Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I just don’t think people are doing malicious ads like that. Like I’m sure it exists but like what’s the point? If you are the malicious person you pay money for ads to freeze someone’s computer and that’s it? It’s not even like you would gain anything from it
 help



Failure to imagine an incentive doesn't mean there isn't one. You can't rely on this type of thinking to reason about security. The thing you would have never thought of is what gets you.

For example, an ad provider itself can be hacked by a malicious party, so the "pay money for" part no longer applies.

Or an attack by a state actor or other large entity, where paying for a coordinated disruption of some region or company makes financial or military sense.

Those are just two things that came to my mind, and are likely a fraction of plausible incentives someone might have now or in the future. People are creative and unpredictable. Weird shit happens. Fact is stranger than fiction...

Instead, just ask: should visiting a website ever have the power to freeze your computer without your consent? If you think the answer is no, this is a security bug and it should be fixed.


That’s why I said I’m sure it does exist but based on it only freezing the computer until you reboot it that’s not useful for hackers doing it to make money and doesn’t seem that useful for disruption unless of course you do hack a bigger ad network then I could see it legitimately being disruptive rather than a slight nuisance. It definitely should be fixed though, it’s crazy it’s gone so long with no fix



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: