Forgot your password?
typodupeerror

Comment America.gov is a DOGE Scam (Score 4, Interesting) 115

This "new" site is part of a larger effort by that slob to kneecap or compromise US government Web sites, and steal your personal data.

I first read about the effort here: https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fthedreydossier.substac...

Yesterday, she took a look under the hood of America.gov, and yes, it's as bad as everything else the DOGE vandals have been doing: https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fthedreydossier.substac...

Up until this point, government Web sites were designed, built, and maintained by the agencies responsible for that government service. For example, if you wanted to apply for or renew your passport, you would go to state.gov, which is run by the US Department of State, which is responsible for processing applications for and issuing passports. No other department has lawful jurisdiction over passports.

From the point of view of the law, that's still true. But the slob, without anyone's permission, kluged together passports.gov. This site was built and is run by the White House's "National Design Studio," completely outside the law and without any independent oversight. The State Department was not consulted and has nothing to do with it. Further, the site is filled with third-party trackers, analytics, and some custom code that copies every page you view, including form contents, to an unknown third party.

Oh, and the guy leading the National Design Studio and in charge of building these fake sites? He's Joe Gebbia -- cofounder of Airbnb. Read both articles for more details.

In short, you should treat America.gov as a malware site and stay well away from it. Under no circumstances should you feed it any of your personal information.

Comment Re:kudos (Score 5, Insightful) 75

what's the point?

The point is to be able to use your hardware in the manner you deem appropriate, and to ensure it is not doing sneaky shit behind your back.

If, instead of a Playstation, we were talking about rooting LG televisions to run custom Linux builds stripped of pervasive privacy-violating code and "apps," I suspect your opinion might be rather different. (And no, when the entire industry has turned to the Dark Side, voting with your wallet doesn't work.)

Comment Re:Why does anyone take this seriously? (Score 2, Insightful) 159

Remember when the Chinese destroyed that satellite in space a few years ago (2007 - geez, it's been a while) to "demonstrate their capabilities"? We NEED systems in space to defend/retaliate against that kind of stuff.

This isn't Reagan's "Star Wars" that was ridiculed. It's the new realpolitik.

Comment Re:Who will pay for this? (Score 4, Interesting) 33

To clarify, the users were OpenAI themselves, so there is no question that they would be liable in this case.

The bots were not intentionally deployed; rather, they were being tested on how well they could complete a data recovery task (downloading a certain file from a certain server on a simulated Internet) that had been complicated by putting various obstacles in the way. Unfortunately, they found a different way to solve the problem: by getting the file from the real Internet, where it was publicly available. Part of this process involved collaborating with each other by treating the RubyGems website (which is supposed to be for polished packages) like GitHub; unlike every other package site hack in history, the exploits they uploaded weren't meant to be downloaded by unsuspecting users. As usual the bots cheerfully ignored all the clues that they had escaped containment and were consistently justifying their actions as acceptable due to being in a sandboxed testing environment. (This is something OpenAI has pledged to focus on.)

The actual damage done to RubyGems seems to be that OpenAI is now unwittingly in possession of a substantial number of user login tokens. This certainly meets the definition of a data breach, but it's not like the credentials are for sale on the dark web. As a website operator I'd much rather be mauled to death by this well-meaning swarm of superintelligent infants than targeted by even a single actual malicious human. In all likelihood OpenAI will just quietly pass RubyGems a sizeable donation and it'll all blow over.

Comment Re:Dumb crawlers require dumb solutions (Score 1) 43

To be honest that was actually my first theory, since the bots didn't seem interested in exploring the rest of the domain. I suppose there's no way to know for certain. I concluded that it must be an imbecile's attempt at harvesting, though, because the queries weren't really exploring the string space in any useful way. Here's a sample:

"GET /index?author=15&go=Search&id=48&name_restrict=1&q&re&results_&results_pagenum=2980 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=5440&template=41&type HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=33500&templat HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=32640&templ HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&res&results_page&results_pagenum=39300 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_&results_pa&results_pagenum=12340 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_r&res&results_pagenum=6100 HTTP/1.1"
"GET /index?author=2&go=Search&group=0&group_restrict=1&id=48&name_restrict=1&q&results_pagenum=2920&te HTTP/1.1"
"GET /index?author=15&go=Search&id=48&nam&results_&results_pagenum=17940 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results&results_pag&results_pagenu&results_pagenum=37720 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&results_pagenum=9360&template=41&type_r HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_restrict=1&q&r&results_pagenum=28040 HTTP/1.1"
"GET /index?author=15&go=Search&id=48&name_&results_pag&results_pagenum=10400 HTTP/1.1"

The only thing this is fuzzing is the query string parser. It's not testing the limits of string buffers, it's not using interesting characters, it's just brain-damaged. The fact that it's also fetching different page numbers shows it's trying to follow page links and failing badly at doing so.

The site gets plenty of sniffing from garden-variety pests. e.g. this half-hearted attempt to find a framework or two that I don't have:

"POST /__rsc HTTP/1.1"
"POST /api/auth/session HTTP/1.1"
"POST /api/auth HTTP/1.1"
"POST /__nextjs_action HTTP/1.1"
"POST /.action HTTP/1.1"
"POST /_rsc HTTP/1.1"
"POST /api/auth/callback HTTP/1.1"
"POST /_middleware HTTP/1.1"
"POST / HTTP/1.1"

(of course, none of these URLs exist other than /, and you definitely can't just POST to it)

All this said... I've seen that spammers regularly misconfigure their tools, they'll try to register accounts with names like #[X:\LISTS\NAMES.TXT] and it only makes sense that some other cybercriminals trying to get rich quick have a similar lack of interest in programming shit correctly. Generally people don't turn to script kiddie shit if they have a personality conducive to putting in an honest hard day's work perfecting their craft.

Comment Dumb crawlers require dumb solutions (Score 5, Interesting) 43

I had a problem where AI scrapers were absolutely DETERMINED to fish out every possible query string from a search results page. Almost all of the query strings they tried were invalid due to shitty and dysfunctional string substitution. "&page=100" wouldn't be followed by "&page=101", it would be followed by "&pag&pag=1010" or something even more insanely half-baked, until the query strings were like 100+ characters long. It was the technological equivalent of watching HIV mutate in real time.

But the insane thing was that, aside from page number, they were always requesting info about the same other criteria: filtered by the same user, the same page type, and with no text string. So I just took those particular values and started banning logged-out users who requested that combination of criteria.

I figured I'd need to change my tactics in a couple of days once the botnet got bored of that particular page and moved on to requesting bogus entries for another user.

MariaDB> select count(*) from ip_bans;
+----------+
| count(*) |
+----------+
| 671671 |
+----------+

It hasn't.

Comment "Policing" Is Doing a Lof of Heavy Lifting Here (Score 4, Insightful) 57

"It is clear Flock has aspirations far beyond ALPRs to become a digital platform for policing," [emphasis mine]

They misspelled, "Orwellian suveillance and harrassment."

Law enforcement officers are already abusing Flock's existing capabilities for stalking. This will not improve matters one iota.

Comment Re:Putin's "Project Panama" (Score 2) 64

They don't need to be.

The thousand-men armies scanning books get the books by buying them by the pallet load. It's stuff that nobody really wants, like old technical books that are out of date, self-published books, etc.

If the book was actually valuable you wouldn't expect the seller to sell it for dirt cheap.

Slashdot Top Deals

Genius is one percent inspiration and ninety-nine percent perspiration. -- Thomas Alva Edison

Working...