Hacker News new | ask | show | jobs
by theamk 1913 days ago
Well, generally blocking bot c&c accounts isn’t in anyone’s “best interest”. The amount of traffic those bots generate is negligible, and there is a non-zero overhead to read an email from cybersecurity company, decide if this is legit, and enact the block in question. Still, most companies cooperate. (Thinking about it, I am not quite sure why.. is it a desire to be a good internet citizen? Or fear of being blocked by corporate firewall?)

Who owns the recipient address is completely immaterial. So is the existence of other exporters. No one says they have to mess with blockchain or the site’s database - all they need is one api endpoint. How many non-malware accesses are there that use v1 api, query that specific address, use curl user agent, and send ?limit=2 query? I bet none. That script is not flexible at all, it has a single hardcoded URL.

Finally, regarding the slow blocking : it is a valid concern, but it exists no matter if there is a blockchain or not. Remember that story about bots using invisible characters in the comments below someone’s Instagram account? I wonder how long it took researchers to explain that those innocuous looking comments from fresh accounts are actually malware related. Or imagine using some sort of foreign-language web forum as C&C: the admins there might not want to cooperate with US-based cyber security researchers at all.