Live data from Hacker News

Paypal.com appears to be unavailable

paypal.com

81–90 of 128 posts

Re: Paypal.com appears to be unavailable

#81

I suspect we are going to see two major changes over the next few weeks as a direct result of the "cyber-attacks" going on recently. 1. Financial services will re-evaluate the risks of this kind of attack vs. the cost of assigning more resources to guard against it. 2. Governments will finally start taking IT security seriously. The latter is the more interesting, because while banks are generally reasonably clued up…

Governments take IT security very seriously, I don't see where you've seen they don't. The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.

That has been the opposite of my experience. To a large extent, the government can't take IT security seriously, because they've outsourced it. There are smart people in and around the government but no coherent strategy. I don't want to get too specific but no DoD network I've seen or talked to people who ran ranks with the least of my financial services clients.

Re: Paypal.com appears to be unavailable

#82

Earlier quoted context omitted.

>If you dominate a market, a serious ethical duty devolves upon you to do right by your customers, but Paypal, Visa, and MC, on which donation-supported non-profit orgs like Wikileaks almost entirely depend, have utterly failed to fulfill that duty; in fact they didn't even try. The majority of Paypal Visa and Mastercard customers rely to some extent on a stable international environment. Suggesting that these compan…

I think you've watched 'Fight Club' too many times.

I've seen it, perhaps if I saw it again I'd have clue what you're on about?

Re: Paypal.com appears to be unavailable

#83

Earlier quoted context omitted.

I would like to clarify on this issue a bit. 1. Declaratively the governments are indeed taking IT security seriously. Thus many guidelines, laws and other formal documents regarding IT security have been accepted. Unfortunately many of these are internally inconsistent or in conflict with others. The net result is that in the name of "security" the governmental IT systems are unnecessarily complicated and expensive.…

Security is hard. Security on a large scale system is is very hard. Securing a legacy system is extremely hard. Securing a large legacy system is near impossible. Yes the government wants to cover its ass first and foremost. But that doesn't mean they don't take IT seriously, they just don't understand it to the point they cannot select people to work with that understand it correctly. disclaimer: I've designed COMSE…

If they took IT security seriously, it wouldn't be a checkbox in a Lockheed or SAIC contract.

Re: Paypal.com appears to be unavailable

#84
post #74

Earlier quoted context omitted.

This is not true. I work for a major DDoS mitigation equipment company and we see SYN floods all the time. And you CAN block one million users from all opening up one connection. Our software/hardware makes this happen. There are MANY MANY ways that DDoS can be dealt with; the biggest hurdle in many cases is convincing a customer that they might be next. Until then, they often don't see the need to spend the money on…

Yeah, it's hard to speculate as to what's going on, because we are not Paypal or Mastercard. Maybe someone from Anonymous works there and changed their uplink media to 10BaseT :) So about the SYN floods you see in real life, how do those work? Do routers not do SYN proxying for the servers behind them? Do SYN cookies not work? Are sequence numbers being forged? Is the link saturated? Something else?

Routers don't do SYN proxying. SYNs are just regular packets and are passed along to a host.

FIREWALLs on the other hand, might use a SYN to make an entry in a table that's used to track connection state. That table might be overloaded by a SYN flood. Same thing applies to load balancers.

SYN cookies work just fine at the ENDPOINTs.

Re: Paypal.com appears to be unavailable

#85
post #74

Earlier quoted context omitted.

The problem is that you just can't secure a whole infrastructure overnight and that security is very hard. Actually, you can never completely defend against every possible attack. Any finite limit can be exceeded. As long as an attacker can use up some sort of finite resource on your box or network, you're toast. SYN floods don't happen anymore because SYN cookies make the size of your TCP half-open connection table…

This is not true. I work for a major DDoS mitigation equipment company and we see SYN floods all the time. And you CAN block one million users from all opening up one connection. Our software/hardware makes this happen. There are MANY MANY ways that DDoS can be dealt with; the biggest hurdle in many cases is convincing a customer that they might be next. Until then, they often don't see the need to spend the money on…

Well, I worked for Arbor, and while it's true that you can readily block packet-y attacks even from a million sources (as long as you can characterize the attack), you're kind of missing 'jrockway's point.

During the Olympics in Korea, which Arbor ran DDoS protection for, attackers set up web pages that simply directed hundreds of thousands of computers at URLs on the MSNBC sites. How are you going to filter against that? If you have a botnet, you can saturate a target with totally legitimate traffic.

You can talk all you want about anomaly detection and attack characterization, but if your attacker has a botnet that generates totally legitimate traffic patterns, you have a very hard problem to solve. It isn't intractable, but probably will require code changes to your application to address.

A lot of anti-DDoS gear that gets sold to enterprises is snake oil. Most companies aren't in a position to filter their own traffic.

Re: Paypal.com appears to be unavailable

#86

Earlier quoted context omitted.

You're ignoring the thousands (hundreds of thousands, millions?) of "innocent" businesses that are having problems because of this. Sure try and hurt Visa, Mastercard and Paypal, but hurting innocent people? Isn't that exactly what the US government have done? "It's for the greater good". The people involved in these attacks are just as bad.

I'm going to preface this by saying that I'm not actually a huge fan of WikiLeaks or of Anon, but... Try to keep things in perspective. We're facing a substantial progression towards a hybridization of the scenarios outlined in 1984 and Brave New World, and you're worried about the disruption of commerce? Are your priorities really that warped? There's always collateral damage, whether it's merchants or your civil ri…

I'm sorry, but do you honestly think this is anymore than a bunch of angry teenagers who will be bored in a week? Look back on every other instance of "Anon" "protesting" and work out what has changed. Please do show what they've actually done beyond cause minor temporary disruption, it just so happens that this time the minor disruption has real world repercussions and is hurting businesses. The people who are responsible for this are those in US government, I think it's pathetic companies like Visa, Paypal and Mastercard are being attacked when they've done nothing wrong, it's the US government at fault but they're "untouchable" to these angsty teenagers so they do the thing they always do and attack the weakest targets.

Give it a week and nobody will remember any of this, besides the businesses that lost money.

Re: Paypal.com appears to be unavailable

#87
post #75
post #71

I'm morally indifferent, even in favour of the principle of wikileaks. I'm not in favour of a leaker of US information motivated only by wanting reforms that are pipe dreams. Freedom of speech can never extend to state secrets. In Europe, we'd never be so attached to the idea that we'd take it that far. I think we may have sacrificed a lot - eg. the ability of the net to process pre-Christmas payments, for the "gain"…

It doesn't sound like you are in favour of the principle of WikiLeaks.

It should continue to exist, in case someone does have something worthwhile to release. But in this case it was hardly worth it. Except for the secret sites, that WAS irresponsible. The acceptable principle of the site does not exempt its operators from the law of developed countries, and will obviously subject them to the lawlessness of undeveloped ones.

Now they're threatening to take down twitter (who don't need any help in doing that!) because they are percieved to be preventing 'wikileaks' from trending. Looks increasingly like a load of kids with a ddos hammer seeing enticing nails everywhere.

Re: Paypal.com appears to be unavailable

#89

Earlier quoted context omitted.

I'm going to preface this by saying that I'm not actually a huge fan of WikiLeaks or of Anon, but... Try to keep things in perspective. We're facing a substantial progression towards a hybridization of the scenarios outlined in 1984 and Brave New World, and you're worried about the disruption of commerce? Are your priorities really that warped? There's always collateral damage, whether it's merchants or your civil ri…

I'm sorry, but do you honestly think this is anymore than a bunch of angry teenagers who will be bored in a week? Look back on every other instance of "Anon" "protesting" and work out what has changed. Please do show what they've actually done beyond cause minor temporary disruption, it just so happens that this time the minor disruption has real world repercussions and is hurting businesses. The people who are respo…

>Give it a week and nobody will remember any of this

That's the tragedy not

>besides the businesses that lost money.

Nobody cares about citizenship or rights anymore. Just money.

Re: Paypal.com appears to be unavailable

#90
post #58

I suspect we are going to see two major changes over the next few weeks as a direct result of the "cyber-attacks" going on recently. 1. Financial services will re-evaluate the risks of this kind of attack vs. the cost of assigning more resources to guard against it. 2. Governments will finally start taking IT security seriously. The latter is the more interesting, because while banks are generally reasonably clued up…

I won't hold my breath, though; this could all end in tears, with a mess of ill-informed and poorly-implemented measures that cause all kinds of additional dangers to innocent people without actually fixing the real problem. If I were a betting man, I'd say we'll see many years of ill-informed and badly implemented draconian policy. I'd go further to say that it won't improve significantly until at least a couple mor…

There's an inherent assumption in this though that 'digital natives' will survive the process for long enough to get themselves elected though. We all routinely filter out all sorts of little oddities about life because they're 'just the way it's always been', 'it has to be this way for safety' or whatever.

If that generation has enough of these views hard-wired into their understanding, _now_ could be the high-water mark for understanding of the dangers and appropriate reactions.

Post reply on HN