Hacker News
new
|
past
|
comments
|
ask
|
show
|
jobs
|
submit
login
unkeen
on Jan 13, 2025
|
parent
|
context
|
favorite
| on:
Disco Elysium Explorer
What would make it more secure if it were a domain that gets resolved to an IP address?
TomasEkeli
on Jan 13, 2025
[–]
giving it a domain-name and serving with https encryption on it would improve all kinds of security.
then again, it feels wonderfully apt that it is on some random ip
Etheryte
on Jan 13, 2025
|
parent
[–]
Security of what? You're not inputting any data of your own into the site.
sedatk
on Jan 13, 2025
|
root
|
parent
[–]
Hypothetically speaking, you can still be MitM'ed.
Etheryte
on Jan 13, 2025
|
root
|
parent
[–]
And then what, serve me fake Disco Elysium dialogs? What's the threat model?
sedatk
on Jan 13, 2025
|
root
|
parent
[–]
Either pick one of the recent JavaScript sandbox escape CVEs on a vulnerable browser, or redirect to your phishing page as to your liking. Again, hypothetical and very unlikely, but the risks are there.
Etheryte
on Jan 14, 2025
|
root
|
parent
[–]
They could do all of this without mitming by just making a submission on HN. The extra step doesn't add anything.
sedatk
on Jan 14, 2025
|
root
|
parent
[–]
Then why don't they, do you think?
valicord
on Jan 14, 2025
|
root
|
parent
[–]
Because it's a made up threat that only exists in your imagination?
Guidelines
|
FAQ
|
Lists
|
API
|
Security
|
Legal
|
Apply to YC
|
Contact
Search: