‹ BackHN Continuity

Thread

CrowdSec Source Code Leak

160 points · 57 comments · eccgecko

  1. sandeepkd · · focus · HN ↗
    On the funny side, reading the website tagline, apparently they claim to know who is attacking you, they just happen to miss out on who attacked them.

    Turns out they are not really a security company, just an aggregator of bad IPs. Ideally this kind of aggregator problem is best suited for a trusted not-for-profit company where providing the data needs some level of credibility and querying the data costs you nominal fee to keep the setup floating.

    1. strictnein · · focus · HN ↗
      What, exactly, is the definition of a "security company" in your mind? Threat Intel companies definitely fall under that normally, so I'm curious what you think it is.

      Also, the idea that this type of thing could just be stood up as a "not-for-profit" company and ran for peanuts is kind of silly. How would the nominal fee pay for the engineers and infrastructure? Or would this just be a volunteer effort and you'd like people to do this for free for you?

      1. sandeepkd · · focus · HN ↗
        Any company where understanding of security practices has a direct impact on its revenue from early phases can be considered as a security company in my view.

        From what I have seen a large chunk of internet exists and stands on the shoulder of folks who did the volunteer work cause they were passionate about it and enjoyed that part. Once built, the nominal fee for API to check IP address should cover the costs way easily for the servers.

        Letsencrypt is a great example, it did took away the big money from all these commercial CA's, who used to issue blue, green and what not kind of checkmarks. Thats one big reason reason why the migration to HTTPS happened faster.

        1. itintheory · · focus · HN ↗
          The basic software is open source, and the list is free if you're running the tool and contributing detections back. They do have some curated lists that you have to pay for.

          It's quite a bit less expensive than most other commercial products of this kind that I've looked at.

        2. strictnein · · focus · HN ↗
          So I guess your answer is yes, you would like someone to do this work for you for free, because others have done other work for free. And then once the free work is done, you will happily pay a nominal fee to gain the benefit of all the free work?

          > Any company where understanding of security practices has a direct impact on its revenue from early phases can be considered as a security company in my view.

          This could, quite literally, be any company on earth then? But not CrowdSec, because they had a single security issue? Every company on earth has had those, including every security company.

          1. mistrial9 · · focus · HN ↗
            fallacy and apologist point of view here. Shall we dig in?

            fallacy is "Oh I guess you mean" .. insert large unsolvable and probably unpopular derailment. Bonus points for aggressive labeling of the opponent being opposed to money.

            apologist - "Any company on earth" .. We all stand together, Every Company On Earth .. does this warrent serious replies?

            1. strictnein · · focus · HN ↗

              [dead]

          2. sandeepkd · · focus · HN ↗
            There is discussion and then there is argument. Discussion is more about sharing and learning where as argument becomes all about proving a point, specifically individuals targeted point of view.

            My observation is generic and more about state of things rather than focusing on one entity.

            Also lets not belittle the hard work by just labelling it out as free. If only money had been motivation for everyone then the world would have been a different place. And like a lot of people I have done my share of passionate work that provided satisfaction to me and money for others, thats way tangential though

            1. strictnein · · focus · HN ↗
              > My observation is generic and more about state of things

              You are the one who stated a specific company wasn't a security company. When asked to define what one was, your definition included any company on the planet.

              > Also lets not belittle the hard work by just labelling it out as free

              Who is belittling it? My point is that it's hard work and should be rewarded, not expected by someone to be done for them.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.