Polymarket's Rush to Grow Left a Door Wide Open for Fraudsters
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
A 72-hour external packet-capture experiment recorded every wireless packet from factory Google Pixel 8 phones left idle and plugged in behind an enterprise pfSense firewall running Wireshark. The phones were isolated on a private WPA3-Enterprise Wi‑Fi network with no other clients; an independent hardware wiretap ensured operating-system traffic could not be hidden by on-device monitoring. The complete raw CSV (timestamps, device build, destination domains and IPs, ASN 15169, ports, and payload sizes) is published under CC BY 4.0 for reanalysis.
The measurement shows stock Android phones never truly idle: an average of 348.4 outbound requests per hour (≈8,920 daily), with the top background leaks being Wi‑Fi BSSID uploads (84.2 req/hr), hardware and SIM fingerprint hashes (48.0 req/hr), Google Cloud Messaging heartbeats (14.8 req/hr), Google Photos sync tokens (28.5 req/hr), and search-widget prefetches (22.1 req/hr). Per-service breakdown lists Google Play Services (~142.6 req/hr, 7.8 MB/day), Location/Maps (~84.2 req/hr, 4.2 MB/day), Device Provisioning (~48/hr, 2.4 MB/day), Photos (~28.5/hr, 1.9 MB/day), and others. Replacing OS and Google services (e.g., GrapheneOS) or blocking known Google endpoints via Pi‑Hole/AdGuard/NextDNS dramatically reduces or eliminates these background connections.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.
Polymarket's rapid expansion has created vulnerabilities that fraudsters could exploit. Regulators have raised concerns about the platform's security and oversight practices. (wsj.com)
Windows product activation used a secret binary blob called 'Microsoft Bob' in volume licensing media to prevent unauthorized use. This key and media combination leaked early in 2001, leading to piracy and subsequent blacklisting by Microsoft. (twitter.com)
RSA-896, a challenge number, was factored on September 19, 2026, by Stephen A. Weis using Claude. The factorization reveals the prime factors p and q of the 896-bit RSA modulus. (saweis.net)
Twenty-five years after a proposed national ID system was rejected, the US has quietly moved toward a digital identity platform called Login.gov, which consolidates personal data without public debate. This system could eventually enable broad surveillance and access control across institutions without explicit legislation or public approval. (thedreydossier.substack.com)
Hugging Face experienced a security breach, but the impact was less severe than initially reported. The company clarified that the hack did not compromise sensitive data or major systems. (wsj.com)
Congress is investigating the diversion of F-35 aircraft parts to Hong Kong. The incident has raised concerns about potential security breaches involving military equipment. (politico.com)
Today's best Hacker News stories, summarized and screenshotted, one email a day.