https://www.paypal.com/ still works, all they're doing is hammering the front page, any transactions over SSL should still work fine.
I briefly logged onto their IRC channel. It is a total chaos but still they all agree to one target. They have also been hammering www.paypal.com port 443 so I expect this to do down soon too.
Paypal.com appears to be unavailable
101–110 of 128 posts
Re: Paypal.com appears to be unavailable
#102Re: Paypal.com appears to be unavailable
#103Earlier quoted context omitted.
This is not true. I work for a major DDoS mitigation equipment company and we see SYN floods all the time. And you CAN block one million users from all opening up one connection. Our software/hardware makes this happen. There are MANY MANY ways that DDoS can be dealt with; the biggest hurdle in many cases is convincing a customer that they might be next. Until then, they often don't see the need to spend the money on…
Well, I worked for Arbor, and while it's true that you can readily block packet-y attacks even from a million sources (as long as you can characterize the attack), you're kind of missing 'jrockway's point. During the Olympics in Korea, which Arbor ran DDoS protection for, attackers set up web pages that simply directed hundreds of thousands of computers at URLs on the MSNBC sites. How are you going to filter against…
The problem of distinguishing between legitimate traffic and attack traffic gets harder when the attack starts to look more like legitimate traffic. It doesn't get impossible.
You can have a more effective attack if you have a LOT of machines you can use to generate legitimate requests. Of course, after a short while, it's going to be possible to determine which of those hosts are part of the botnet because you can build a history of their requests over time.
So it's not an impossible problem to solve; just a hard one. Most enterprises don't really want to pay the money necessary to protect the bulk of their enterprises.
I don't think I missed jrockway's point, but I do think you're missing mine: namely, that effective DDoS protection is expensive and time-consuming from a training standpoint relative to any individual company's exposure. That's why we don't see more anti-DDoS features in high-profile websites, not because it's ineffective.
Even so...we STILL see lots of packet-y type attacks. It's often overlooked but crafting effective attacks requires really good programming skills. Such skills are often unevenly distributed in script-kiddie kommunities.
Re: Paypal.com appears to be unavailable
#104https://www.paypal.com/ still works, all they're doing is hammering the front page, any transactions over SSL should still work fine.
I briefly logged onto their IRC channel. It is a total chaos but still they all agree to one target. They have also been hammering www.paypal.com port 443 so I expect this to do down soon too.
Re: Paypal.com appears to be unavailable
#105Paypal is notorious to freeze accounts as they like, and bully people around. They can do this because they know they are big. Now they are starting to force their own political agendas on the world population as well. I've quit my account with them because I want this world to be a better place to live in, than being controlled by a bully who harass people.
Great. How do I close account with Anon, because I don't want them to infringe on my ability to make payments?
Many people -- WikiLeaks, in fact -- are protesting US action in Iraq. They are particularly upset about the "collateral damage" of civilians being caught up in the violence.
Yet here, those cheering for the DDoS attacks in support of WikiLeaks are just shrugging off the collateral damage that this attack is causing.
Addendum: the quick, reflex downvotes are really annoying. If you think I'm not contributing to the discussion, please at least take the time to explain why. It seems to me that there's a patter for these. I lose a few points immediately, but then as more thoughtful people actually take the time to think about it, the score climbs back up into positive territory. That suggests to me that the down-votes are just readers being petulant because I disagree with them.
Re: Paypal.com appears to be unavailable
#106What amount, if any, preparation can guard against a cyber mob-rule attack? It seems that unless a machine is unplugged from the network, you're up shit creek without a paddle.
Re: Paypal.com appears to be unavailable
#107Earlier quoted context omitted.
You know, I am really glad that you're not at all concerned about the invisible hand which seems to synchronize actions across governments, Visa, MC, PayPal, Amazon, and other major businesses. All in the name of shutting down free speech. Wikileaks has not been charged with any crime anywhere in the world, let alone been found guilty. So why is it the US government is after them like the villain in a bad James Bond…
Wikileaks has not been charged with any crime anywhere in the world, let alone been found guilty. At a very minimum wikileaks is distributing copyrighted information without authorization. Technically they can be taken completely down via the DMCA. Ultimately of course PayPal, Amazon, Mastercard and others don't want to do business with Wikileaks, or anon, or any similar "fuzzy" business. The business doesn't have to…
Re: Paypal.com appears to be unavailable
#108If you dominate a market, a serious ethical duty devolves upon you to do right by your customers, but Paypal, Visa, and MC, on which donation-supported non-profit orgs like Wikileaks almost entirely depend, have utterly failed to fulfill that duty; in fact they didn't even try. Their actions, arbitrary or spineless, have almost completely choked off funding for Wikileaks. I never imagined ending up saying this, but I…
>If you dominate a market, a serious ethical duty devolves upon you to do right by your customers, but Paypal, Visa, and MC, on which donation-supported non-profit orgs like Wikileaks almost entirely depend, have utterly failed to fulfill that duty; in fact they didn't even try. The majority of Paypal Visa and Mastercard customers rely to some extent on a stable international environment. Suggesting that these compan…
> Wikileaks actions suggest they want to take down the establishment that
> in a large part enables such companies to operate.
How so? If my government is doing illegal things, or just things that I don't agree with behind closed doors, should I just accept that there's nothing that I can do to change that? Should these things be ignored because to bring these things to light would 'de-stabilize the international environment' and cause hardships to businesses?I'm also curious as to how the release of these cables is going to 'take down the establishment.' Do you fear that the US government will crumble, sending America into a period of anarchy all due to WikiLeaks? If not, then do you think that any reasonably intelligent person would believe that that would happen? Do you classify Wikileaks as 'not reasonably intelligent?' If not, then why?
> Indeed the fact that these companies have now been attacked by the associates of
> those they chose not to support means that they made the right decision.
For starters, Anonymous could be best described as a 'Stand Alone Complex' as has been pointed out here and on Reddit a couple of times. It's a loosely coupled group of people that is ever changing as people join/depart from it based on whether they 'believe in the cause' or 'get bored' or whatever. Censorship on the web by 'the establishment' really gets Anonymous riled up (see Scientology trying to get the Tom Cruise video pulled from the web). To say that Anonymous is an 'associate' of Wikileaks is about as close to the truth as saying that Osama Bin Laden is an 'associate' of the American public just because they share the believe that the US Army should not be in Iraq.That point aside, these companies chose to drop support for Wikileaks because they associated 'dropping Wikileaks' with 'zero risk' and 'keeping Wikileaks' with 'high risk.' That risk-assessment is no longer valid due to these attacks. Whether 'dropping Wikileaks' is still lower risk than keeping them is debatable, but it is no longer 'zero risk.' There are companies that only understand financial incentives. If you want them to pay attention to you, you need to affect their bottom line. What I gather from you post is that when a company becomes a pillar of commerce like these credit card processors have, then we can no longer morally affect their bottom line due to the effects that will have on other businesses. The problem with these belief is that you are effectively stating that these companies are 'untouchable' and a stone's throw away from 'too big to fail.'
> Why would they want to bolster groups that will turn and attack them?
Not that DDoS is necessarily the way to go, but I doubt that there would be any other way to get credit card companies to even give you the time of day once they have deemed that you are 'useless' to them. Do you have an alternate method of making the credit card companies stand up and listen to you once they've decided that you are to be ignored? > Taking a capitalist view basically Wikileaks supports believe that the rest
> of us should be screwed over so they can make their point. It's not civilised
> it's brutish anarchism.
No offense, but human civilization/society is a huge object that has a large amount of momentum and doesn't turn on a dime. This is why most large changes come with a lot of violence and disruption.Using your logic, Rosa Parks was a brutish anarchist because she believed that 'white people' should be 'screwed over' and prevented from having a seat at the front of the bus in order for her to make her point. The best course of action would be to disrupt no one. Maybe if Rosa Parks had just lodged a written complaint with the local board of commerce, white racists would have non-violently accepted that black people are their equals?
Re: Paypal.com appears to be unavailable
#109I wonder if Amazon is next?
Amazon is too big to be taken down. It will require much more infrastructure than paypal.com
Re: Paypal.com appears to be unavailable
#110Earlier quoted context omitted.
Great. How do I close account with Anon, because I don't want them to infringe on my ability to make payments?
You've made me realize what I think is a startling bit of irony. Many people -- WikiLeaks, in fact -- are protesting US action in Iraq. They are particularly upset about the "collateral damage" of civilians being caught up in the violence. Yet here, those cheering for the DDoS attacks in support of WikiLeaks are just shrugging off the collateral damage that this attack is causing. Addendum: the quick, reflex downvote…
I don't know if Assange goes around saying "anarchy for everyone!" and I don't care. I don't like the idea of vast swaths of government operating in secret. From the CIA, to the closed door congressional meetings.
Second, it's only money. In the scheme of things it's probably a net positive for the economy as alternatives are explored, supporting perhaps financial startups, security firms are employed, etc.
You (and lot's of others) are comparing that to leaks detailing loss of life. I don't get it. The moral compass on HN is weird.