• CmdrShepard49@sh.itjust.works
    link
    fedilink
    English
    arrow-up
    6
    ·
    1 day ago

    The author of this article seems like the jerk to me and acts like he just found a major vulnerability in Android or something not a free app that collects no PII.

    • unknownuserunknownlocation@kbin.earth
      link
      fedilink
      arrow-up
      7
      arrow-down
      1
      ·
      1 day ago

      This app is about reporting the activities of an increasingly authoritarian state. Security should be top of fucking mind in an app like that. Otherwise the authorities will hack into there in no time and then everyone involved will have a bad time.

      • Orygin@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        1
        ·
        7 hours ago

        A server that received no PII will have a hard time logging them even if the feds take over the server.

      • CmdrShepard49@sh.itjust.works
        link
        fedilink
        English
        arrow-up
        2
        arrow-down
        3
        ·
        1 day ago

        Reporting them anonymously, so what exactly is there for the government to hack in and find? This isn’t Facebook where you have to provide them with your photo ID.

        • unknownuserunknownlocation@kbin.earth
          link
          fedilink
          arrow-up
          8
          arrow-down
          1
          ·
          23 hours ago

          You do realize that if they hack in they could simply set it to log user data while making it continue to appear anonymous to the outside? Even just an IP address could be pretty useful in locating who is tipping off the public about ICE raids.

          • Orygin@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            1
            ·
            7 hours ago

            Log what user data ? None is sent and that’s shown by the guy shitting on the project in their blog post.
            Plus if they want your IP they don’t need to hack the server, they ask either the provider, cloudflare, your ISP or even just via PRISM.

          • NotMyOldRedditName@lemmy.world
            link
            fedilink
            English
            arrow-up
            5
            ·
            edit-2
            21 hours ago

            An IP address might not be sufficient to prove someone did something in a court of law, but it will definitely be enough to be thrown in a ICE detention center, assulted, and possibly deported if your skin isn’t white before it gets to court.

          • CmdrShepard49@sh.itjust.works
            link
            fedilink
            English
            arrow-up
            4
            arrow-down
            3
            ·
            22 hours ago

            You do realize that the extent of this “disclosure” was looking at what version of Apache he’s running and quite literally nothing else? No testing. No verification. No evidence.

            As pointed out in the comments on the disclosure, this version of Apache does have the necessary patches in some installs and even if it didn’t, its unlikely to leave any vulnerabilities as his app is completely bare bones intentionally for the very reasons you listed.

            You can come up with all kinds of fictional scenarios for what could happen like we’re in some hacker movie where the government just “hacked into the mainframe,” but that doesn’t make them real without any actual evidence.

            This dude obviously has a personal agenda here and is trying to make some big scandal out of nothing.

            • WhyJiffie@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              2
              arrow-down
              1
              ·
              16 hours ago

              No testing. No verification. No evidence.

              what do you mean? that Micah should have tested the vulnerability, by hacking the server? that’s heavily illegal.

              • Orygin@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                1
                ·
                7 hours ago

                That’s usually how that works. You do a pen test and report vulnerabilities found and show a proof of concept of how you did it.
                Just checking the version of Apache means absolutely nothing here and any security check that only does that is useless.

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  25 minutes ago

                  That’s usually how that works. You do a pen test and report vulnerabilities found and show a proof of concept of how you did it.

                  if the operator blocks you instead of giving a fuck, the consent for that cannot be obtained.

              • CmdrShepard49@sh.itjust.works
                link
                fedilink
                English
                arrow-up
                2
                ·
                edit-2
                10 hours ago

                Defamation is also illegal, so what’s your point? That didn’t stop him from making claims about ICEBlock without any actual proof in his rush to disparage this guy and his app as people do when they have an axe to grind. He clearly “handled it in the worst possible way.”

                • WhyJiffie@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  ·
                  26 minutes ago

                  Defamation is also illegal, so what’s your point?

                  if the iceblock dev weren’t such a douchebag, they wouldn’t be defamed. It’s not good if they didn’t update security critical software, but what’s much worse is how the dev handled it.