Earlier quoted context omitted.
I definitely get the feeling that’s what they’re going for. They mentioned they’re just testing out a new botnet made from IoT devices.
And so the IoT wars begin...
Malicious attack on Wikipedia – what we know and what we’re doing
81–90 of 320 posts
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#82Earlier quoted context omitted.
You seem familiar with hardware and software hacking, but not the creativity of bad-faith legal hacking ;-) If you pass that law on Day Zero, I claim that on Day One, manufacturers provide some horribly arcane command-line interface for rooting lightbulbs and washing machines, and add some boilerplate to their shrink-wrap licenses forcing customers to acknowledge that they have admin privileges on their devices. Prob…
Does the license auto-root the device? If yes, then it's an obviously dishonest circumvention of the law and judges will see right through it. If not, then the manufacturer has to prove the device was rooted if they want to pass liability to someone else. If that still doesn't solve the problem, the media will take care of it. "Buying this smart lightbulb puts you at risk of being sued for thousands of $$$" can't be…
"Selling this insecure IoT-device/phone/router/tv that requires every consumer to become a security expert, and taking no responsibility for OTA patches and so forth, puts you at risk for paying hundreds of millions of dollars in fines and/or damages."
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#83Earlier quoted context omitted.
Can't wait to tell Gran she's legally liable for a DDoS because her unsecured IOT washing machine best buy sold her caused the internet to cave in ;)
Skip Gran and sue Best Buy and the IoT washing machine manufacturer.
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#84Re: Malicious attack on Wikipedia – what we know and what we’re doing
#85Earlier quoted context omitted.
And they're hiring! https://wikimediafoundation.org/about/jobs/#section-8 I worked there for four years and I miss it every day.
> I worked there for four years and I miss it every day. Sorry but now I'm curious, why did you leave?
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#86Earlier quoted context omitted.
Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…
You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's n…
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#87I don't understand the goal though. What to gain ? Training for another big target ?
- Advertising for potential DDoS service buyers - Bragging rights - Experimentation Edit: Also potentially political or personal. Eg Posting something that offends 8chan||nation states etc. There's quite often blackmail involved (Pay us $x BTC and we go away). Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins.
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#88Earlier quoted context omitted.
> I worked there for four years and I miss it every day. Sorry but now I'm curious, why did you leave?
Wikipedia has a huge impact in people's lives, particularly in non-English languages, and there's so much work to do, and so much of it feels urgent and necessary. I really responded to that, and I wasn't careful, and burnt myself out. (This was not the fault of the org; Wikimedia is largely a do-ocracy, and if you're intent on working through the small hours of the night, there is very little anyone can do to stop y…
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#89Earlier quoted context omitted.
Skip Gran and sue Best Buy and the IoT washing machine manufacturer.
There are exactly zero big box retailers or lobbyists that will abide that.
Re: Malicious attack on Wikipedia – what we know and what we’re doing
#90Earlier quoted context omitted.
Caveat: the last full Kiwix English Wikipedia archive was made in 2018. They could use some help with automating their build process if anyone here has the time.
From a cursory glance at the site and source code, it's really hard to see who/what is involved with building an archive. There's automated builds set up for the Pi image itself.