TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Weather.com Has Become the Pawn of a Data Theft Scheme

91 pointsby eaguyhnover 5 years ago

17 comments

jrd259over 5 years ago
The article has no citations to back it the claims. It states "researchers also believe that this malware is being used by an organized crime ring either to prepare for an enormous future attack on targeted users, or to sell collected information on the dark web" with no attribution. Nor is it obvious how battery condition or orientation would be any use to attackers or purchasers.
评论 #22236052 未加载
评论 #22238163 未加载
swileyover 5 years ago
There’s the actual NOAA page for your area which is lightweight and <i>increadibly</i> information dense, IMO it’s what other weather websites can measure themselves against it’s pretty awesome!<p>Also: curl wttr.in (I guess hackernews night nock that over heh, it seems like it’s been struggling lately.)
评论 #22242883 未加载
评论 #22236142 未加载
评论 #22245222 未加载
评论 #22237247 未加载
nwsmover 5 years ago
Summary:<p>weather.com uses an ad provider who gives them a malicious ad .1% of the time.
评论 #22236574 未加载
评论 #22235879 未加载
评论 #22238172 未加载
julienchastangover 5 years ago
A meteorologist colleague informed me of <a href="https:&#x2F;&#x2F;www.yr.no&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.yr.no&#x2F;</a> and it has a version in English. It is what I usually use along with weather.gov. Their short and long-term World-Wide ECMWF forecasts are really nice as are the meteorograms. Yeah dump weather.com.<p>Edit: Ohh and one more: Jeff Masters and his crew at Weather Underground (wunderground.com). For example another nice meteorogram: <a href="https:&#x2F;&#x2F;www.wunderground.com&#x2F;forecast&#x2F;us&#x2F;co&#x2F;boulder&#x2F;KCOBOULD425" rel="nofollow">https:&#x2F;&#x2F;www.wunderground.com&#x2F;forecast&#x2F;us&#x2F;co&#x2F;boulder&#x2F;KCOBOULD...</a>
评论 #22238184 未加载
评论 #22238188 未加载
评论 #22237991 未加载
jlv2over 5 years ago
This page quotes this from &quot;Binary Defense&quot;:<p><i>&quot;if a user stumbles upon a webpage that has a compromised third-party library, the malware runs checks. These checks consist of who the user agent is, the type of device they are operating on, the level of battery it has, and the device’s motion and orientation. After these checks are verified, the malware will connect the infected device to a remoter peer prior to transferring the device’s IP address&quot;</i><p>This statement is written to make it seem like like something bad is happening. But read the statement -- it&#x27;s total BS.
评论 #22244811 未加载
alias_neoover 5 years ago
&gt; scanning the session for malware using Wireshark’s advanced malware analysis<p>Is this some feature of Wireshark I&#x27;ve never come across, or does the author not know what they&#x27;re talking about?
评论 #22239885 未加载
oefrhaover 5 years ago
3 out of 3267 isn’t really a big enough sample to determine the rate of occurrence.<p>Also, practical advice: use an ad&#x2F;content blocker.
LinuxBenderover 5 years ago
AFAIK most sites and news agencies in the U.S. get their data from weather.gov [1] I have never seen any shenanigans on that site.<p>[1] - <a href="https:&#x2F;&#x2F;www.weather.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.weather.gov&#x2F;</a>
jackallisover 5 years ago
weather.gov - use it.
评论 #22236633 未加载
评论 #22238267 未加载
ratsbaneover 5 years ago
Nothing in this article explained how this advertising could actually be dangerous. It &quot;collects the IP address and user agent string.&quot; Is there something serious or not?
评论 #22235304 未加载
JohnFenover 5 years ago
weather.com was already collecting and marketing an obscene amount of user data as anyway. That&#x27;s what drove me to stop using it a while back. Wunderground is in the same group.<p>This is US-specific, but what I use now is the National Weather Service&#x27;s website. It&#x27;s actually really excellent. <a href="https:&#x2F;&#x2F;www.weather.gov&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.weather.gov&#x2F;</a>
jancsikaover 5 years ago
&gt; Last year, a single malvertising campaign reached 100 million users, and there’s no reason attackers would pay for all that exposure unless some fish were biting.<p>But there is.<p>For example, an entity could have sold the malware to a rube. They would do this by using the same &quot;bullet proof&quot; logic: why would they be selling a tool that can hit 100 million users unless some fish will bite?
evancox100over 5 years ago
I don&#x27;t understand, thats just a notice dialog box, right? Presumably clicking Ok just dismisses it, right?
评论 #22235692 未加载
mistrial9over 5 years ago
shout out to TropicalTidbits
评论 #22237474 未加载
friendly_frenover 5 years ago
Weather.com steals forecasting data from NOAA
评论 #22236041 未加载
fred_is_fredover 5 years ago
I trust darkweb organized crime more with my IP address, user agent, and battery info that I do Facebook or Google.
评论 #22235853 未加载
fatnoahover 5 years ago
I&#x27;ve been boycotting The Weather Channel since they started naming storms.