Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

151–160 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#151

Earlier quoted context omitted.

From a cursory glance at the site and source code, it's really hard to see who/what is involved with building an archive. There's automated builds set up for the Pi image itself.

Agreed. I can see that other Wikipedia languages are crawled - https://wiki.kiwix.org/wiki/Content_in_all_languages shows dozens of updates this week - but the best leads I have involve poking around the openZIM Github org, https://github.com/openzim . There might be a running "zimfarm" somewhere?

You can build your own ZIMs from any MediaWiki instance using this tool: https://github.com/openzim/mwoffliner.

Maybe it would be worth putting together another zimfarm that is constantly updating.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#152

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

I, too, wish to punish people for daring to own something that might have a zero-day.

The negative externalities of owning vulnerable devices need to come home to roost at some point, yeah.

I've chosen to own a "dumb" (read: "reliable") washing machine, and it cannot be used in such an attack. I have to endure the indignity of peeking downstairs to see if I left clothes in it, which is a cost of sorts, but it's nowhere near the cost I'd expect to bear if I bought a vulnerable washing machine and it provided resources to knock Wikipedia off the internet.

What other disincentive to putting vulnerable devices on the internet do you propose?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#153

Earlier quoted context omitted.

I used to work at FB and now work at Reddit. The engineering staff count at Reddit is within the same order of magnitude as the number you cite above. :)

Yeah, but unlike on Reddit, I never see "something went wrong" on Wikipedia. No offense to you nor your team, but to me, as a consumer, reddit's product doesn't appear nowhere near as polished as Wikimedia's projects.

No offense taken, I don’t work on the product side of things there.

Also, with the caveat that I don’t know enough about the implementation details of the product at Reddit: I’d argue that Reddit’s workload is more write heavy that Wikipedia’s workload, which makes caching and scaling a bit harder for Reddit, relatively speaking.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#154

Earlier quoted context omitted.

The proportion of read/write may skew towards reads, but Wikipedia still is an application where any user can create state visible to all other users. It's not as simple as this comment makes it out to be.

But how quickly must those writes be reflected in the reads of others? If you can accept a few minutes of latency there, I imagine things would get easier

In order for wikipedia's anyone can edit to work, its really important that when someone makes a bad edit to a popular article that it can be removed immediately. This is important both to get things fixed quickly and to make it less of a juicy target so less people vandalize (no fun to vandalize if it doesnt stay up).

I suspect latency in the minutes for cache updates would be unaceptable to wikipedia users

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#155
post #63

Earlier quoted context omitted.

It might be, but currently doesn't appear that's the motivation here, not if they're also attacking twitch & WoW.

My guess is they tried google and facebook without any luck so they moved on. The choices made would tell me that they are younger mid-late 20s / probably not from an English speaking country. Motivation.. sense of power.

Why do you think they are not from an English speaking country? They are likely advertising their botnet (and seems to be working rather well).

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#156

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. During an attack, you make a BGP announcement and the traffic goes via Verisign scrubbing/tunnels. No application changes are required, no Matthew Prince selectively and benevolently enforcing CF neutrality. It's used by large banks.

This recent CF product announcement might be the same thing (not sure, sounds similar): https://blog.cloudflare.com/magic-transit/

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#157
post #138
post #130

Earlier quoted context omitted.

>no Matthew Prince selectively and benevolently enforcing CF neutrality. What's the logic behind this? It's still a single point of failure and relying on a corporation. If the daily stormer or 8chan tried to use them, they would probably kicked off as well.

If you are not a political undesirable, it does help, though. I think Wikipedia is fine in this regard, not something to shun of for a big corp.

I think it’s somewhat misleading to refer to those who support genocide and child abuse as simply “political undesirables.”

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#158
post #37

Earlier quoted context omitted.

How many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?

You'll also have to prove the IOT device DDoSing from my IP isn't a rogue device. I swear it's not mine.

If someone hacks my WPA password and torrents child porn from my IP I am liable (in Germany) - no need to prove it was me or my device.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#159

Earlier quoted context omitted.

But how quickly must those writes be reflected in the reads of others? If you can accept a few minutes of latency there, I imagine things would get easier

It must be immediate, because Wikimedia can detect edit conflict (when someone update the article you are in the middle of editing)

That doesn’t mean all reads have to be immediate, only some.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#160
post #138
post #130

Earlier quoted context omitted.

>no Matthew Prince selectively and benevolently enforcing CF neutrality. What's the logic behind this? It's still a single point of failure and relying on a corporation. If the daily stormer or 8chan tried to use them, they would probably kicked off as well.

If you are not a political undesirable, it does help, though. I think Wikipedia is fine in this regard, not something to shun of for a big corp.

Wikipedia is blocked in China. It's politically undesirable for 1/8 of the human population...
Post reply on HN