HN user

flashmob

277 karma
Posts3
Comments129
View on HN

The security model of Bitcoin comes from proof of work

This is not the security model, this is the consensus model. It's based on probabilistic finality, meaning that the probability that a transaction won't be reversed increases as more blocks are added on top. One major advantage of PoS is that it has "Absolute Finality" - after a certain amount of blocks, it's absolutely impossible to do a 51% attack. (See https://medium.com/mechanism-labs/finality-in-blockchain-con...)

Note that a higher hashrate does not mean more secure, it's a common falsehood. The security of bitcoin depends on the percentage of miners that are honest - this is mentioned the bitcoin whitepaper. Fortunately, the incentives align for the majority of miners to stay honest, and this is what the whitepaper predicted.

It wasn't shutdown for spam, and the service is not a spam service but an ant-spam service.

The service has been sending out emails since about 2013. It only lets out a limited number of emails, and there's an anti abuse policy in place. The IP address always has a good reputation with Google and Microsoft, I am well aware of all the feedback loops.

Yes, I was under the impression that this is what they meant. It would have been great to be able to to chat so that I could learn more about how much this would cost, but as outlined above, they decided to end the conversation.

You're right, currently the server is sitting in "rescue mode" and under OVH's instructions, I'm not allowed to swap it back to the normal hard disk boot. That's ok, I can still mount the disks manually via SSH and move everything out. So at least that's some good news - the server hasn't been seized.

The hosting bill has been paid up until December, so I'll will be looking to get a partial refund hopefully.

Anyways, gotta roll with the punches I guess. Thanks for your comment.

of course - create any website open to the public where they can message each other, and there will always be some abuse. It's unavoidable.

But what can you do? You can't police the messages for every potential form of abuse. (I've only ran an automated spam filter to make sure that the service is never used for blatant spam. I've also blanket-blocked some domains whenever I noticed a pattern in any abuse reports, and finally recipients were able to easily do a permanent block themselves). In any case, running a messaging service even more difficult if you're a small guy and not Facebook or Google.

I've added more information about the details of the suspension in another post on here: https://news.ycombinator.com/item?id=24998922

Admin of Guerrilla Mail here.

I've been hosting the site on OVH since 2016. The site hasn't changed much during this time, and I've been quite happy with their services until now.

A little bit about Guerrilla Mail: It its' first and foremost, an anti-spam solution. Nowhere on the website it says that's an "anonymous email" provider. In fact, the email sending feature prominently warned the user that their IP address would be included in the headers of the email sent. (The sending feature was not for anonymous email, but for the rare chance that a user needed to send an email from there or reply. Guerrilla Mail is mostly used for receiving)

The timeline for the suspension went like this:

On October 12th, I received what seemed like a canned message from the OVHCloud Abuse team, saying that my server was (quote) "used for a fraudulent activity" and threatening termination within 48 hours.

There was no further details about the nature of the "fraudulent activity". I've replied to the message asking to give more details.

On October 16, I've received a reply, but still no details about the specific case. They mentioned that, their quote: "the problem here is clearly, that your service is too easy to use for fraudulent and illegal activities. ", further threatening to shut down the service within 7 days "if the situation does not improve". They also suggested a list of measures that the site should take.

I've replied informing that most of measures that they suggested were already taken, plus some other measures including an anti-abuse policy that has worked well over the years.

On October 19, I received a reply, this time hinting that I should pay them for an additional service, their quote "Maybe you see an option in using a service which lets you customize the Whois-Record, so your contact details can be mentioned for abuse instead of ours.".

I've started to deeply consider such a service, but before I would take it up, I wanted to get more info about the alleged law enforcement requests they receive, that are never forwarded, so I've asked them for more information about these once again.

On November 2nd, I received a reply, but still no details about the specific case, or the rate of such requests, questions that I've asked previously were ignored. Again, they were offering the additional service, their quote "change of infra to have your own abuse contact in registry info".

At this stage I was ready to buy whatever they were offering. I've replied to the email with only two sentences "Is there someone I can speak with directly on your team? Let's do a 30 minute call and reach an understanding."

On November 4th, I received a reply notifying that the server has been suspended.

Btw, if there's anyone at OVH that wants to look at the issue, it is WTLXFRCVSG.85a1

Nowhere on the website it says that it's an anonymous email service provider - it was an anti-spam email solution first and foremost. In fact, the email sending feature prominently warned the user that their IP address would be included in the headers of the email sent. (The sending feature was not for anonymous email, but for the rare chance that a user needed to send an email from there or reply. Guerrilla Mail is mostly used for receiving)

I'm also one of those who switched from PHP to Go and now I have quite a bit of legacy PHP code that just works and don't have time to rewrite.

My solution:

Use a Go FastCGI client library to call PHP by talking directly to php-fpm. It saves on the HTTP request overhead and no need to run a web server. Actually, php-fpm is a decent application server itself.

Edit: Here's a link to example code: https://github.com/tomasen/fcgi_client

Yep. Also, he had to be careful not to say anything that would suggest that having a monopoly in the OS market would somehow benefit the dominance of the content busniess, it seems like the interviews were trying him on that. I think the antitrust accusations started to simmer around then?

Interesting to note, Microsoft bought Hotmail for $400 million the following year.

They register again and again after the trial has expired

This is great! You have users who are using your product, how could you not be happy? Find out why they are not converting, perhaps your offer isn't that great for their demographic? Note that even if they didn't pay to your service, they may be your biggest fans who may recommend your product to other people. DEA users are usually tech-savvy types, they are also the kind of people who are the early adopters when it comes to tech (since they were able to figure out how a DEA works & how to use one), and are probably the ones who normal people go to get advice. Don't forget that even if not a paying customer, they are still a customer in the sense that they could review your service or refer others through word of mouth! If you're blocking DEA services, it may end up costing you more.

Counterpoint: Software engineers can just make it a configuration option and leave it to the user to decide how it is run. Unlike civil engineers who can't build a bridge with a configuration option for a 'light & unsafe' bridge, software engineers can make everything an option, and that's often the best practice.

Of course, assuming that they are unaware of how their user / client / employer will actually use the software, they should be fine.

Well, there isn't such thing as 100B in cryptocurrency, so definitely not in crypto. (It would be very hard/impossible to acquire that amount right now).

This brings us to an interesting thought. Cryptocurrency transaction values have been steady growing, starting from pizzas to alpaca socks and now it's even possible to settle multi million dollar transactions. In the the future we'll probably see larger, billion dollar plus aquisitions settled in cryptocurrency, why not? For that to happen though, their marketcaps will need to rise significantly from what they are now, at least to multi trillion dollar levels.

Oops, I see, was assuming it was used for MTA too! So there was never really a dedicated TLS port for MTA to begin with?

Yes, unfortunately you'd be losing email. Port 465 has been deprecated a while back (1997).

I guess that's the problem - there is no practical way to disable plaintext email from the start. You may always need to accept the connection, see if the client will STARTTLS, disconnect if they do not and hope they don't re-try and keep hammering your servers with the same message, the error message "hey, i'm not accepting plaintext" will most likely get ignored.

Yes - it's a weak argument, and one that's probably been debunked by looking the way https lifted off recently. My view is if port 465 was still around today, it would probably get the same level of attention as port 443 has. We could have been at a stage where port 25 could be made intentionally unavailable (same way we move browsers from http to https) and everything forced to 465. Email agent developers would be forced to update their practices as well, no email should be sent over plaintext. At present, there is no good way to tell your clients you're not accepting plaintext. STARTTS is from a world where 99% of emails were plaintext.

The STARTTLS vulnerability to downgrade attacks is a significant downside that port 465 doesn't have (if using modern TLS protocols at least). My opinion is that perhaps the severity of the STARTTLS downgrade attack wasn't that much considered when port 465 was deprecated.

Perhaps fixing STARTTLS is one of those problems where the solution adds even more problems (and moving parts).

BTW, what ever happened to SMTP on a dedicated TLS port (465)? Why did it get deprecated?

Hi! I run a "copycat" site that perhaps you may be referring to in that post, GuerrillaMail.com (well, actually, I didn't copy it myself, but acquired it from another guy many years back) and also been using Redis to store all incoming mail in memory. RAM is cheap these days and you can find decently priced servers with >= 128GB easy. Haven't moved over to websockets or "chunking" / deduplication yet, but architecture and UI needs an update in that direction to make it more instant. Thanks for some ideas ;-)

Actually, like you, I've also hand-rolled most of it myself, replacing the previous guy's architecture. It's been a lot of fun. No frameworks, no bootstrap, just a few dependencies here and there. Started with PHP, but now prefer to use Go for anything new. Also hand-rolled the SMTP server which turned in to a project on its own, https://github.com/flashmob/go-guerrilla

It read like a standard run-of-the-mill press release you would expect from a big corporation. Btw, the word-stem 'develop*' appeared 31 times. Reminded me of the old famous chant...

"Developers, developers, developers!"

If you wait long enough, say, for 144 confirmations (or 24 hours, whichever is greater) then a double spend may as well be the least of your worries, for bitcoin, or any of the top mined crypto-currencies.

These double-spend attacks are only successful if the receiving party doesn't wait long enough.

Also, could't find any sources from exchanges if they were actually successful? The article didn't mention which exchanges.

Quote:

"Blockchain data indicates that the attacker successfully reversed transactions as far back as 22 blocks, leading developers to advise raising confirmation requirements to 50 blocks."

So as long as exchanges wait 50 blocks before crediting, they should be all right.

Noticed this also, no need to monitor and adjust the speed which is a mundane task (in cruise control traffic conditions). Eyes can be on the road instead.

This is similar to the problem for pilots, who can be distracted by mundane tasks due the complexity of controls in modern aircraft. If these tasks are removed, the pilot can focus on what's more important.

According to NASA " For the most part, crews handle concurrent task demands efficiently, yet crew preoccupation with one task to the detriment of other tasks is one of the more common forms of error in the cockpit."

https://asrs.arc.nasa.gov/publications/directline/dl10_distr...

These coin/porfolio trackers are a privacy nightmare. You're basically telling some stranger your detailed crypto finances, and it's unknown how your data may be used.

One of the golden rules in crypto is to never disclose your holdings to anyone on the internet, yet people are using these apps without a second thought!

These are the allegations. The prosecutor's motive is to throw up all possible allegations without necessarily being proven, accurate or true. It is up to the courts to decide whenever guilty or not. I wouldn't use that document as proof of what they actually did. Anyhow, thanks for the link.

Coinbase Ventures 8 years ago

This is the fault of the bitcoin project, not coinbase. Bitcoin transactions should just work without the end user not having to worry about what's under the hood. Why the bitcoin client cannot just use segwit / schnorr automatically? Why it doesn't provide a simple API for batching? All that stuff is up to the end user to develop.

I have some possible evidence to this theory.

At around x-mass / new year, Facebook flashed a message on my wall which said "in 2017, you received 0 birthday wishes". (Screenshot reported by others https://goo.gl/images/YWfsqb).

I thought it was amusing since it sounded like a bug, it looked like the engineer forgot to account for the special case where wishes == 0. However, putting your comment into perspective, I now think it was most likely a well-calculated tactic, perhaps generated by an AI as you suggested and I guess it wouldn't be shown unless it was A/B tested.

Interestingly, the message was shown around xmass / new year, where people tend to be more vulnerable to suicide / self harm.