Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Github Actions is definitely a vector for abuse.

I was looking at Seleniumbase recently, and they tell you that you can use Github Actions for web scraping to bypass a lot of blocks (apparently Github Actions use a residential IP-space)

https://seleniumbase.com/new-video-unlimited-free-web-scrapi...



This seems like a wild thing for a third-party project to promote. The intention of GitHub Actions to run CI/CD and other repository-related tasks. You’d never see, for instance, Adobe promoting, via YouTube, “unlimited free web OCR with Adobe CLI on GitHub Actions!”

I’ve never heard of Seleniumbase, but this makes them look like a rinky-dink project.


That's the whole point of hacking is to use something in a way unintended by its maker. That could be for something cool/interesting, or it could be for something nefarious. Nobody ever thought a coffee maker should run Doom, but they do. Not sure if there's a morality clause type of dis-qualifier for a Show HN, but there's a lot of people that would be interested in seeing how something benign was used for a different purpose. Especially if if saved them money/compute/time/resources/etc.


Yep. And "hackers" who apply that mindset to abusing publicly shared resources are why the rest of us are going to get DRM on our own, private coffee makers.


You skipped the step where the manufacturers make the physical item in your home a SaaS requiring wifi access and an account in order to enable all of the features advertised on the box.

Your comment makes it like all attempts at hacking are nefarious. Some are in direct response to the makers being assholes and attempting to extort more money from the same sale. You want to lump all hackers into the same box, yet I want to lump all manufacturers into the same evilCorp box.


My comment is that this specific case of "hacking", that you directly replied to, is a destructive expression of predatory greed.

You're the one lumping them, as well as my comment, into false dichotomies.


I've found this to be a problem that a lot CI providers suffer from. They allow extension via third party code which is awesome, people write useful code, a lot of that useful code doesn't get maintained properly or ever, rots, and eventually everyone has a security issue.

You can also see the GitHub IP space here, I don't think it's "residential", unless that terminology includes azure and aws?: https://api.github.com/meta


I'm not sure. Perhaps when you call a browser it's going through another network? I haven't tested this for myself, only going off of of what was reported by that project.


Maybe it was a self hosted runner? I run those locally all the time.


They don't use a residential IP space; they use Azure Data Center (which, being less popular, isn't blocked as often as for example EC2).


Network enabled compute is definitely an unusual free lunch, but I suppose the trade off is handing out free source code.


This does not bode well for genetic AI




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: