Hacker News new | past | comments | ask | show | jobs | submit | eikxyz's comments login

GDPR was never intended to be "good for startups". Just like pro-climate policies are never intended to be good for the economy.

GDPR was intended to be good for peoples privacy. Pro-climate policies are meant to be good for the climate.

Somethings gotta give. People are generally more important than startups. Climate is generally more important than economy. Because without people, there are no startups. And without climate, there is no economy, people, or startups.


So who is benefiting from this article 13? The copyright holders.

Not the people, not the startups, not the EU companies.

There are things to be said about GDPR and climate, but not so much about article 13. It's just retarded and insane. These people have totally no clue.

"Artificial intelligence can recognize faces today, filter out preferences and even park independently. It should be easy to distinguish between original and parody." - Says the Germany's equivalent to the RIAA

https://twitter.com/gema_news/status/1098263167636041729


"You can talk at a distance instantly today, it should be easy to transport people instantly."


"They can modify human DNA today, so curing cancer should be easy"


I think eikxyz was only arguing in favour of the GDPR, not article 13, which is indeed obviously retarded and insane.


this is the standard of current debate: "people are more important than ...". Well done! Well done! I guess that does give carte blanch to any and all regulations that can be said to be "for the people", so all of them. Wow, nobody though about this before, really good. You are a master philospher, Sir! Pay no mind though to the people who had arranged themselves in mutually beneficial relations that these regulations hinder or destroy because they are not real people. Only those persons who need their PII "protected" (not from the state of course) are really real anyway.

Idiots like this fool are also running the EU, my god was the internet a great place before his ilk got here.


You're contradicting yourself.

> pro-climate policies are never intended to be good for the economy

> without climate, there is no economy, people, or startups


The thing to do here is to read everything this person has said and to take in the bigger picture of what they are trying to say. Focusing on the details like this is doing yourself a disservice, because it makes it look like you don't have the skills they taught you in school.


I think eikxyz means that pro-climate policies are not designed to allow quick profits; they will actually constrain some actors in the economy. They also may help to ensure the survival of the economy itself, so that at least some economic actors can still function.


That some benefits will naturally occur as a side effect of a policy does not actually change the intention of that policy.


1 Resecurity's wordpress site has directory listing turned on. Most content on the website seems to have been uploaded in february. 2 The services that does the press releases looks suspicious. 3 The second service also looks suspicious 4 Golden Bridge Silver and Gold Award winners... Anyone heard of this? Seems they sell thophies

[1] https://resecurity.com/wp-content/uploads/ [2] https://www.prnewswire.com/news-releases/resecurity-names-ia... [3] https://www.businesswire.com/news/home/20190226005414/en/Res... [4] https://goldenbridgeawards.com/store/

Looks like a fish, smells like a fish



“Resecurity Inc., California-Based cybersecurity company”

timezone_string: Europe/Kiev

Admin IP address: 109.207.124.196, AS196740, Ukraine

Really piling on the confidence here.


This one's before the Forbes article:

Citrix Data Breach – Next is what to do next newsbeezer.com "resecurity" kiev ukraine from newsbeezer.com 19 hours ago · KIEV, UKRAINE – 2019/01/ 20: Citrix Systems software ... According to Security Company Resecurity, the attacks were ...

https://newsbeezer.com/zimbabwe/citrix-data-breach-next-is-w...

Here's the article's top image sub-text:

Citrix was hit by hackers in attacks that may have exposed large amounts of customer data. KIEV, UKRAINE – 2019/01/20: Citrix Systems software Company logo displayed on a smartphone. (Photo by Igor Golovniov / SOPA Images / LightRocket on Getty Images) Getty

The image is hosted by Forbes: https://thumbor.forbes.com/thumbor/600x315/https%3A%2F%2Fspe...

Why newsbreezer has an article dated an hour earlier in a Google search than the Forbes article which is hosting the image on both sites, and why it's coincidentally sub-texted with KIEV, UKRAINE, I can't explain...


Way too sloppy for a false flag operation. Probably just some shady company trying to make a buck.

Regardless, it would be irresponsible to trust their attribution claim, especially when no evidence has been presented.


I just did a search for `"resecurity" kiev ukraine` on Google and got some strange results showing news articles from well-known sites stating KIEV, UKRAINE in context with the article's top pic... I'm not sure how to explain that:

Why The Citrix Breach Matters -- And What To Do Next Forbes "resecurity" kiev ukraine from www.forbes.com 18 hours ago · KIEV, UKRAINE - 2019/01/20: Citrix Systems Software company logo seen ... According to security firm Resecurity, the attacks were perpetrated by ...

https://www.google.com/amp/s/www.forbes.com/sites/kateoflahe...

https://www.forbes.com/sites/kateoflahertyuk/2019/03/10/citr...


Nice find. It contains the e-mail address mr.archee@gmail.com

Which seems to belong to a russian guy: https://support.webasyst.ru/forum/4011/filtr-v-vide-select/

Must be a russian speaking Iranian ;-)


Unsecured directory listing of a common php cms that shows uploads, and one of them them is a full DB dump made with phpmyadmin. The only thing missing is execution rights in that directory.

This is either an insider joke or a jump back to 2004.


this is "wordpress-normal" - the funny/sad part is its the wordpress blog of a security company investigating a huge breach...


Unless this is actually not a security company investigating a huge breach.


I've never seen directory listing turned on as a normal part of WP install.


Well, its better to get some wordpress hacked, than it is to have a server onprem get pwned and used as a inadvertent bastion to your internal network.


phpmyadmin is apprx. the only thing i remember about making a website.


Nice. According to the wp_users table there are 3 users, all nearly exactly 1 year old (2018-03-03, 2018-03-05, 2018-03-17).What are the chances that's a coincidence?


Is there any risk you take by posting that?

That is a page that I doubt the author would have wanted to be public, and is not linked to from the home page or its descendants. Wasn't that the case against weev?

(IMO, if it is public, it should be legal to post to it, but whatever.)


Interesting question. Technically, it is public. The user didn’t break anything or use any nefarious techniques. The web server is configured to list directories which in concert with file permissions makes it public. Not sure how/if this might be analogous to “just because a door isn’t locked doesn’t mean you can go in”.


feels like there isnt even a door . . "just because its in my front yard doesnt mean youre allowed to walk in front of my house and look at it sitting there."


This argument is not much different than what the grandparent is referring to. weev was convicted of conspiracy to access a computer without authorization because he advised a guy who discovered a publicly available HTTP API hosted by AT&T that returned email addresses based on guessable ids. The conviction was overturned, but on procedural grounds, not legal ones.


Directory listing wasn't on on the AT&T server.


He accessed “public” URLs that he inferred the existence of but wasn’t supposed to access. So I guess if you can start at the homepage of this site and find a link to a directory, you’re OK.


It was linked from https://resecurity.com/wp-content/uploads/, which is a common and public URL, and anything uploaded there is intended to be public. Of course, whoever uploaded it either wasn't aware or didn't think it through--maybe they thought nobody would ever visit that page.

As you can see, the link is gone now.


This url is now showing a 404.



They took it down. What did it say?


It was an SQL dump of their entire database: https://archive.is/https://resecurity.com/wp-content/uploads...


They also seem to have stolen a number of graphics on their website. If you check their filenames, they have the default filename of when you take a screenshot on OSX. Then take this one for example:

https://resecurity.com/wp-content/uploads/2019/03/Screen-Sho...

Throw it into Google's reverse image search and you'll find the graphic if was cut out of:

https://www.incimages.com/uploaded_files/image/970x450/Finan...


Thanks for finding that. This image from their directory listing (maybe on their site somewhere but I couldn't find it) shows me at least something about their offering - looks like another dark web breach alerting service.

https://resecurity.com/wp-content/uploads/2019/02/slide-3.pn...


FYI, PRNewswire is one of the oldest, respected, and expensive newswire services around. Businesswire is also very well established. Not sure how those seem “suspicious”.


Not sure if that was meant to be sarcastic. They have a pretty clear history of accepting garbage for money. https://www.seroundtable.com/google-panda-pr-newswire-change...


PRNewswire is used by the vast majority of the Fortune 1000, including for releases that are required for SEC compliance. They are probably the oldest and most widely used of all the newswire services.

The point is that using PRNewswire or Businesswire is hardly “suspicious,” because most businesses that do press releases use one or the other.


What's suspicious about PR Newswire / Business Wire? They're the industry standard wire tools in Public Relations.

The Golden Bridge trophies seem to be available to buy if you've won.


I don’t know specifically about Golden Bridge but I have been on the receiving end of other trophy clearinghouses: we were notified we had won a whatever of the year award without even applying for it and that we could purchase the actual trophy for a very reasonable price. Basically these companies’ business is selling overpriced crystal trinkets.


As have I, it's a fairly common racket. However, rights to a trophy / rights to use the logo etc are also sold by perfectly legitimate awards too.


Only fake awards sell trophies. they give the award to everything and make money in trophy sales. See also SuperDoctors, Who's Who, and pay to publish journals with no peer reviews.


Bootloader on an SD-card, a condom and lots of codeine


For businesses, security is mostly about having someone to blame. If Microsoft did not leverage the hardware encryption capabilities in the drives they would end up being responsible for the performance not being as good.

In the world of proprietary black boxes, security is evaluated by the claims of the product sheet.

Microsoft is trusting SSD manufacturers to do the right thing, just as businesses are trusting Microsoft BitLocker to do the right thing.

Personally I trust Microsoft to make decisions that are good for their stock holders. That means having just enough security to avoid ending up with the blame in cases like this.

Samsung's lawyers are probably brain storming ways to get back at those pesky security researchers who made them look bad.


Would love to play around with this, but getting this up and running seems daunting.


Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: