Hacker News new | ask | show | jobs
by m3047 1401 days ago
I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances.

With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you applied for credit with them. No funds are stolen. You demand they show proof. They say nope, because TTPs. So: how do I know it's a one-off, and not data theft by fraud at scale? Off goes a letter to the FTC...

Do you think like a muppet? Here is satirical example (http://athena.m3047.net/temporizing.html):

    TEMPORIZING FOUND NOT TO BE A FORM OF LYING
    
    "Temporizing", which is speculating from what we know now as to the
    motives of actors in the past and presenting that as historical fact,
    has been found not to be a form of lying. "Social proof demonstrates
    that temporizing is not lying" said a social commentator.
    
    The news was greeted optimistically as a good day for humanists and
    levels the playing field because "now the standards of proof we need
    to meet for the existence of society are the same as for religion".
    
    "People must have known about this in the past because it seems
    like they should have" said a man in the street. "Everybody who
    believes in science trusts society" said another.
2 comments

I have no idea what your post is about but from MS's perspective it isn't the site owners but MS's users around the world that are victims of thr threat actor that need protection. If it truly is a compromised site then the site owner is also a victim but as owners it is also their duty to secure and cleanup their site that is currently endangering the public.
Microsoft is not the Guardian of the World. If they take it upon themselves to act as such without being a responsible Netizen (cooperating with other site operators to provide a higher quality Net) then they are more interested in cementing their own position rather than being a part of a civilized Net.

Imagine if I just suddenly started spreading around rumors of your malfeasance and shadyness, and untrustworthyness.

It's a big deal.

They are not guarding the world but their windows users that don't use chrome but edge and IE (MS browsers) in this case, google and firefox also do this by default.

Leave it to HN to get me to defend even MS lol.

If it truly is a compromised site then the site owner needs to clean it up; but starting the sentence with "If.." doesn't make it so.

Alex Pinto's classic research into the (lack of) overlap among threat indicator feeds should be a shot across the bow; I worked with threat indicators for a decade. To fend off muppet thinking I would like to remind everybody that they're selling threat indicator feeds; nobody that I know of sells not-a-threat feeds. A false positive means a site was falsely reported as a threat [sp]; a false negative does not mean that it is good, it simply means it is omitted from the list of threats.

In my experience vendors are a lot more worred about false positives than dropping something which is a threat on the floor (false negatives in context). However, moral hazard pushes them to publish things which turn out to be false positives anyway, because at the end of the day they're selling FUD.

My network, my rules. Something doesn't have to be a threat for it to be blocked from a private network in my opinion; there are lots of reasons for that, including minimizing potential threats. Something could be hosted on stinky infrastructure, but it's unknown or hasn't been demonstrated to be a threat. Profiles for operational security vary, and so does the appetite for proactively blocking (and whitelisting necessary resources): just because it's legal doesn't mean it doesn't put me at a competitive disadvantage if people know what I'm doing. I have no problem with people sharing and discussing such indicators, but there has to be attribution to the sharer: they have a reputation to be considered with equal concern as that of the indicators they publish.

If you're going to do something public with such information, you can't point fingers at "AI" and indicators you found in a paper bag on the bus: you do that, then you own it. Saying the victim deserves it is something you'd better be prepared to defend in court.

In many of these extreme cases where it's non-obvious what is wrong, the victim IS often the one responsible.

Example: Viral video shows police pulling unarmed (and allegedly innocent) suspect out of a parked car that sparks outrage. It's later found out that the victim was previously evading police pursuit just minutes before, and was trying to blend in with the other cars in a lot.