijack/ https://dejanseo.com.au/hijack/ Google never fixed it: In summary, I can take any of your (or anyone else's content) pass more pagerank to it than the original page and then I become the original page. Not only that but all your inbound links now count towards my site and I can see your links in Search Console of my domain. This is something link graph theory refers to as "link inversion" and is very harmful to smaller publishers.
- winkeltripel 8y agoI believe that you acted ethically, unlike Google. The history API should be locked behind one of those: "RandomSite.com wants to use the History API: Allow / Deny" dialogs, and the TLD and second-level-domain should be clearly marked in browsers, to prevent this sort of https://google.com.search.mydomain.cz https://google.com.search.mydomain.cz schenanigans
- cryptonector 8y agoDid we not have enough evidence already that this is true??!
- marichards 8y agoWe need experiments like this. Clinical studies, try to address various factors beyond does the drug technically work, but does it work in practice (coping with people doing everyday things like having dementia, drinking or babies). We have a flawed obsession with responsible disclosure (that we should mandate includes public disclosure). What we need is a framework for Software Studies that allows any nature of research including in at risk areas and they should answer to ethics committee and regulators, not a disclosure terms of service from the company likely to be put in a bad light. We need an equivalent to ICH GxP. Drugs have to deal with all the same craziness as software, they're just centuries ahead at how to do it (although they still fail at public disclosure). Was this study appropriate? Whilst Google corrupts the security integrity of the internet with its Ad and Analytics system, it shouldn't be complaining. For the rest of us, I think we need to pressure for regulation if you want to draw lines and look to the drug industry for inspiration. At the very least we need InfoSec Trials if not the whole suite of Software.