frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

6Sense's Privacy Policy Page loads scripts from polyfill(.)io

1•SignalDr•50m ago
We have completed a forensic investigation into a major B2B marketing vendor's (TrenDemon, linked to 6sense) production SDK and uncovered a systematic vulnerability that impacts thousands of customer sites. We are categorizing this as the Adversarial GTM Architecture.

The system is designed to defeat privacy audits and achieve permanent user tracking.

1. The Core Vulnerability: Remote Code Execution (RCE) Framework The vendor's primary script is not an analytics tool; it is a Remote Code Execution as a Service (RCEaaS) framework.

Mechanism: The SDK uses a proprietary constructor ($TRD\_GenericScriptComponent) to execute arbitrary code delivered from the vendor’s API via dynamic calls to eval() and innerHTML

Vector: This RCE capability is deployed as a "tripwire" that triggers at the moment of highest user engagement (e.g., video completion or form submit).

Result: The vendor can change the functionality of their clients' sites (e.g., deploying new tracking scripts, keyloggers) on the fly without updating the main script file.

2. The Persistence and Evasion Layer This architecture relies on active, high-level evasion to prevent security observation:

Permanent Tracking (The 8,000-Year Cookie): The system sets cookies with an expiration date of December 31, 9999, a clear violation of GDPR's Storage Limitation Principle and evidence of intent for permanent identity persistence.

Audit Evasion Logic: The production code contains detection logic that specifically targets the regex patterns of compliance and legal discovery tools (monitor|checker|validator|analyzer), causing the script to change its behavior when audited.

Supply Chain Risk (PollyWannaCrack): The execution engine relies on loading scripts from polyfill.io, which is a publicly known, compromised CDN.

3. The Payload (Identity Brokering) The primary function of the RCE is to facilitate identity theft:

Cross-Vendor Theft: The system actively encodes and exfiltrates authentication-grade cookies from secondary vendors, specifically the Marketo cookie (maCook), providing TrenDemon with the key to the user's entire marketing identity.

Surveillance Network: The RCE framework is used to dynamically inject and orchestrate a payload array of other surveillance tools (RB2B, LiveIntent, Apollo, etc.) into the host page.

We believe this architecture represents a structural failure in GTM security, demonstrating that the pursuit of attribution has led to the deployment of hostile, RCE-capable code designed for unobservability. We have developed and deployed patches to mitigate this threat.

We encourage security researchers and auditors to independently verify the presence of the $TRD\_GenericScriptComponent and the audit evasion logic within the vendor's production code.

https://www.deployblackout.com/investigations/6sense

Zimbabwe's forest and energy projects reveal the downside of carbon credits

https://theconversation.com/zimbabwes-forest-and-energy-projects-reveal-the-downside-of-carbon-cr...
1•PaulHoule•1m ago•0 comments

The Sights and Sounds of Bhutan

https://waitbutwhy.com/2025/11/bhutan.html
1•gmays•2m ago•0 comments

The Constraints That Create Autonomy

https://www.davidpoll.com/2025/12/constraints-create-autonomy/
1•depoll•3m ago•0 comments

Show HN: Sigma Runtime ERI (v0.1) – Open benchmark for attractor-based LLMs

https://github.com/sigmastratum/documentation/blob/main/runtime/benchmarks/README.md
1•teugent•4m ago•0 comments

Ehtml

https://e-html.org/
1•edtech_dev•6m ago•0 comments

Feeling Old: 44 Is the First Big Aging Cliff for Millennials

https://www.thecut.com/article/middle-aged-millennials-feeling-old-44-aging-cliff.html
2•ryan_j_naughton•8m ago•1 comments

Linguistic Sightseeing: The Germanic Languages, Part I

https://collisteru.substack.com/p/linguistic-sightseeing-the-germanic
1•surprisetalk•9m ago•0 comments

Workplace hierarchies are gravity wells

https://notleo.com/workplace-hierarchies-are-gravity-wells/
1•ja2•9m ago•0 comments

One-Third of US Families Earn over $150k

https://marginalrevolution.com/marginalrevolution/2025/11/one-third-of-us-families-earn-over-1500...
2•surprisetalk•9m ago•0 comments

Talent sorting in Germany is flawed

https://simongrimm.substack.com/p/medical-school-is-a-bad-choice-for
1•surprisetalk•9m ago•1 comments

TrueMeter: AI Energy Agent That Optimizes Utility Bills

https://truemeter.com/blog/truemeter-ai-energy-agent-that-optimizes-utility-bills
8•oateco•10m ago•0 comments

Creating AI Ready Data

https://sdcstudio.axius-sdc.com/
1•twcook•10m ago•0 comments

Multivox: Volumetric Display

https://github.com/AncientJames/multivox
2•jk_tech•10m ago•0 comments

Corn's clean-energy promise is clashing with its climate footprint

https://floodlightnews.org/corn-ethanol-clean-energy-vs-climate-costs/
2•coloneltcb•11m ago•0 comments

47 Days to Demo. 47 GameDev Lessons Learned

https://themakerway.com/devblog/2025/12/03/47-lessons-learned.html
1•uzish•11m ago•0 comments

Fog of War

https://en.wikipedia.org/wiki/Fog_of_war
1•rolph•12m ago•0 comments

Anthropic Interviewer: What 1,250 professionals told us about working with AI

https://www.anthropic.com/research/anthropic-interviewer
1•meetpateltech•12m ago•0 comments

Ask HN: Anyone here self-hosting databases and needing advanced features?

1•SirusCodes•13m ago•0 comments

Show HN: Giftl – A simple, free gift registry

https://www.gif.tl/
1•frustracean•14m ago•0 comments

Beyond the dollar: Helping newsrooms reach sustainability

https://www.pressforward.news/beyond-the-dollar-helping-newsrooms-reach-sustainability/
1•mooreds•15m ago•0 comments

The End of the Train-Test Split

https://folio.benguzovsky.com/train-test
2•gmays•15m ago•0 comments

Launch HN: Browser Buddy (YC W24) – A recommendation system for Internet writing

https://www.browserbuddy.com/
3•alien0006•16m ago•0 comments

Firecrawl getting blocked due to headlesness

1•maclarens•17m ago•0 comments

Managing a Windfall

https://www.bogleheads.org/wiki/Managing_a_windfall
1•mooreds•18m ago•0 comments

Released After 27 Years on Death Row Due to Now-Disgraced Bite Mark Testimony

https://www.forensicmag.com/3594-All-News/623083-Man-Released-After-27-Years-on-Death-Row-Due-to-...
2•WaitWaitWha•18m ago•0 comments

Steve Cropper, legendary guitarist for Booker T and the MGs, dies aged 84

https://www.theguardian.com/music/2025/dec/03/steve-cropper-death
4•bookofjoe•20m ago•0 comments

KiTTY Terminal Graphics Protocol

https://sw.kovidgoyal.net/kitty/graphics-protocol/
2•peter_d_sherman•21m ago•0 comments

Migration and the Persistence of Violence

https://www.pnas.org/doi/10.1073/pnas.2500535122
2•bikenaga•21m ago•1 comments

Show HN: CSVtoAny, CSV Local File Converter

https://csvtoany.com/
3•nighwatch•23m ago•0 comments

AWS Developer Experience State of the Nation with Ali Spittel

https://redmonk.com/videos/aws-developer-experience-state-of-the-nation-with-ali-spittel/
1•mooreds•25m ago•0 comments