Slashdot Mirror


Pirate Bay Browser Streaming Technology Is a Security and Privacy Nightmare (softpedia.com)

An anonymous reader writes: Last week the Pirate Bay added support for streaming video torrents inside the browser in real-time. Kickass Torrents followed the next week. The technology they used is called Torrents Time. A security researcher has discovered that this technology which is a mix of client and server side code is actually a security and user privacy disaster. Attackers can carry out XSS attacks on TPB and KAT, the app runs on Mac as root, attackers can hijack downloads and force malicious code on the user's PC, and advertisers can collect info on any user that has Torrents Time installed.

11 of 72 comments (clear)

  1. Next on the news... by MitchDev · · Score: 4, Insightful

    MPAA and RIAA releases tainted movies and music on torrents themselves...

    1. Re:Next on the news... by gstoddart · · Score: 4, Informative

      You don't need to hear their name, the US government has now been tasked to do this shit on their behalf, they just write the text of the laws and treaties behind the scenes.

      You don't think ICE policing copyright because they're under the control of DHS was an accident, do you?

      Once the agency with the keys to the kingdom polices copyright, you can be more in the background.

      --
      Lost at C:>. Found at C.
    2. Re:Next on the news... by CeasedCaring · · Score: 3, Funny

      MPAA and RIAA releases tainted movies and music on torrents themselves...

      Didn't they merge to become MAFIAA (Music And Film Industry Associations of America)?

    3. Re:Next on the news... by JustAnotherOldGuy · · Score: 4, Informative

      You don't need to hear their name, the US government has now been tasked to do this shit on their behalf, they just write the text of the laws and treaties behind the scenes.

      This is, sadly, an extremely accurate description of how things work now. The corporations provide "advice" and "policy position consulting" in the form of fully-written bills and treaty amendments, and the law makers just staple them into the binder.

      I'm not kidding in the least, this is literally how it woks these days.

      --
      Just cruising through this digital world at 33 1/3 rpm...
  2. "the app runs on Mac as root" by Anonymous Coward · · Score: 4, Funny

    This isn't a security issue! Modern app appers know that ONLY apps can app other apps, so if you're apping The Pirate App, then only that app can app your apps!

    Apps!

  3. Shady thevies do shady things to computers by naris · · Score: 3

    News at 11!

  4. Re:Active content *is* a priv & sec nightmare by gstoddart · · Score: 3, Insightful

    As long as the dried up lame bed (lake?) has text, we don't give a crap.

    Some of us still prefer to get information in the form of text, and not video ... and animate whirligigs and other crap add nothing to the experience.

    But, really, in terms of not trusting javascript? That really should be common sense by now.

    --
    Lost at C:>. Found at C.
  5. Re:So? by houghi · · Score: 4, Insightful

    Who expects privacy and security when they use Internet ?

    Fixed that for you.

    --
    Don't fight for your country, if your country does not fight for you.
  6. Re:I hope they hack Linux and BSD users by Rik+Sweeney · · Score: 5, Funny

    That's right! One renders your system inoperable, the other is a Windows fatal system error.

    (ducks)

  7. Re:Oh dear balls. by tnk1 · · Score: 5, Insightful

    Even The Pirate Bay itself is quite hacked code.

    Remember that these softwares are made by amateurs who spent their time downloading warez instead of getting proper professional programming education.

    Actually, I doubt that they lack CS education. What they lack is QA. "Good" developers with educations let this sort of shit through all the time. The businesses who make software actually make an effort to test their software for security and functionality.

    The problem with these guys is that coding is sexy, QA is not.

  8. Re:Rome was not build in one day by wonkey_monkey · · Score: 3, Interesting

    Or just have some patience. Bloody kids.

    When I were a lad, it took days to download a 700mb Xvid DVD rip at 640x360 resolution. And we felt blessed.

    A couple of hours to download a 1080p MKV with 5.1 sound? Luxury!

    --
    systemd is Roko's Basilisk.