Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

111–120 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#111
post #84

On a side note, I was surprised to learn, that Wikipedia does not have a proper status page. status.wikimedia.org redirects to grafana dashboard and it too was down yesterday.

I wouldn’t expect a site to have a publicly available status page or anything like public grafana boards. Isn’t that what HTTP error codes are for? Can you share examples of where this is common?

HTTP status codes tell you that something is broken, but likely not details. Or nothing at all, if all you get is a timeout because the service just got DDoSed.

Many services and sites have them, a few random examples:

https://status.flickr.net/

https://www.vimeostatus.com/

https://3down.mit.edu/

https://www.githubstatus.com/

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#112

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

If you consider the amount of money they are burning in comparison to 5 years ago, are the results really that impressing? See https://en.wikipedia.org/wiki/Wikipedia:Wikipedia_Signpost/2...

[deleted]

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#113

Earlier quoted context omitted.

I, too, wish to punish people for daring to own something that might have a zero-day.

Are we talking about zero days here or obvious vulnerabilities known for decades but nothing gets done because there’s no cost associated with leaving it insecure? I strongly suspect the latter.

How are you supposed know what chipsets are in your smart lightbulb?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#114
post #45
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

There was a string of arson attacks on little free libraries in Metro Vancouver; eventually a pair of teenage boys were arrested. I suspect that the sharing of knowledge and encouragement of developing wisdom is, to some, a threatening prospect. Perhaps they have experienced learning difficulties and are struggling with shame and frustration, or perhaps they disagree strongly with the concept of an intellectually lib…

That's sad to hear, I always love coming across the little free libraries. I would guess they were just bored and angry teens, likely not making any deeper statement but just expressing their anger and frustration and willingness to break the rules. Also, it's fun to watch things burn, and they come with built-in kindling. Hopefully some judge will make them rebuild what they burned, that would be fair and give them more appreciation for the work of others that they destroyed thoughtlessly.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#115
post #84

On a side note, I was surprised to learn, that Wikipedia does not have a proper status page. status.wikimedia.org redirects to grafana dashboard and it too was down yesterday.

I wouldn’t expect a site to have a publicly available status page or anything like public grafana boards. Isn’t that what HTTP error codes are for? Can you share examples of where this is common?

Atlassian has a whole service that just hosts public status pages

https://www.statuspage.io/

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#116
post #86
post #41

Earlier quoted context omitted.

You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's n…

You can't expect everyone to be able to identify when their car is not running as expected. Wait, you can and you must under the law. Also there are liabilities.

Very much not the same thing. Your car can't interact with the cars of others without physical contact, and when it does interact, via a crash or otherwise, it would be very obvious to anyone. Even if you were constantly watching the traffic of your phone and other devices, you'll probably miss malicious packets that are sent among the thousands of packets each device sends per minute. It's also not as obvious to recognize what constitutes malicious behavior in your internet device compared to your car.

Also, the operation of the car is simple enough that you can take it to a mechanic for an inspection and they can reliably inspect everything that the car does. There are no hidden behaviors under complex conditions, like crashing into others when there is a full moon or the sky is cloudy. Your devices can do that. If you bring me your phone/laptop/etc and ask me if it's going to send malicious packets to someone somewhen, I can't reliably tell you that it won't. I'm not sure that even if you gathered all software and electronics engineers that supposedly were involved in the construction of your device, they'd be able to provide a reliable answer. I can tell you that it seems like it wouldn't based on initialization files and services, but I can't tell if the function is hidden somehow, like obfuscated in the machine code of the kernel or something. Finding that would require auditing all assembly code running on the machine, which would not be a task for mortals.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#117

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

I was motivated to donate a small amount of BCH to WMF after reading this announcement.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#118

Earlier quoted context omitted.

There's also a read-only IPFS mirror of Wikipedia in English: https://ipfs.io/ipfs/QmXoypizjW3WknFiJnKLwHCnL72vedxjQkDDP1m...

I love ipfs. Can this actually be ddos’d as well?

The ipfs.io is just a web-based way to access IPFS, called a gateway. There are a bunch of different gateways. In addition, you can run an IPFS node locally, and then as long as just one node holds the content you're looking for you are looking for you're good. There are also browser extensions to re-write gateway URIs to localhost URIs.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#119
post #86

Earlier quoted context omitted.

You can't expect everyone to be able to identify when their car is not running as expected. Wait, you can and you must under the law. Also there are liabilities.

Brakes squeal when they are wearing down. If I put a penny in the tread of my tires and see Abe Lincoln’s head I know they are bald. If my head lamps go out I’ll notice; if it’s a brake light I get a red indicator lamp on my dash that says I have a problem. Let’s talk about liability when home routers make a revving engine sound when they push too many packets per second, or start playing a “buckle up” warning chime…

I'm liable if water/sewage breaks in my condo and there won't be any 'squeal'. Analogies work but are not equal. My point is that there should be liability for the malfunctioning internet equipment, definitely so for businesses.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#120

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. During an attack, you make a BGP announcement and the traffic goes via Verisign scrubbing/tunnels. No application changes are required, no Matthew Prince selectively and benevolently enforcing CF neutrality. It's used by large banks.
Post reply on HN