HN user

z-factor

93 karma
Posts1
Comments37
View on HN

I understand how the attack works, the question was about how a practical exploit would actually be carried out. I've figured out how one would issue GET requests from the right environment, but I don't know if the same is possible for POST.

The request has to be issued by the attacker from the victim's browser. If the attacker can do that, why is he unable to read the response to that request?

Edit: I think I can see a scenario where a third-party website does these requests via an <iframe> or an <img>. I'm not sure there's a way to do POST quite as easily.

The attacker has to be able to issue requests on behalf of the user with injected "canary" strings. I fail to see a practical exploit where one can do this and wouldn't have access to the secret in the response anyway. What am I missing?

Speaking from personal experience (Ukraine).

There are plenty of job opportunities and the coders are relatively even more overpaid than in the West, so that's not the reason.

The real reason I believe is that people mostly can do this with impunity. There's very little being done for prevent or prosecute credit card fraud. In Ukraine and Russia CCs are still used very little, so this fraud hurts "the West" which is mostly seen as a good thing by the general population. Rampant piracy is practically encouraged for the same reason.

Of course this creates a barrier for doing legitimate business online. For example PayPal simply does not allow merchant accounts from Ukraine and Russia to reduce fraud. These countries are the safe haven for hosting illegal content etc. It would benefit local programmers to clean up the reputation of the country and to my great annoyance people just do not realize this. Crooks are accepted as keynote speakers at business conferences etc (they do make money, so what's the problem?)

They were using Akamai and not CloudFront last time I checked (which was a while ago). And of course they must have legacy systems that were built before their in-house solutions were available.

There seems to be a correlation between geek culture and liking engineering, but I'm not convinced there's correlation with being any good at it. I'd say there's negative correlation if any.

I think hmexx did not intend the money to be the major incentive. It seems to me that the major incentive there is seeing your idea finally implemented and having someone handle the part that you don't like or don't know how to do. However, as much as my ability is unknown from just this offer, I don't think it can be argued that it's any less than hmexx's marketing abilities -- he claims to be techie, not some hotshot marketeer.

First of all the same problem exists with hmexx offer -- he can stop putting any work in and will still be the 50% equity cofounder.

Second, if the business is promising and I have a significant equity in it, of course I'll pour more work into it. I'm on the next project only while the other party does their part marketing until we evaluate in a couple months if it's working out.

And I also want to point out that my work is not something you can buy on elance at all, and most definitely not for cheap anywhere.

There's value in getting it done fast and right the first time and having quality talent invested in the success. The upfront money is more of a way to guarantee that the idea person is invested in the success as well.

You could be right as well and then it's a testament to disproportionate leverage money has in our world.

Well, the consensus is that the value of an idea is almost certainly zero, so the only way to make it worthwhile is to get one runaway success in a big pool of attempts. Everyone knows the VC version of this approach. This is how it would look like for a programmer. I'm not dead-set on these specific upfront costs and equity split, this is just the reverse of the original offer.