Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

51–60 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#51

I don't understand the goal though. What to gain ? Training for another big target ?

Just a wild guess, but they could be showcasing their capabilities before selling them to the highest bidder.

Being able to take down such big websites would probably go a long way in giving them some credibility when selling their services.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#52
post #45
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

There was a string of arson attacks on little free libraries in Metro Vancouver; eventually a pair of teenage boys were arrested. I suspect that the sharing of knowledge and encouragement of developing wisdom is, to some, a threatening prospect. Perhaps they have experienced learning difficulties and are struggling with shame and frustration, or perhaps they disagree strongly with the concept of an intellectually lib…

More likely just trying to have fun. I'm sure they would do the same to local schools.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#53

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

I'd actually love to see a fully working IPFS fallback for wikipedia when regular hosting doesn't work. Would it even be possible with ipfs?

IPFS has a Wikipedia mirror but it is fairly out of date since it is dependent on the Kiwix archive.

https://github.com/ipfs/distributed-wikipedia-mirror

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#54

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

It's because they're just serving a big site, not running the world's most sophisticated surveillance and ad serving machine. Serving giant websites isn't all that hard if you're just spewing out SQL queries into html templates. It all scales in all directions with a properly thought through architecture.

But also perhaps it’s because they didn’t allow a team to endlessly iterate on tech minutiae until they required many teams to keep it running and iterate on tech minutiae.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#55
post #37

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

How many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?

If these systems are owned by private people then the company who designed it/deployed it is liable. If I have root on the device then it's my fault if I screw up, if I don't have root and it's just a plug and play appliance then whoever designed it/sold it can be liable. This solves the issue of "grandma buying an IoT washing machine" mentioned in another comment as the manufacturer of the machines can be sued directly without bothering grandma (besides a recall program and/or firmware update to patch the vulnerabilities).

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#56

I don't understand the goal though. What to gain ? Training for another big target ?

- Advertising for potential DDoS service buyers - Bragging rights - Experimentation Edit: Also potentially political or personal. Eg Posting something that offends 8chan||nation states etc. There's quite often blackmail involved (Pay us $x BTC and we go away). Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins.

> Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins.

Well, it is still a lot of wasted resources (bandwidth, energy, compute) for everyone involved (ISP, CF, attacker, defender, compromised machines), so I wouldn't be so quick to say that "everyone wins".

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#57
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

[deleted]

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#58

Earlier quoted context omitted.

Did they say anywhere what their motive was?

Do these kinds of attacks usually have a motive?

They can be used by blackhats selling e.g. DDoD-netbots to prove the “quality of the merchandise”.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#59

Earlier quoted context omitted.

It's because they're just serving a big site, not running the world's most sophisticated surveillance and ad serving machine. Serving giant websites isn't all that hard if you're just spewing out SQL queries into html templates. It all scales in all directions with a properly thought through architecture.

Please be careful of logical tautologies: "It all scales in all directions with a properly thought through architecture" sounds dangerously like, "Programming isn't that hard if you just do it right."

I appreciate what you're saying, but I don't think it quite applied. What I meant was that it's easy to create an architecture for an application that doesn't scale well at all. Eg - poorly sharded data, lots of cross dependencies etc. However, if you properly think through your data model and data flows and use cases, it's generally possible to create a system that is extremely scalable in all directions. This is certainly not easy, but it's a hell of a lot easier than creating some huge ai driven data slurping ad empire.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#60
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

Award for worst hot take of the day goes to....
Post reply on HN