Live data from Hacker News

Paypal.com appears to be unavailable

paypal.com

61–70 of 128 posts

Re: Paypal.com appears to be unavailable

#61

Earlier quoted context omitted.

Governments take IT security very seriously, I don't see where you've seen they don't. The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.

I would like to clarify on this issue a bit. 1. Declaratively the governments are indeed taking IT security seriously. Thus many guidelines, laws and other formal documents regarding IT security have been accepted. Unfortunately many of these are internally inconsistent or in conflict with others. The net result is that in the name of "security" the governmental IT systems are unnecessarily complicated and expensive.…

Security is hard. Security on a large scale system is is very hard. Securing a legacy system is extremely hard. Securing a large legacy system is near impossible.

Yes the government wants to cover its ass first and foremost.

But that doesn't mean they don't take IT seriously, they just don't understand it to the point they cannot select people to work with that understand it correctly.

disclaimer: I've designed COMSEC systems

Re: Paypal.com appears to be unavailable

#62

I suspect we are going to see two major changes over the next few weeks as a direct result of the "cyber-attacks" going on recently. 1. Financial services will re-evaluate the risks of this kind of attack vs. the cost of assigning more resources to guard against it. 2. Governments will finally start taking IT security seriously. The latter is the more interesting, because while banks are generally reasonably clued up…

On the news here in .nl this morning there was an item on a police search that was carried out at a hosting provider that hosted a web page calling for the DDoS on MasterCard and hosted software (LOIC, presumably).

So yes, it's already happening, and in the coming years the internet is bound to change profoundly.

On a meta level, and for improving my own communication skills, I'm a bit surprised that you are being upvoted while I got downvoted yesterday in the MasterCard thread for saying essentially the same. Anyone who answered me yesterday and disagreed with me care to tell me why? Did I not make my point clearly enough, or was it the form of the message?

Edit: link to previous post: http://news.ycombinator.com/item?id=1983858

Re: Paypal.com appears to be unavailable

#63
post #41

Earlier quoted context omitted.

You don't think that Paypal is also a bully as well? Closing people's accounts (not just Wikileaks) when they see fit, having no real recourse to try and get your money once that's happened etc. Paypal have a reputation for being a bunch of thieves. I can't say I feel bad for them. I've never been burned by them, I'm just going from the amount of people here that post a regular "Paypal froze my account" story.

Well, that's why we have courts to settle disputes in a civil manner.

Don't Paypal's terms of service deny you the right to settle disputes in court?

Re: Paypal.com appears to be unavailable

#64
post #50

Earlier quoted context omitted.

I don't understand your point. If they hadn't disabled Wikileaks' accounts these jobs and people would have suffered how exactly?

If they hadn't disabled Wikileaks accounts there would have just been another topic just as controversial that would have gotten a bug up hacker's asses. This isn't a story about Wikileaks. Wikileaks is just the handy example. This is a story about how small numbers of people can have a temper tantrum and produce a global impact. You can't reason backwards and say "well if they just hadn't done X everything would be…

That's just not true. There has neither been a reaction of this kind for other "bugs up hacker's asses" nor has there been an issue this controversial for a very long time. I can't think of any... perhaps the Morris' worm or Kevin Mitnick.

Re: Paypal.com appears to be unavailable

#65

Earlier quoted context omitted.

I briefly logged onto their IRC channel. It is a total chaos but still they all agree to one target. They have also been hammering www.paypal.com port 443 so I expect this to do down soon too.

What IRC channel are you talking about?

Sh.. you didn't get this from me: irc.anonops.net

Re: Paypal.com appears to be unavailable

#66
post #44

Earlier quoted context omitted.

I'm not saying they aren't but when has the tactic against a bully being to bully them? Regardless of what you think about Paypal themselves, there are an awful lot of people that rely on the service they provide that can now no longer use that service due to the tactics of Anonymous.

Maybe this raises a serious question. Why are so many people (including myself) reliant on one company for handling their payments? Maybe traders should start adding alternative forms of payment to their excepted payments. I know I will.

It's good to accept more than one kind of payment for flexibility, but is the dominance of one payment method really so awful? It always seemed like a natural monopoly to me. It's so closely tied to paper cash... (which you'll remember must be ubiquitous and the only currency to function- except in extreme cases)

Re: Paypal.com appears to be unavailable

#67

I suspect we are going to see two major changes over the next few weeks as a direct result of the "cyber-attacks" going on recently. 1. Financial services will re-evaluate the risks of this kind of attack vs. the cost of assigning more resources to guard against it. 2. Governments will finally start taking IT security seriously. The latter is the more interesting, because while banks are generally reasonably clued up…

Governments take IT security very seriously, I don't see where you've seen they don't. The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.

The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.

Actually, you can never completely defend against every possible attack. Any finite limit can be exceeded. As long as an attacker can use up some sort of finite resource on your box or network, you're toast.

SYN floods don't happen anymore because SYN cookies make the size of your TCP half-open connection table infinitely large. So no DoS anymore. But other things are not that easy to fix; you can prevent 1 IP from opening a million slow connections to your server and filling up your state table and running your web server out of fds. But you can't prevent a million people from all opening up one connection without blocking legitimate users.

DoS is very hard to defend against. I think in this case, there is probably something easy to fix (get rid of those Windows 95-based routers and app servers), but in the general case, there is nothing that can be done.

Re: Paypal.com appears to be unavailable

#68
I really don't think this kind of behaviour helps anything. Though we may disagree with the actions of these corporations, using thousands of ordinary people's computers to flood sites many people use for things that have nothing to do with Julian Assange, Wikileaks or anything whatsoever linked to the cable leaks is simply wrong.

Being immoral in order to expose the immorality of others does nothing but muddy the waters. There are better ways of challenging these things while retaining your decency.

Re: Paypal.com appears to be unavailable

#69

If you dominate a market, a serious ethical duty devolves upon you to do right by your customers, but Paypal, Visa, and MC, on which donation-supported non-profit orgs like Wikileaks almost entirely depend, have utterly failed to fulfill that duty; in fact they didn't even try. Their actions, arbitrary or spineless, have almost completely choked off funding for Wikileaks. I never imagined ending up saying this, but I…

You're ignoring the thousands (hundreds of thousands, millions?) of "innocent" businesses that are having problems because of this. Sure try and hurt Visa, Mastercard and Paypal, but hurting innocent people?

Isn't that exactly what the US government have done? "It's for the greater good". The people involved in these attacks are just as bad.

Re: Paypal.com appears to be unavailable

#70
post #54

What I like most, is that all people click on the link although it says "It's unavailable". Wondering if this has an additional effect on the availability.

Nah, no way. PayPal wouldn't go down from a few 10k additional hits. PayPal is huge, and needs 100% uptime, and in addition to that has undoubtedly prepared for a major DDOS attack. They have unlimited resources, they have expertise, and they've seen it coming. If Anonymous can take PayPal down, then they can take anyone down.

> They have unlimited resources

They don't, if they did you would not be reading this post.

Post reply on HN