Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's not a "hacking attack", it's an element on a website:

    <iframe src=http://bylock.net width=1 height=1>
or

    <img src=“http://bylock.net” width=1 height=1>
This code, if it was a part of a page you browse, would cause your browser to load the linked site, almost exactly like clicking on this link: http://bylock.net. This iframe was present in various websites and apps.

The nefarious component of the attack is that the Turkish government surveils all Internet traffic within its borders and thought that the website may have helped some of its opponents commit what it believes to be treason. Its surveillance data tells it all the sites your phone looks up, and it accused people whose phones looked up that domain as being guilty of treason.



Just replied to someone else: I was wondering if the pixel is just a relatively innocuous advertising pixels. Advertisers/publishers place random pixels from vendors/etc on their website all the time and rarely vet anything. I wouldn't be surprised is bylock was advertising in those apps and asked each app to place a pixel to track conversions/clicks/etc.


Thank you for your response. Why would the other apps put this line of code? Are they hand-in-hand with Bylock?


Check out soared's comment above. Basically, 1-pixel images like these are used by companies to track when someone views their content. It's a very common practice - most of your emails probably contain tracking pixels so that whoever sent them can tell if you viewed the email. If they see a request on their server for the URL they put in the tracking pixel, they know you've opened the email.

In Bylock's case, it was most likely a tracking pixel embedded in advertisements for Bylock that the other apps were displaying. The pixel helped Bylock track how many people were viewing their ads.


Thank you, soared and jdormit!




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: