Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

91–100 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#91
post #41

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's n…

Nothing stopping you from capturing packets at the router or using tcpdump on your phone. Not convenient but theoretically possible.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#92

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

There's also a read-only IPFS mirror of Wikipedia in English: https://ipfs.io/ipfs/QmXoypizjW3WknFiJnKLwHCnL72vedxjQkDDP1m...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#94
post #41

Earlier quoted context omitted.

You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's n…

Nothing stopping you from capturing packets at the router or using tcpdump on your phone. Not convenient but theoretically possible.

> Nothing stopping you from capturing packets at the router or using tcpdump on your phone. Not convenient but theoretically possible.

You don't interact with people out of your bubble much, do you? It's time to start write better code, not blaming users for the programmer's incapability.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#95
post #89

Earlier quoted context omitted.

There are exactly zero big box retailers or lobbyists that will abide that.

Big box retailers seem to be able to comply with regulations mandating physical safety. Digital security requirements could be enforced by a similar system.

No thanks. I'd rather DDoS attcks than whatever the version of a seatbelt locking "safety" mechanism is that these moron companies would force upon people.

"Place eyeball for retina scan to unlock your dick pic machine."

No thanks.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#96

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Who are they?

Some clown named ukdrillas. That's about all any one knows.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#97
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

except, mental states are perhaps less stable than physical ones, ultimately, and using a 'web site' is largely a mental model on the part of the user, while a technical model on the part of the provider. Dysfunctional mental drivers + lots of access + lots of time .. versus a door that locks each night and an alert attendant or three.. This is dismaying but not shocking.. the first time I saw a newly planted tree on…

Or maybe stop planting trees if your people are so ignored and powerless they feel the need to destroy it.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#98
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

Could you ELI5 how these sorts of attacks are possible and what the average Joe can do to mitigate them?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#99

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Did they say anywhere what their motive was?

They are advertising their services.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#100
post #41

Earlier quoted context omitted.

You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's n…

Nothing stopping you from capturing packets at the router or using tcpdump on your phone. Not convenient but theoretically possible.

Gee, lemme just call up my grandma and teach her how to set up kismet and snort.

Seriously though, this is like holding some one liable if his car is stolen and used as a get-away car in a crime. It's also not really possible to get a shell on most of these devices with serious effort, so apart from turning one off, I'm not sure how any one is supposed to mitigate this. They're too locked down to do any kind of disinfection, in most cases. I guess now I have to teach granny to use a uart cable, too.

Post reply on HN