HN user

sensitivefrost

98 karma
Posts0
Comments23
View on HN
No posts found.

Bug bounty people (myself included, though mine's quite aged) have written scrapers on all the main popular CI/CD platforms, to automagically scrape tokens from logs & submit bug reports to get paid. Unsurprising if malicious actors have done the same.

Tcl Ported to Go 4 years ago

OpenBet use it quite a lot as well, so it powers a large number of the world's most popular gambling sites.

That's not what VRchat's blog post say at all, though.

"Every month, thousands of users have their accounts stolen, often due to running a modified client that is silently logging their keystrokes as well as other information. These users – often without even realizing it! – run the risk of losing their account, or having their computers become part of a larger botnet."

People running a backdoor client and getting their passwords stolen? That doesn't sound... wrong?

Yes? That's how bug bounties work. Companies that care about their security pay for bugs. Those that don't, don't. Sony care, but $20k for this chain of bugs is pretty poor, especially when they offer up to $50k (for criticals). I'm curious why Sony think this is a High severity and not Critical.

EDIT: looks like it's not critical because of this https://twitter.com/theflow0/status/1535424299397369856

In which case, 20k still feels low, but not as unfair.

I could mildly ignore the invasive telemetry on my terminal (of all things), but making me sign into the terminal to use it is really bizarre behaviour. You make it a point on your web page that it isn't "yet another Electron app", but damn does it behave like one.

Why would you feel sorry for people making a ton of money working for a tech corporation? They know what they sign up for. Like, don't feel bad for Meta employees either or employees of weapons manufacturers either.

I mean you can. Compromising Windows networks that are poorly configured is hilariously easy.

That doesn't mean a Linux/macOS network is more secure inherently - I find people patch their macOS and Linux devices a _lot_ less than on Windows, so I find a lot of older bugs and exploits work really easily.

Entirely depends on how good you actually are at your job & keeping stuff locked down and patched.