being starved of money for years by advertisers, payment providers, and service providers
Given the language in this announcement that lays blame at everyone else's feet except the people responsible for maintaining the platform, I'm pretty sure that no lessons were learned, and that the security is not likely to improve beyond whatever bandaids that were needed to address this hack.
transcriptase · 2d ago
Get real. Companies with infinitely more money, staff, and robust security practices are hacked every day. The only difference is they put out a vague generic corpospeak statement whereas this one admitted it was caused by a skeleton crew on a shoestring budget getting caught out. Given the nature of their user base and how many others would love to see 4chan go down, if things were as bad as you imply then hackers would be taking the site down weekly.
MichaelZuo · 2d ago
Source?
I have never heard of a bank’s core mainframes being hacked in the last decade (outside of pen tests), even for mid size banks outside the global top 100.
These are not the core mainframes… the only parts that actually get what might be called lavish spending on security.
Everything else outside of that… banks obviously have incentives to cut security spending to as low as possible.
transcriptase · 2d ago
Nobody is comparing 4chan to bank mainframes except you. I can’t give a source for something I didn’t claim in the first place.
MichaelZuo · 2d ago
Are you confused?
The claim was “ Get real. Companies with infinitely more money, staff, and robust security practices are hacked every day. ”
Banking core mainframes are the only thing I know of that gets anwhere near that kind of claim in terms of money, staff, and “robust security practices” 24/7/365.
And even then it’s far from infinite.
transcriptase · 2d ago
“Infinitely more” compared to a shoestring budget does not mean infinite unless you want to be annoyingly pedantic.
The fact is I provided a fairly comprehensive list of hacks and breaches, many coming from large public companies that spend more in a year on security than 4chan brings in for ad revenue in a decade.
MichaelZuo · 2d ago
It’s not even a million times more for a typical mid size bank… probably not even 100,000x… and as far as I know their core mainframes have been 100% secure over the past decade.
Hence my point.
Are you even fully reading my comments?
If you only meant that your claim applies only within an upper limit of say 1000x… saying “infinitely more” is obviously going to mislead some fraction of the readerbase.
sjdrc · 2d ago
What are you talking about? There are massive breaches of huge companies who should be doing better all the time.
In 2017:
> More than 40% of the population of America was potentially impacted by the Equifax data breach.
In 2022:
> In September 2022, Optus experienced a major data breach that exposed the personal information of millions of customers
That's just 2 off the top of my head.
MichaelZuo · 2d ago
Did you miss the words “bank” and “core mainframes”?
i.e. what they actually might spend millions of dollars per week on securing.
meinersbur · 1d ago
Because only a hacked "core mainframe" (definition please) of a bank can excuse the lack of resources at 4chan? Only accepting overly specific evidence is a neat trick to never lose an argument.
bradly · 2d ago
Even when talking about themselves in the article they mostly focus on some hardware server business.
In software outdated dependencies are vulnerabilities. The tech leadership knew this tradeoff and closed their eyes and hoped they'd get to it before someone else did. They did not and you shouldn't expect to be able to either.
If you do not have the resources to support the continual, ongoing updating of a dep, you do not the resources to add said dep.
ivraatiems · 2d ago
How likely is it that the attacker, who now has all of their source code, has already identified several additional vulnerabilities they can use? Seems pretty likely to me.
I don't think advertisers, payment providers, service providers, or hardware vendors told 4chan what version of OpenBSD to run or how often to update packages. Those are tasks that require time and effort, yes, but they're not herculean. They could have been done. I think laziness and disinterest are the more likely reasons.
stego-tech · 2d ago
So…it sounds like typical 4chan?
ForOldHack · 2d ago
"We are still standing..." with our pants around our ankles, running around headless, seamless, breathless, brainless.
"I'm pretty sure that no lessons were learned." I would bet that was the case.
RIMR · 2d ago
>One slow but much beloved board, /f/ - Flash, will not be returning however, as there is no realistic way to prevent similar exploits using .swf files.
Wow, this is a pretty incredible level of incompetence. Server-side SWF exploits are easily mitigated, unless they are using some sort of server-side SWF interpreter, which is absolutely not needed if you implement client-side Ruffle (or just require people to install the browser extension).
They can complain all they want that advertisers and payment processors refuse to work with them, but it's clear that no competent engineers want to work with them either if they're saying stuff like this.
r9zgWUN7WS3k6i · 2d ago
It seems that you're thinking about the SWF content in terms of playback, which is not what they were doing. They were looking inside the bundles for ZIP files and malware (4chan users to shove horrible things into the files they upload), and extracting metadata from the SWF. We'll never know the exact details unless they share the source code. It is possible to write a secure SWF parser, but I think they decided to stop supporting this relic instead.
> Ruffle
Yes, they used that. Take a look at the board.
moralestapia · 2d ago
You can always volunteer to help "the incompetents".
kace91 · 2d ago
Does 4chan contain anything worth checking nowadays?
I remember visiting the site as a teenager to check rage comics, and even for the abrasion of the internet of the time it was too shocking for anything beyond an occasional look - random gore, pictures of underage girls, racist tirades and the like.
I know some people enjoy that Wild West, lack of rules environment for some reason, but is there any content that’s worth it for those who don’t?
clarionbell · 2d ago
One of those things (the one that's definitely illegal) is gone for long time now. I think more than a decade. The rest is very much still there.
reginald78 · 2d ago
I've heard there's a lot of local AI discussions there that don't really occur anywhere else.
Waterluvian · 2d ago
I think it’s kind of funny but also entirely unsurprising that 4chan’s post about getting hacked is one of the most honest posts about this topic I’ve seen.
silexia · 4d ago
4chan is controversial and often very ugly, but it is one of the few old school message boards that allows free speech left.
Like the ACLU used to do, we should help them stay online and exercising their free speech, even if it is annoying and gross.
santoshalper · 2d ago
As a long time ACLU financial supporter, I could not disagree more. 4chan is not and never was a bastion of free speech. Comparing 4chan to the ACLU is like comparing a toddler smearing shit on a wall to art. To practice free speech requires an intent to express a point of view. 4chan had to point of view and was just a shithole.
john-h-k · 2d ago
> To practice free speech requires an intent to express a point of view
Excellent, now we can ban speech we don’t like by just saying it doesn’t actually express a point of view
chris_wot · 2d ago
You can't yell out in a theatre that there is a fire and cause a stampede.
Hopefully, that works. It's the first time I've done an archive like that. It works for me, but it always did because I'm using the Bypass Paywalls Clean add-on in Firefox https://gitflic.ru/project/magnolia1234/bpc_uploads
chris_wot · 2d ago
So, you can yell "fire" falsely and cause a stampede?
Alex Jones would like a word with you.
skyyler · 2d ago
Alex Jones defamed families by lying about the details of their children's deaths on his internet show. Courts have decided that his actions count as defamation.
Why did you bring him up here? Do you think his being punished for profiting off of the defamation of school children is a violation of his first amendment rights?
chris_wot · 1d ago
No, just the opposite. It wasn't a violation of his first amendment rights. You can't target the families of shooting victims like he did and claim that it was "free speech".
gruez · 2d ago
Yes, because the current supreme court standard is "imminent lawless action".
mikestew · 2d ago
Alex Jones would like a word with you.
As TFA helpfully points out, defamation is outside First Amendment protection.
ternaryoperator · 1d ago
Alex Jones lost a civil case to the families of the victims. There was no first amendment issue because the first amendment specifies what the government can and cannot limit w.r.t. speech.
hn_acker · 1d ago
> There was no first amendment issue because the first amendment specifies what the government can and cannot limit w.r.t. speech.
Defamation is by definition unprotected speech, but in the US the legal criteria of what is protected and unprotected speech fundamentally revolve around the First Amendment. The courts, part of the government, enforce civil disputes. The First Amendment applies to civil lawsuits which would directly or indirectly restrict or compel speech.
Alex Jones met the criteria for defamation in multiple civil cases because he spread false statements (conspiracy theories, to be clear), he ignored every indication that his statements were false (in a way that I believe fulfills at least the "reckless disregard of whether it was false or not" branch of the actual malice standard established in Sullivan [1]), and his statements harmed the families reputations (to the point where people motivated by or hiding behind his lies threatened the families [2] and defaced at least one victim's grave [3]).
Disclaimer: I personally believe that Alex Jones knew his statements were false and spread them anyway (the "with knowledge that it was false" branch of actual malice).
> So, you can yell "fire" falsely and cause a stampede?
As the article I linked points out, that trope was (and still is) a hypothetical that tells us nothing useful about first amendment speech rights. The reason the article is so valuable and often cited is when one of those first amendment tropes is tossed into a discussion, it's usually to imply some specific speech which is protected - is not protected. They are often deployed either in error by those who don't understand how very narrow and incredibly rare first amendment exceptions actually are, or as a bad faith rhetorical device by those who already know the first amendment protects speech they wish it didn't.
As a student and fan of first amendment jurisprudence, the fascinating thing about the tropes is that most of them come from old, exceptional cases where the court got it wrong. Cases which were either reversed by later courts or so thoroughly disavowed they've never come back before the court. A long time ago, various eras of SCOTUS courts wobbled around in the long process of figuring out first amendment exceptions and some bad decisions were made - then later corrected. After decades of trying (and failing) to work out a set of rules permitting "good speech" while stopping "bad speech", it became obvious it was impossible.
Over the past 50 years or so, SCOTUS narrowed in on a detailed set of precedents which are as consistent and crystal clear as they are radically extreme - always protecting almost ALL speech - including the worst, most vile, offensive and hateful speech that has no redeeming value whatsoever. Speech I personally despise and wish no one ever said. While I hate the speech (and, often, the speaker), I fiercely defend the first amendment which protects it. Tolerating the awful things people I dislike do with their rights is the price of still having those rights when we need them most. After all those decades of trial and error, in the end, I think SCOTUS finally got it just about perfect.
So the next time you feel like hauling out the "fire... crowded theater" thing, consider instead just saying "The goddamn first amendment fully and absolutely protects this offensive, vile, bullshit speech - and I hate that these assholes said this shit because it's wrong - and here's why..." This would have the benefit of very likely being correct regarding the first amendment and I'd totally respect your feelings and even probably agree with you.
chris_wot · 1d ago
You could more easily have quoted ''Brandenburg v. Ohio'', 395 U.S. 444 (1969) [42]-[44]:
The line between what is permissible and not subject to control and what may be made impermissible and subject to regulation is the line between ideas and overt acts.
The example usually given by those who would punish speech is the case of one who falsely shouts fire in a crowded theatre.
This is, however, a classic case where speech is brigaded with action. See Speiser v. Randall, 357 U.S. 513, 536—537, 78 S.Ct. 1332, 1346, 2 L.Ed.2d 1460 (Douglas, J., concurring.) They are indeed inseparable and a prosecution can be launched for the overt acts actually caused. Apart from rare instances of that kind, speech is, I think, immune from prosecution.
Absolutely. Point is we have to judge it in context. People saying horrible things for no reason on a message board is fundamentally different to causing a stampede in a cinema.
I agree that we need laws to make "yelling fire and causing stampedes" illegal. I do not agree that "free speech requires an intent to express a point of view" is the correct way of implementing this.
RIMR · 2d ago
Absolutely not. Free speech exists just fine on the Internet, evidenced by the fact that a site like 4chan is capable of existing in the first place. We don't have to financially support repulsive communities just to protect their ability to exist.
If 4chan were taken down by government action, I might be inclined to speak up for them in some capacity, as I don't consider that anything 4chan is currently doing illegal, but that's not the situation here. If 4chan dies because it's a poorly-managed shithole with no allies, then we can and should let it die, and rest easy knowing that it wasn't censored, it collapsed under it's own debt.
rideontime · 2d ago
What are you planning to do to help them stay online?
knowitnone · 2d ago
they were clearly focused on purchasing hardware over writing secure code
bradly · 2d ago
I agree. It is interesting how much they focus the hardware servers in the article.
I'd be more interested knowing which package was vulnerable?, was it a known exploit?, and what systems were/are in place to alert on vulnerable dependencies?. Instead they are focused on the new servers just taking too long and not enough money because of advertiser pressures.
dbaggerman · 2d ago
They do mention their OS being out of date. One possible interpretation is they are using packages provided by a Linux distro, and getting up to date may have required a full OS update.
If that's were case, it would be easy to see how they might want to tie their OS upgrade to a hardware refresh rather than taking servers offline for a reinstall.
j_bum · 2d ago
According to a Firebase video [0], the outdated and exploited package was called GhostScript.
Fireship is the channel name - firebase is the product he initially had based his channel off
j_bum · 2d ago
Oops - thanks for correcting my typo
xnx · 2d ago
Probably didn't even need to change their code, just get on current versions.
lysace · 4d ago
This is a worthwhile read. Don't trust user input and try your damnest not to feed it into third party components. If you do, keep them up to date.
giancarlostoro · 2d ago
I wonder if 4chan would benefit from open sourcing their website. Reddit used to be this way. Outsource the dev work to the open web.
Funes- · 4d ago
One of the pillars of the old, non-infested-by-normies Internet, still stands. Good news.
esseph · 2d ago
I remember when that site came about. It was a shithole then, and it's even worse of a shithole now.
mrandish · 2d ago
Yeah, it's never really been a place I'm interested frequenting but I'm also oddly pleased that we live in a world where it can still exist.
RIMR · 2d ago
Keeping a website that has openly catered to pedophiles and nazis online is hardly "good news", unless you are a pedophile or a nazi.
It won't matter for long though. The userbase has had its trust shattered, and this blogpost makes it clear that 4chan has no ability to defend itself from future attacks, which are absolutely coming.
No comments yet
yapyap · 2d ago
lol.
I think it’s moreso that when a normal person enters 4chan they either decide to get out while they still can or stay and become whatever the opposite of a “normie” is.
Wouldn’t say the latter sounds like it would be worth it at all though.
bslanej · 2d ago
There will always be places devoid of normies, thankfully. They exist in every platform, new and old. Knowledge of dog whistles will be necessary though…
bob1029 · 2d ago
Since when has 4chan had an official blog?
tonnydourado · 2d ago
Hopefully, not for long.
smitty1e · 2d ago
Curious as to the basis for animus.
baggy_trough · 2d ago
Wonder what they were feeding that pdf into. Ghostscript perhaps?
santoshalper · 2d ago
Imaging dedicating hundreds or thousands of unpaid hours of your life to protect and preserve what amounts to a truck stop toilet. What a total fucking waste.
They should, in fact, give up and use the time for literally anything else.
Given the language in this announcement that lays blame at everyone else's feet except the people responsible for maintaining the platform, I'm pretty sure that no lessons were learned, and that the security is not likely to improve beyond whatever bandaids that were needed to address this hack.
I have never heard of a bank’s core mainframes being hacked in the last decade (outside of pen tests), even for mid size banks outside the global top 100.
Everything else outside of that… banks obviously have incentives to cut security spending to as low as possible.
The claim was “ Get real. Companies with infinitely more money, staff, and robust security practices are hacked every day. ”
Banking core mainframes are the only thing I know of that gets anwhere near that kind of claim in terms of money, staff, and “robust security practices” 24/7/365.
And even then it’s far from infinite.
The fact is I provided a fairly comprehensive list of hacks and breaches, many coming from large public companies that spend more in a year on security than 4chan brings in for ad revenue in a decade.
Hence my point.
Are you even fully reading my comments?
If you only meant that your claim applies only within an upper limit of say 1000x… saying “infinitely more” is obviously going to mislead some fraction of the readerbase.
In 2017: > More than 40% of the population of America was potentially impacted by the Equifax data breach.
In 2022: > In September 2022, Optus experienced a major data breach that exposed the personal information of millions of customers
That's just 2 off the top of my head.
i.e. what they actually might spend millions of dollars per week on securing.
In software outdated dependencies are vulnerabilities. The tech leadership knew this tradeoff and closed their eyes and hoped they'd get to it before someone else did. They did not and you shouldn't expect to be able to either.
If you do not have the resources to support the continual, ongoing updating of a dep, you do not the resources to add said dep.
I don't think advertisers, payment providers, service providers, or hardware vendors told 4chan what version of OpenBSD to run or how often to update packages. Those are tasks that require time and effort, yes, but they're not herculean. They could have been done. I think laziness and disinterest are the more likely reasons.
"I'm pretty sure that no lessons were learned." I would bet that was the case.
Wow, this is a pretty incredible level of incompetence. Server-side SWF exploits are easily mitigated, unless they are using some sort of server-side SWF interpreter, which is absolutely not needed if you implement client-side Ruffle (or just require people to install the browser extension).
They can complain all they want that advertisers and payment processors refuse to work with them, but it's clear that no competent engineers want to work with them either if they're saying stuff like this.
> Ruffle
Yes, they used that. Take a look at the board.
I remember visiting the site as a teenager to check rage comics, and even for the abrasion of the internet of the time it was too shocking for anything beyond an occasional look - random gore, pictures of underage girls, racist tirades and the like.
I know some people enjoy that Wild West, lack of rules environment for some reason, but is there any content that’s worth it for those who don’t?
Like the ACLU used to do, we should help them stay online and exercising their free speech, even if it is annoying and gross.
Excellent, now we can ban speech we don’t like by just saying it doesn’t actually express a point of view
Hopefully, that works. It's the first time I've done an archive like that. It works for me, but it always did because I'm using the Bypass Paywalls Clean add-on in Firefox https://gitflic.ru/project/magnolia1234/bpc_uploads
Alex Jones would like a word with you.
Why did you bring him up here? Do you think his being punished for profiting off of the defamation of school children is a violation of his first amendment rights?
As TFA helpfully points out, defamation is outside First Amendment protection.
Defamation is by definition unprotected speech, but in the US the legal criteria of what is protected and unprotected speech fundamentally revolve around the First Amendment. The courts, part of the government, enforce civil disputes. The First Amendment applies to civil lawsuits which would directly or indirectly restrict or compel speech.
Alex Jones met the criteria for defamation in multiple civil cases because he spread false statements (conspiracy theories, to be clear), he ignored every indication that his statements were false (in a way that I believe fulfills at least the "reckless disregard of whether it was false or not" branch of the actual malice standard established in Sullivan [1]), and his statements harmed the families reputations (to the point where people motivated by or hiding behind his lies threatened the families [2] and defaced at least one victim's grave [3]).
Disclaimer: I personally believe that Alex Jones knew his statements were false and spread them anyway (the "with knowledge that it was false" branch of actual malice).
[1] https://en.wikipedia.org/wiki/New_York_Times_Co._v._Sullivan
[2] https://en.wikipedia.org/wiki/Alex_Jones
[3] https://apnews.com/article/alex-jones-infowars-bankruptcy-sa...
As the article I linked points out, that trope was (and still is) a hypothetical that tells us nothing useful about first amendment speech rights. The reason the article is so valuable and often cited is when one of those first amendment tropes is tossed into a discussion, it's usually to imply some specific speech which is protected - is not protected. They are often deployed either in error by those who don't understand how very narrow and incredibly rare first amendment exceptions actually are, or as a bad faith rhetorical device by those who already know the first amendment protects speech they wish it didn't.
As a student and fan of first amendment jurisprudence, the fascinating thing about the tropes is that most of them come from old, exceptional cases where the court got it wrong. Cases which were either reversed by later courts or so thoroughly disavowed they've never come back before the court. A long time ago, various eras of SCOTUS courts wobbled around in the long process of figuring out first amendment exceptions and some bad decisions were made - then later corrected. After decades of trying (and failing) to work out a set of rules permitting "good speech" while stopping "bad speech", it became obvious it was impossible.
Over the past 50 years or so, SCOTUS narrowed in on a detailed set of precedents which are as consistent and crystal clear as they are radically extreme - always protecting almost ALL speech - including the worst, most vile, offensive and hateful speech that has no redeeming value whatsoever. Speech I personally despise and wish no one ever said. While I hate the speech (and, often, the speaker), I fiercely defend the first amendment which protects it. Tolerating the awful things people I dislike do with their rights is the price of still having those rights when we need them most. After all those decades of trial and error, in the end, I think SCOTUS finally got it just about perfect.
So the next time you feel like hauling out the "fire... crowded theater" thing, consider instead just saying "The goddamn first amendment fully and absolutely protects this offensive, vile, bullshit speech - and I hate that these assholes said this shit because it's wrong - and here's why..." This would have the benefit of very likely being correct regarding the first amendment and I'd totally respect your feelings and even probably agree with you.
The line between what is permissible and not subject to control and what may be made impermissible and subject to regulation is the line between ideas and overt acts.
The example usually given by those who would punish speech is the case of one who falsely shouts fire in a crowded theatre.
This is, however, a classic case where speech is brigaded with action. See Speiser v. Randall, 357 U.S. 513, 536—537, 78 S.Ct. 1332, 1346, 2 L.Ed.2d 1460 (Douglas, J., concurring.) They are indeed inseparable and a prosecution can be launched for the overt acts actually caused. Apart from rare instances of that kind, speech is, I think, immune from prosecution.
https://www.law.cornell.edu/supremecourt/text/395/444
I agree that we need laws to make "yelling fire and causing stampedes" illegal. I do not agree that "free speech requires an intent to express a point of view" is the correct way of implementing this.
If 4chan were taken down by government action, I might be inclined to speak up for them in some capacity, as I don't consider that anything 4chan is currently doing illegal, but that's not the situation here. If 4chan dies because it's a poorly-managed shithole with no allies, then we can and should let it die, and rest easy knowing that it wasn't censored, it collapsed under it's own debt.
I'd be more interested knowing which package was vulnerable?, was it a known exploit?, and what systems were/are in place to alert on vulnerable dependencies?. Instead they are focused on the new servers just taking too long and not enough money because of advertiser pressures.
If that's were case, it would be easy to see how they might want to tie their OS upgrade to a hardware refresh rather than taking servers offline for a reinstall.
[0] https://youtu.be/XNratwOrSiY?si=dxfD8Y7-wfOi0XcJ
It won't matter for long though. The userbase has had its trust shattered, and this blogpost makes it clear that 4chan has no ability to defend itself from future attacks, which are absolutely coming.
No comments yet
I think it’s moreso that when a normal person enters 4chan they either decide to get out while they still can or stay and become whatever the opposite of a “normie” is.
Wouldn’t say the latter sounds like it would be worth it at all though.
They should, in fact, give up and use the time for literally anything else.