Live data from Hacker News

Paypal.com appears to be unavailable

paypal.com

111–120 of 128 posts

Re: Paypal.com appears to be unavailable

#111

Earlier quoted context omitted.

I briefly logged onto their IRC channel. It is a total chaos but still they all agree to one target. They have also been hammering www.paypal.com port 443 so I expect this to do down soon too.

What in the world does the SSL connection have to do with anything? Surely it's the same web servers that are getting swamped, regardless of whether the incoming traffic is clear or SSL.

The secure/payments stuff probably happens on totally different servers.

Re: Paypal.com appears to be unavailable

#113
post #111

Earlier quoted context omitted.

What in the world does the SSL connection have to do with anything? Surely it's the same web servers that are getting swamped, regardless of whether the incoming traffic is clear or SSL.

The secure/payments stuff probably happens on totally different servers.

Sure, payments processed through their API might be different servers. But that's a completely different question than whether the traffic is clear or SSL.

Re: Paypal.com appears to be unavailable

#114

Earlier quoted context omitted.

I'm going to preface this by saying that I'm not actually a huge fan of WikiLeaks or of Anon, but... Try to keep things in perspective. We're facing a substantial progression towards a hybridization of the scenarios outlined in 1984 and Brave New World, and you're worried about the disruption of commerce? Are your priorities really that warped? There's always collateral damage, whether it's merchants or your civil ri…

I'm sorry, but do you honestly think this is anymore than a bunch of angry teenagers who will be bored in a week? Look back on every other instance of "Anon" "protesting" and work out what has changed. Please do show what they've actually done beyond cause minor temporary disruption, it just so happens that this time the minor disruption has real world repercussions and is hurting businesses. The people who are respo…

This is nothing more than Eco-terrorism for nerds. What's wrong with blowing up some buildings, after all they only cost money, and the fate of the world is at stake! Please. This is terrorism pure and simple--do right by Wikileaks or we will hurt you. Maybe it's terrorism you finally agree with because this time it's for the Internet, but let's be under no illusions it won't utterly backfire.

Re: Paypal.com appears to be unavailable

#115

Earlier quoted context omitted.

I'm going to preface this by saying that I'm not actually a huge fan of WikiLeaks or of Anon, but... Try to keep things in perspective. We're facing a substantial progression towards a hybridization of the scenarios outlined in 1984 and Brave New World, and you're worried about the disruption of commerce? Are your priorities really that warped? There's always collateral damage, whether it's merchants or your civil ri…

I'm sorry, but do you honestly think this is anymore than a bunch of angry teenagers who will be bored in a week? Look back on every other instance of "Anon" "protesting" and work out what has changed. Please do show what they've actually done beyond cause minor temporary disruption, it just so happens that this time the minor disruption has real world repercussions and is hurting businesses. The people who are respo…

I wouldn't be so sure that they're just going to lose interest in a week. Look at scientology, that's still going on.

Re: Paypal.com appears to be unavailable

#116
post #98

Earlier quoted context omitted.

I take death seriously, that does not mean I get to live forever.

You don't give some random army grunt access to your on/off switch.

Actually, I happen to work for the Army so I am often near well armed "grunts" with access to that off switch. It's a judgment call, but I assume walking around the Pentagon is probably safer than driving which I am also willing to do. More to the point, I think being respectful to well armed people is prudent, hiding under the bed is pointless. So, while I recognize the risk to life and limb at some point you need to focus on risk mitigation rather than avoidance.

PS: To put this into perspective, one of the guys I work with was there for 9/11. He sustained significant injury while several people in the room with him died. Yet, he is also willing to work in the building and most people in the building where not harmed.

Re: Paypal.com appears to be unavailable

#117
post #114

Earlier quoted context omitted.

I'm sorry, but do you honestly think this is anymore than a bunch of angry teenagers who will be bored in a week? Look back on every other instance of "Anon" "protesting" and work out what has changed. Please do show what they've actually done beyond cause minor temporary disruption, it just so happens that this time the minor disruption has real world repercussions and is hurting businesses. The people who are respo…

This is nothing more than Eco-terrorism for nerds. What's wrong with blowing up some buildings, after all they only cost money , and the fate of the world is at stake! Please. This is terrorism pure and simple--do right by Wikileaks or we will hurt you. Maybe it's terrorism you finally agree with because this time it's for the Internet, but let's be under no illusions it won't utterly backfire.

I oppose ALF and ELF both.

Re: Paypal.com appears to be unavailable

#118
post #116

Earlier quoted context omitted.

You don't give some random army grunt access to your on/off switch.

Actually, I happen to work for the Army so I am often near well armed "grunts" with access to that off switch. It's a judgment call, but I assume walking around the Pentagon is probably safer than driving which I am also willing to do. More to the point, I think being respectful to well armed people is prudent, hiding under the bed is pointless. So, while I recognize the risk to life and limb at some point you need t…

Not interested. My original post was not about your completely-missing-the-point simile, but about the fact the the US government demonstrably sucked at IT security when they let the great unwashed have the kind of access they had to State Department cables.

Re: Paypal.com appears to be unavailable

#119
post #85

Earlier quoted context omitted.

Well, I worked for Arbor, and while it's true that you can readily block packet-y attacks even from a million sources (as long as you can characterize the attack), you're kind of missing 'jrockway's point. During the Olympics in Korea, which Arbor ran DDoS protection for, attackers set up web pages that simply directed hundreds of thousands of computers at URLs on the MSNBC sites. How are you going to filter against…

I'm not going to get into specifics but I'd like to address your points. The problem of distinguishing between legitimate traffic and attack traffic gets harder when the attack starts to look more like legitimate traffic. It doesn't get impossible. You can have a more effective attack if you have a LOT of machines you can use to generate legitimate requests. Of course, after a short while, it's going to be possible t…

I agree that you missed my point :)

My point is, any finite limit can be exceeded. In days of old, it was state tables and file descriptors. Now it's bandwidth. Filtering doesn't matter once the packet has traveled down your finite link to your packet filter. That bandwidth has been used, and denied service to a legitimate user that wanted his packet to go to your server.

Mostly, you're right, it comes down to luck. Attackers don't get the chance to do a daily dev / qa / release cycle. They write something, push it to a bunch of users who hate Amazon and Paypal today, and that's the end of it. If they wrote good code, the attack will be good. If they need to tweak something, they missed the opportunity.

That's what's saving everyone here -- luck.

Re: Paypal.com appears to be unavailable

#120
post #64

Earlier quoted context omitted.

If they hadn't disabled Wikileaks accounts there would have just been another topic just as controversial that would have gotten a bug up hacker's asses. This isn't a story about Wikileaks. Wikileaks is just the handy example. This is a story about how small numbers of people can have a temper tantrum and produce a global impact. You can't reason backwards and say "well if they just hadn't done X everything would be…

That's just not true. There has neither been a reaction of this kind for other "bugs up hacker's asses" nor has there been an issue this controversial for a very long time. I can't think of any... perhaps the Morris' worm or Kevin Mitnick.

No there hasn't been a story like this -- ever. That's what makes it an interesting story.

Expect more like this. Eventually we'll get around to some issue that you can't feel so self-righteous about pursuing. Then the shoe will be on the other foot.

Post reply on HN