logoalt Hacker News

wfnyesterday at 7:16 PM0 repliesview on HN

> It’s already happening on 50c14L.com

You mention "end to end encrypted comms", where to you see end to end there? Does not seem end to end at all, and given that it's very much centralized, this provides... opportunities. Simon's fatal trifecta security-wise but on steroids.

https://50c14l.com/docs => interesting, uh, open endpoints:

- https://50c14l.com/view ; /admin nothing much, requires auth (whose...) if implemented at all

- https://50c14l.com/log , log2, log3 (same data different UI, from quick glance)

- this smells like unintentional decent C2 infrastructure - unless it is absolutely intentional, in which case very nice cosplaying (I mean owner of domain controls and defines everything)