Jia Tan "JiaT75": Added error text to warning when untaring with bsdtar (2021)
github.com
github.com
And it's not an isolated case, this happens pretty much always when some issues attracts attention on GH.
Can't we respect the project and give the people there space to work, and leave the peanut gallery commenting to reddit/hn/twitter/whatev.
So I say they are getting exactly what they wanted to get.
This is exactly the problem. If you want your resort be vandalized, build a nice road to it.
And some orgs are even eager to fuel this with things like Hacktoberfest.
What are you sitting on, if not an arm chair? We all agree that the xz attack was of unparalleled sophistication and complexity, spread carefully over years, funded by a State. Many people were taken in so how is it helpful to pile on Jia Tan's primary victims?
> but calls to safe_fprintf were replaced with calls to the unsafe fprintf. The diff doesn't make this obvious due to the removal of a newline in a parameter list.
It wasn't noticed because it was specifically designed not to be obvious.
Anyone who has maintained large/complex software like this knows that name recognition is worth a ton, and it kind of has to be that way. It's just not practical at all to scrutinize every commit/change as though the committer is an adversary, and particularly when you know the person it is not a reasonable ask. I would bet the truth is basically "yes, we knew him so it didn't get full scrutiny," and honestly that's an honest (but hard to give) answer.
I do hope (perhaps naively) that this (security code reviews) is something AI can get really good at in the future, because that would be a real value add IMHO.
It's like Where's Wal(do|ly): once you know where to look, it's obvious, but if you don't even know you're supposed to be looking for it, you may never find it
Sure, that's not how it's SUPPOSED to happen, but I'll eat my hat if at least 95% of people who've approved a PR at some point couldn't have been walked down that path by a dedicated attacker over time. Hopefully this has been enough of a jolt to make that less likely the next time someone tries it.
People often cite death and taxes as the only certainties in life-- we could easily include human fallibility.
What was it ... 80% of aviation accidents due human error?
In the years I worked as a nightclub bouncer, dozens or hundreds of people would try to fool me every night... and sometimes they did! I had a lot of experience foiling them, but they had a lot more time on their hands to scheme whatever thing they were scheming than I had to pay attention to them, individually.
As people pointed out, this was a technically simple attack-- the meat of the attack was psychological and emotional. In practice, particularly smart people are more susceptible to attacks like this because they subconsciously assume they'll catch everything that comes at them, and make a lot of assumptions about the attack vectors of problems based on what they're good at, like the classic XKCD about cryptography vs a wrench.
It would offer a good solution, and one that would scale.-
(Until, of course, the AI systems themselves become compromised or weaponized ...
But that is a few arms race cycles away yet.-
Sometimes you gamble and lose. The bank doesn’t care that “well there was a good chance I was going to be fine” when it comes time to pay your mortgage.
“But I’m the only one that knows the floor plan!” doesn’t quite cut it. Exit the premises and get some therapy.
so akcheually some people are sitting on a block of concrete!
theorizing that it was wrong to merge in itself is not victim blaming. but of course piling up in GH discussions and issues unconstructively, and just expressing opinions is bullying.
Raising competent empathic well balanced individuals is difficult, to say the least. And it’s not like the so called world leader elites really show they are some paragons of these traits.
Maintainers can 'lock down' the issue to just projects members, but that's very much an after-the-fact thing.
PS. And, for some people it might undoubtedly be *all* their "social" ...I guess the argument for it is that it lets people easily "get involved"? Seems like there's some merit to making it easy for users to leave feedback. Maybe thumbs-up or thumbs-down on an issue really is valuable feedback in some situations. I'm torn between saying the social features are bad because they lower the barrier for low quality engagement, and saying that even low quality engagement can lead to valuable insights.
https://web.archive.org/web/20081216011059/https://github.co...
Which changed to "social coding" later:
https://web.archive.org/web/20110217073759/https://github.co...
"social coding" eventually moved to the page title, and disappeared from the page itself:
https://web.archive.org/web/20120202143623/https://github.co...
"Social code hosting" and "social coding" are not on the front page anymore, but they definitely kept all the social features.
So, they have comment minimization by assigned moderators. Or you can just delete / edit comments and issues. Obviously not as powerful as a pre-screening queue. Less work tho!
Is there something new here I missed, or some additional context that makes this specific commit relevant right now?
Like, if we put it in the classic context of
1. Farm Karma
2. ?
3. Profit!
I'm not clear on step 2. What's step 2
And of course that pre-supposes malice (or at least greed), which is in violation of Hanlon's Razor.
Gallowboob reportedly got paid <https://knowyourmeme.com/memes/people/gallowboob>.
It used to be called Curation, Marketing, or Expert Advice but it's been algorithmified to death.
On Instagram, it makes sense to me:
1. I farm for likes and karma
2. I start endorsing low value crap from whatever fad is trending this hour
3. Profit
On HN, I have no idea what step 2 is: what is the middle step between farming and profit that doesn't involve, like, founding a startup? What's the specific tactic on this platform?
Marketing on HN can be very powerful. The mindshare gain can be enormous. Niches in general are very rewarding if the underlying platform (Google/Facebook/Amazon/Ebay) doesn't deplatform you.
I don't have time to look it up but I'm sure minimaxir (Certified HN Influencer) has made a study on it.
PG remarked on it in What I've Learned from Hacker News[1]:
"But what happened to Reddit won't inevitably happen to HN. There are several local maxima. There can be places that are free for alls and places that are more thoughtful, just as there are in the real world; and people will behave differently depending on which they're in, just as they do in the real world.
I've observed this in the wild. I've seen people cross-posting on Reddit and Hacker News who actually took the trouble to write two versions, a flame for Reddit and a more subdued version for HN."
Anecdata: just today I reactivated an account on a startup I learned about from a Show HN[2]
[1] https://paulgraham.com/hackernews.html [2] https://news.ycombinator.com/item?id=24990238
I appreciate you taking the time to respond thoroughly. Thanks!
Edit: it occurred to me that another potential reason that the tactics used to monetize karma farming on HN may be less obvious to me than on other platforms is because here, the tactics are more specifically designed to target me
In this post, they are discussing some changes to print code specifically for the libarchive project, and some notable personalities in the security community chime in, including Colin Percival (Tarsnap among others) and Taviso (Google project zero among others).
Various discussions on this backdoor (in rough chronological order):
* Backdoor in upstream xz/liblzma leading to SSH server compromise:† https://news.ycombinator.com/item?id=39865810
* What we know about the xz Utils backdoor that almost infected the world: https://news.ycombinator.com/item?id=39891607
* How the XZ Backdoor Works: https://news.ycombinator.com/item?id=39911311
* The xz sshd backdoor rabbithole goes quite a bit deeper: https://news.ycombinator.com/item?id=39956455
* XZ backdoor story – Initial analysis: https://news.ycombinator.com/item?id=40017310
† Original report, AFAICT.
Here are parts 2 and 3 (weren't discussed on HN):
>Part 2: Assessing the Y, and How, of the XZ Utils incident (social engineering)
https://securelist.com/xz-backdoor-story-part-2-social-engin...
>Part 3: XZ backdoor. Hook analysis
https://securelist.com/xz-backdoor-part-3-hooking-ssh/113007...
PS. Or some "unaffiliated" group somewhere is getting their SOF cut off ...it's not a major flaw, and no exploit. but it seems as if nobody paid due attention to actual changes.
This comment sums it up nicely with a gif: https://github.com/libarchive/libarchive/pull/1609#issuecomm...
It seems doubtful that a state actor is trying to use terminal escape sequences to hide an error message... The state actor wants code execution, not the ability to backspace some warning on a developers terminal. Besides, using such a vulnerability seems far too dangerous - those escape sequences would be plainly obvious in any log file or any inspection of files on-disk.
And at the same time, if you are an undercover state actor, there is no point in potentially revealing yourself by inserting some security problem that isn't exploitable.
For example — and this is just hypothetical - the author may have found that some consumer of this codebase uses it in a script, and consumes console output in some form. By modifying its output to behave differently, they may be able to influence the consumer’s execution in some clever way so as to create other conditions necessary for additional exploitation.
Or - the PR could have just been a test to gauge the scrutiny of the approvers.
... (until and if you see the larger picture, which might be insurmountably difficult ...
... this, coupled with AI-level scalability of social engineering, at AI-level scale -and- with an AI-level understanding of "known-outcomes" that might be desirable towards given goals: "Leader change", etc.-)
https://news.ycombinator.com/item?id=40428032 - Abusing url handling in iTerm2 and Hyper for code execution (2024-05-21)
I beg to differ, I actually checked.-
I'd hate it if I had been less than consistent :)
PS. At least from about 2021 on ...I nonetheless appreciate your curiosity).-
Yup, that's what I mean.
PS. It has also, countless times, saved me when I "retroactively" needed to claim authorship of something I had writen, by pointing it out. Most people either don't notice or do and don't say ...
Thanks for your attention to detail and the opportunity to converse.-
I like to separate every little intentional change into their own commits. So a formatting change would be separated into its own commit.
If you are looking for “red flags” notice if the diff is clean or not according to what you expect to see changed; if you only expect to see some error text change then multiple lines being changed is weird. Also use a decent diff viewer which is somewhat content/language-aware.
Stochastic karma farming benefits from a larger N, hence posting without reading.
I mean, I can make my own guesses about various forms of attention seeking and hopes to somehow cash in on high karma all day long but, to me it feels like HN is among the worst possible venues for that. I'm not aware of easy ways to convert HN karma into cash flow like you maybe could with followers on other platforms. So I don't immediately see a benefit in just farming karma for its own sake.
Is there some benefit to karma farming I'm not aware of? Like, some points-to-dollars conversion stream that I'm not in the loop on?
That said, visibility in this community IS valuable.
How many billions of dollars flow through yc companies?
Obligatory discussion of hacker news karma points: https://news.ycombinator.com/item?id=35174825
(Not to say I always do this, but I do definitely click first into comments more often than I go straight for the article - it allows a much lower bar for what seems initially interesting, and I've read a lot more fascinating stuff (submissions and discussions) than I would have otherwise that way.)
So to clarify: do you comment on the content of the post without reading it? I'm specifically interested in why people comment on links and articles they didn't read. And for maximum clarity here, I mean commenting on the content of the article, not just contributing to the various related discussions it spawns.
And to reiterate, I'm asking in earnest. It's not something I would do, so I'd like someone who does to weigh in.
But for example this thread is on such a tangent (and it could be a hell of a lot less) that TFA is completely irrelevant to what I would comment or how it would be received, so yes I might; almost certainly have on several occasions (over years and wouldn't-like-to-think-many comments).
And as an example of how it could be much less of a tangent, more related but still not require reading TFA to comment, I saw something recently where a top-level comment was along the lines 'I would use strace for this personally', and then the thread was all about strace. Commenting in that thread, other than to compare it to whatever OP was doing, doesn't really require reading the article, because it's about something else now, and that's been made clear from the top-level comment.
I suppose it's kind of like joining a discussion at a party - you don't need to be excluded just because you missed the thing that started the conversation. Difference here is if you want/need to or are interested, you can still just go and read it without someone having to awkwardly/hurriedly fill you in.
I just wish people would stop writing C code for libraries that consume arbitrary data.
I've been reading "the man who solved the market" about Jim Simons and his hedge fund Renaissance. This reminds me that there was a period just after the fall of the Soviet Union where Renaissance was flooded with very technically strong, very motivated, very hard working, and very fraudulent ex-USSR people.
They're leaking guys, wake up.
PS. The GNU GRU?