Someone used my IPFS gateway for phishing
incoherency.co.uk
incoherency.co.uk
I think the best way to popularize IPFS will be out-of-the box support in major browsers. I think Mozilla may be the first one here.
[0] https://www.bleepingcomputer.com/news/security/phishing-atta...
Brave Browser already has Tor integration in private tabs and working IPFS integration on -dev channel since beginning of this year https://github.com/brave/brave-browser/issues/819
https://github.com/mozilla/libdweb is one of the efforts, and it provides experimental APIs needed in Firefox to have a nice experience. So AFAIK, Mozilla not only talks about dweb, but also helps with the effort.
They never promised any Tor integration for the near future, see: https://news.ycombinator.com/item?id=17205441 and the first comment. Brave can do Tor integration because its user bases is much smaller than Mozilla's (scaling the Tor network to support the load from all FF users still requires much work).
On demand gateways with micropayments might also do the trick.
I disagree. I don't think this is okay. Aside from this IPFS story, DigitalOcean in general does not care about abuse. Unlike providers such as OVH, DigitalOcean will simply nullroute you when you fall victim to a DDoS attack. I wish they stepped up their game - until then, after hearing those stories, I will not be using their service for anything I care about.
No reputable hosting provider is going to ignore abuse complaints. The best you can hope for is a 24-72 hour window to respond to any complaint.
Interesting question of who has culpability:
- Server receiving creds seems clearly in wrong
- OneDrive hosting the html file which can be used to exfiltrate creds is a bit murkier
- Hosting a link to the onedrive url on IPFS is murkier still.
I didn't look into how GMA.html works, but a quick look just now shows that it posts to https://searchurl.bid/joyceesther0101/finish1.php
Interesting that it is 'facilitating' phishing (as in dependency in attack chain), but only to the extent that would apply to a number of general-purpose open source libraries, or the browser, or any OS or ISP.
Seems like DigitalOcean made the wrong choice, but the technical complexity of the situation is enough to not put too much blame on them. Unresponsive support is disappointing.
I switched to scaleway afterwards.
https://forum.vestacp.com/viewtopic.php?p=68594#p68594
https://www.digitalocean.com/community/questions/how-do-i-de...
Appears there was a vulnerability in this panel, seems plausible that 'owner' of this page is an additional victim of the attacker.
If you also use a browser extension like "IPFS Companion", it can automatically redirect all IPFS-looking URLs to your local gateway.
I agree this doesn't help for casual users who have never heard of it, but it's at least better than "everyone has to use a public gateway all the time".
(But point taken, a lot of people aren't using general-purpose computers.)
I doubt that Microsoft Azure is going to switch off the networking for all of Microsoft OneDrive over this.
Well:
> It was sent by PhishLabs to DigitalOcean, and DigitalOcean forwarded it to me.
I don't think this is the first complaint from PhishLabs to DigitalOcean. I do think DO would have "investigated" up to the level where they'd click the link and see "yep, that's a google sign in form". It's not up to DO to dispute claims made by people who send them abuse e-mails. As for the dispute itself, we all seem to think the IPFS was not hosting the content. But I'm not sure if that holds up in a legal case (the PirateBay is also not hosting any illegal content).
IPFS has no knowledge of the illegal content whatsoever, it all comes from the URL fragment and Microsoft Azure.
I wouldn't trust DigitalOcean with this fire first ask questions later approach especially given the technical nature of OPs setup.
https://en.wikipedia.org/wiki/Lawrence_Kohlberg%27s_stages_o...