Hacker News new | past | comments | ask | show | jobs | submit | svacko's comments login

Surprised to see so much malware served from GitHub domains https://urlhaus.abuse.ch/browse.php?search=github


In my day-to-day work, we analyze millions of files every day, and it's well-known and well-utilized detection evasion techniques to host and serve malware from "trusted" websites. It's so widespread that I did extensive research on that issue. There are well-known apps with $Ms in funding and revenue with a plethora of malware hosted on their servers. Some are even used as C2 servers for data exfiltration. I see an increasing number of companies proactively blocking all traffic to those notorious sites to increase overall network security.

The outcome of my research was the following:

- Disjointed content moderation and cybersecurity departments: Not many companies have content moderation teams equipped to perform malware analysis or make cybersecurity-related decisions (the only company that does an exceptional job in this regard is Meta).

- If hosting malware doesn't impact the company's revenue and reputation, the content moderation team has other priorities.

- Section 230: Companies will refer to Section 230 when asked about hosting malicious content or scanning the content for potential malware.


I see a few false positives. It appears that unsigned software is being labeled as malware, and as grayware on some pages.

Unsigned software is not malware or 'grayware'. It's not inherently malicious.

I'm also seeing coin miners being labeled as malware. They often are, but I'm sure there are misclassificatons along those lines as well in this dataset.



I also found it suspicious, but it seems to be legit - the source of the blogpost can be found on github https://github.com/verygoodsoftwarenotvirus/blog/commit/6a43...


There is also a non-russian alternative called M1 that's being kickstarted https://www.cnx-software.com/2024/02/16/m1-flipper-zero-alte...


Except that it looks just like a Kickstarter scam made in hopes of attracting money from people who didn’t jump on the flipper crowdfunding bandwagon


Yes, I've experienced a few poeple drilling the additional drainage holes on the bottom of the outdoor unit, when they experienced similar problems not having a "nordic" unit. With the nordic unit I mean the features mentioned above - heated compressor and the heating condenser vane.

Though, if it's snow blowing directly inside then I think creating some barrier or add additional shielding of the outdoor unit is required,so that you minimize the chance of the snow DDoS-ing the unit (note: check your unit's service manual for the minimum free distances from all sides of the unit, especially the front one that is the most important to be kept enough free space).


I think Tutanota [0] is also worth mentioning with their transparent reports and warrant canary in place

0: https://tutanota.com/blog/transparency-report/


In the most recent episode of the Last Week in AWS podcast Corey Quinn just talked about this topic https://www.lastweekinaws.com/blog/how-google-cloud-and-aws-...

For AWS, there is also Customer Carbon Footprint tool available https://aws.amazon.com/about-aws/whats-new/2022/03/aws-launc...


My preference is to not need to care about what I'm pasting into my notes app. As I use the app on mobile, desktop OS and store not only organized content there, but also random thoughts, incl. sensitive content. That's I prefer to have it E2EE and use standardnotes.com (no affiliation, I'm just a happy customer)


Last I knew standard notes hid 2FA behind the paywall. Basic security should not be a pay feature. If they're willing to hang non-paying potential customers out to dry what other questionable security choices are they making?

I tried to reason this out with them back when they had a discourse site or forum, I don't recall which it was, and was told, I'm paraphrasing, we're not going to do that and don't ever ask again with no good reasoning given.

Not only a bad look from a security standpoint but also a bad look from a community engagement standpoint. IMO standard Notes is to be avoided.


https://standardnotes.com/plans 2fa looks to be in the free plan now, fwiw. (long-term standard notes user here)


What should they charge for then?


They seem to charge $60/year for markdown (free plan only has plaintext). I wouldn't even want to evaluate it.


What if the entire app is behind a paywall, no free version at all? Is that also wrong?


https://www.skyscrapercity.com - love to see what's being built in the cities around


Piktochart.com is working 4DWW plus national vacations - there are currently searching for a frontend dev https://piktochart.com/careers/#jobs .There are also other companies, like https://buffer.com/journey part of the people-first initiative https://peoplefirstjobs.com following the 4DWW.


OT: Spotify is apparently experiencing an outage in Europe [1] so I went to HN to check if it's not being discussed here. Found this thread but it seems it's not related, as here users are being forcefully logged out and unable to login again (hopefully not a hack) even in the latest Android app and up-to-date browsers.

[1] https://twitter.com/search?q=spotify&src=typed_query&f=live


Here's the thread discussing the spotify outage: https://news.ycombinator.com/item?id=30603574


Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: