Hacker News Security
news.ycombinator.com
news.ycombinator.com
Sometimes building some simple is the best way to build something secure.
Here's an example of an HN password reset link:
hxxps://news.ycombinator.com/x?fnid=<long-random-value>&fnop=passwd-reset
`fnid` identifies a closure. Presumably there's a hashmap of `fnid` values to closures in memory.
It used to be that this was how any action on the site was represented. I poked around for a minute though, and it's evidently not the case for upvotes any more:
hxxps://news.ycombinator.com/vote?id=<integer>&how=up&auth=<long-random-value>&goto=<return-url>
I'm interested in whether the password reset link is a potential issue still.
Using GET to change state, like they're discussing in that thread, is really more of a style issue than a security issue. You need a CSRF token, whatever verb you use.
And that was a few years before my recollection of upvotes using an `fnid`. (I could also be misremembering.)
In the case of password resets, I don't think there's a functional difference between using a map of closures with random tokens and comparing random tokens stored in a database, as is the more conventional approach. If you can guess the random token, or if you can extract them via a side channel, then you can reset passwords. And if you can't, you can't.
Which isn't to say it's not worth having a look :)
Back when I created this we wanted to publicly credit people who had helped us out and this seemed like a good way to do so.
I will never forget how they rolled the [-] button (after a decade of people asking for it and using browser extensions to have it) next to comment on the _right_ side instead of the _left_ side (like reddit).
EVERYONE complained, yet they were like "we will take your feedback into account for the next upgrade in 10 years"
Also some of us have noticed for a while Hacker News is hosted differently than the rest of YCombinator. While YCombinator uses AWS, which makes sense, Hacker News uses a small San Diego firm called M5 Computer Security. They have commented on here from time to time.
M5 Computer Security, also known as Cloud 5 Hosting and a few other names, has popped up on other forums too. The IPs that are owned by them (at least according to WHOIS) wind up holding very strange other websites that aren't say hosting customers (like how to weld underwater, how to get a foreign visa, etc). Some of their name servers also hold data for websites that are definitely not supposed to be there, like the regional government sites of a foreign country (could be part of the Sea Turtle DNS attack we have thought [1]). Also for a security company they seem to have strangely out of date websites [2]. Copyright 2003?
A few weeks ago we wound up calling the FBI's Cyberstorm hotline after we saw something weird with a government in the United States that traced back to M5 and American Internet Services, LLC (they often appear alongside M5 in the hosting records). A week later I had someone from DHS interview me at length (they just showed up at the door) for about 30 minutes. They seemed to be around organized crime, but near the end of the conversation it was mentioned "well they also do a lot of Department of Defense stuff". Uh oh. This seems to be true as they mention it on one of their websites actually [4].
Hopefully someone a few months from now will pick up the case and find out / connect to one of the many other DNS mysteries out there.
[1] - https://blogs.cisco.com/security/talos/sea-turtle-keeps-on-s...
[2] - https://www.m5computersecurity.com/audit-private.php
[3] - www.htleng.com
[4] - https://www.m5hosting.com/about-us/data-centers/san-diego-li...
One of the better documented cases of hosting companies being a proxy for intelligence wars was the 2017 lawsuit Namecheap filed against eNom and Tucows. Long story short, Namecheap was supposed to be US intelligence, and eNom and Tucows were unknown/unnamed other intelligence group/agency [1].
[1] - https://domainnamewire.com/2017/09/01/namecheap-sues-enom-tu...
It's also not a particular secret that hosting companies operate under multiple brands, buy others and at the same time new ones pop up regularly.
HN has been said for a long time to be a front by various less credibly sourced claims.
Likely Scenario: M5 is a front company. There just isn't enough care put into the websites / marketing, and not enough evidence on LinkedIn, to suggest this is a real business staffed by people who are working on stuff full time. And a hosting company definitely needs people full time...
Also this group looks almost cliche Cold War intelligence agency. Their UK name servers appear to host the authoritative records for half a dozen amateur radio groups / HF repeater runners in the UK. Fascinating, could someone reach out to them? cleddau-amateur-radio-society.org.uk AND tenby-radio-repeater-group.org.uk AND taffvaleradio.club with DNS records served from ns1.mhosting.co.uk.