Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

31–40 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#32

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Did they say anywhere what their motive was?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#33
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

I, too, wish to punish people for daring to own something that might have a zero-day.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#34

I don't understand the goal though. What to gain ? Training for another big target ?

- Advertising for potential DDoS service buyers

- Bragging rights

- Experimentation

Edit: Also potentially political or personal. Eg Posting something that offends 8chan||nation states etc.

There's quite often blackmail involved (Pay us $x BTC and we go away).

Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#35

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

Wasn't Instagram famous for having a very small team of engineers responsible for the availability of the entire platform before Facebook acquired them?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#36

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

I, too, wish to punish people for daring to own something that might have a zero-day.

Are we talking about zero days here or obvious vulnerabilities known for decades but nothing gets done because there’s no cost associated with leaving it insecure? I strongly suspect the latter.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#37
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

How many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#38
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

Can't wait to tell Gran she's legally liable for a DDoS because her unsecured IOT washing machine best buy sold her caused the internet to cave in ;)

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#40

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

I'd actually love to see a fully working IPFS fallback for wikipedia when regular hosting doesn't work. Would it even be possible with ipfs?
Post reply on HN