53

Comments

you are viewing a single comment's thread
view the rest of the comments

You do realize that if they hack in they could simply set it to log user data while making it continue to appear anonymous to the outside? Even just an IP address could be pretty useful in locating who is tipping off the public about ICE raids.

[-] Orygin@sh.itjust.works 2 points 1 day ago

Log what user data ? None is sent and that's shown by the guy shitting on the project in their blog post.
Plus if they want your IP they don't need to hack the server, they ask either the provider, cloudflare, your ISP or even just via PRISM.

[-] CmdrShepard49@sh.itjust.works 6 points 1 day ago

You do realize that the extent of this "disclosure" was looking at what version of Apache he's running and quite literally nothing else? No testing. No verification. No evidence.

As pointed out in the comments on the disclosure, this version of Apache does have the necessary patches in some installs and even if it didn't, its unlikely to leave any vulnerabilities as his app is completely bare bones intentionally for the very reasons you listed.

You can come up with all kinds of fictional scenarios for what could happen like we're in some hacker movie where the government just "hacked into the mainframe," but that doesn't make them real without any actual evidence.

This dude obviously has a personal agenda here and is trying to make some big scandal out of nothing.

[-] WhyJiffie@sh.itjust.works 2 points 1 day ago

No testing. No verification. No evidence.

what do you mean? that Micah should have tested the vulnerability, by hacking the server? that's heavily illegal.

[-] CmdrShepard49@sh.itjust.works 3 points 1 day ago* (last edited 1 day ago)

Defamation is also illegal, so what's your point? That didn't stop him from making claims about ICEBlock without any actual proof in his rush to disparage this guy and his app as people do when they have an axe to grind. He clearly "handled it in the worst possible way."

[-] WhyJiffie@sh.itjust.works 1 points 18 hours ago

Defamation is also illegal, so what's your point?

if the iceblock dev weren't such a douchebag, they wouldn't be defamed. It's not good if they didn't update security critical software, but what's much worse is how the dev handled it.

[-] CmdrShepard49@sh.itjust.works 2 points 17 hours ago

In what way is the dev a douchebag? He blocked some self-important troll who has an axe to grind against him. You literally have no idea whether his Apache needs to be updated or not or whether there are any vulnerabilities in his app.

You clearly also have an axe to grind here which is why you have nothing of substance to say and instead rely solely on unfounded accusations and name calling as an argument.

[-] Orygin@sh.itjust.works 1 points 1 day ago

That's usually how that works. You do a pen test and report vulnerabilities found and show a proof of concept of how you did it.
Just checking the version of Apache means absolutely nothing here and any security check that only does that is useless.

[-] WhyJiffie@sh.itjust.works 1 points 18 hours ago

That's usually how that works. You do a pen test and report vulnerabilities found and show a proof of concept of how you did it.

if the operator blocks you instead of giving a fuck, the consent for that cannot be obtained.

[-] NotMyOldRedditName@lemmy.world 5 points 1 day ago* (last edited 1 day ago)

An IP address might not be sufficient to prove someone did something in a court of law, but it will definitely be enough to be thrown in a ICE detention center, assulted, and possibly deported if your skin isn't white before it gets to court.

this post was submitted on 08 Sep 2025
53 points (100.0% liked)

Technology

540 readers
296 users here now

Share interesting Technology news and links.

Rules:

  1. No paywalled sites at all.
  2. News articles has to be recent, not older than 2 weeks (14 days).
  3. No external video links, only native(.mp4,...etc) links under 5 mins.
  4. Post only direct links.

To encourage more original sources and keep this space commercial free as much as I could, the following websites are Blacklisted:

More sites will be added to the blacklist as needed.

Encouraged:

Misc:

Relevant Communities:

founded 4 months ago
MODERATORS