Hacker News new | past | comments | ask | show | jobs | submit | EKSolutions's comments login

It looks like someone has compromised one of their subdomains for Polyfill

Update: Subdomain seems to be returning normal responses again now.


You mean the IA included some JS polyfill from a subdomain and that's what's compromised / where the alert is coming from?



yes, "https://polyfill.archive.org/v3/polyfill.min.js?features=fet..." is the URL with the malicious code


It looks like it is running the service that was part of the supply chain attacker earlier this year. https://github.com/polyfillpolyfill/polyfill-service/issues/...


The service was fine, it was the "official" hosted instance of the service which was compromised. IA appears to be running their own instance.


That was a DNS hack of polyfill.io though right? This looks like it was/is self hosted.


Yeah I'm getting this exact response from the above URL now:

https://sourcegraph.com/github.com/polyfillpolyfill/polyfill...

Seems like they self hosted that service


Correct. The source subdomain of the popup seems to be hxxps[:]//polyfill[.]archive[.]org


That would perhaps explain how they managed to inject the JS alert popup, right?


Yeah, but the leak has been confirmed by HIBP, I found my address in there.


DOH. I hadn't heard this.


As someone who makes quite a few avatars for myself and friends, there is a flag for NSFW when publishing your avatars to VRChat's servers as well as ones for realistic violence, gore and such. I'm unaware of what impact these flags have for the use of said avatars though.

I have tested a fully SFW avatar with the NSFW flag checked in the past and I was able to use it just fine inside private and public lobbies so what we actually need here is a way for either world creators and/or lobby visibility settings to restrict what avatar flags are allowed within the current session of that lobby, as well as the ability for users to auto hide/show avatars with specific flags checked.

This wont be bullet proof as this relies heavily on user based trust (which VRChat have a long history of being against) and someone can very easily reverse what I did and mark a heavily NSFW avatar as SFWto bypass such filters, but it will be a good start for limiting exposure to these avatars.


I am just a regular (free-)user in VRChat, and have never seen a "NSFW"-tag or any kind of rating on avatars, so I thought there were no such thing. I wonder how it is used then.


Just a small correction here. Millions of people use the Fediverse.

Whilst Mastodon brands itself as it's own platform, it's really just one of the many freely available solutions that are used to socialise on the fediverse.

It's a shame that they seem to make an effort to hide this fact when other solutions such as Pleroma and Misskey make it very clear what the Fediverse actually is and that you can use a vast array of software to connect to it.


I actually based that on my memory of the last time I checked fediverse stats. It's currently 1.6 active and about 4 total. Okay, not millions plural if we're only counting active users (and we know MAU is only meaningful to capitalist entities that don't care about people who log on regularly at > month intervals), but certainly enough to suggest some people care, contrary to the post I replied to.

You would have to put something forward to show an effort to hide the existence of other compatible AP implementations before I could comment on that, but I certainly haven't seen it. Mastodon's own joinmastodon.org has two testimonials making it clear the fediverse is larger than Mastodon. And I 100% agree with them: it's the best of those I tried, and I tried them all.

A lot of people confuse a lack of promotion with hiding. Maybe you've made the same mistake here. Mastodon's own blog and documentation regularly mentions the fediverse. All of this is extraordinarily beside the point of the post you replied to, so that's the last I'll say here on this topic.


ISP Router in modem mode

pfSense router

24 port PoE Managed Switch

This then splits off to my homelab, Ruckus & Unifi APs for WiFi and a few other switches around the house for the office, TV and bedrooms.


That's a good setup, pfSense is actually pretty sweet.


Can highly recommend opnSense, a fork with no tracking.


pfSense tracks users? Source?


As someone who has also been running a Misskey server for a little while, I've observed that whilst the resouce usage is a little higher than other federation softwares such as Pleroma, the stability is amazing, even on the development branch.

There are some features missing however that I've grown accustomed to. Functionality that I quite often find myself using on a Pleroma based installation such as leaving internal comments on reports, easily being able to mark posts and media as sensitive and different levels of instance specific blocks (media removal, hidden from public timelines, follow only) are either hidden or not implemented as of yet within Misskey but the development of this software currently seems to be adding in all of the community recommended features that we feel are missing.

Whilst I'm not 100% happy with Misskey in it's current state, I think it's only a matter of time before all of the most popular missing features have been implemented and it become a viable replacement for other more mature fediverse softwares.


A lot of clients that I've worked with will purchase multiple domains for their single website. I always recommend doing a 301 Redirect to the primary domain name with all of the secondary domains.


It's a shame really, I both really want to see the technical details from that post-mortem but, at the same time, I don't want to see such an amazing project go.


The cynic in me thinks the website won't self destruct, but instead will stop working because the domain isn't renewed or the server isn't responding.


I've adopted a naming scheme after Pokemon. My main rig is called Raichu, whilst one of my dedicated servers is called Onix.

The main reasoning behind it was to ensure a large pool of names without having to reuse any from past machines.


Slack seems to be loading just fine for me. What seems to be the issue?


They've posted an update on their status tracker: http://travaux.ovh.net/?do=details&id=43793&


Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: