Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

251–260 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#251
post #241

Earlier quoted context omitted.

> What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack? The problem is that you are basically mitm:ed all the time.

That’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.

You upload your private SSL key to Cloudflare for example. And I was talking about hosting on your own hardware/colos like most large sites do (7x cheaper than AWS list prices on avg)

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#252
post #89

Earlier quoted context omitted.

Big box retailers seem to be able to comply with regulations mandating physical safety. Digital security requirements could be enforced by a similar system.

Because "physical safety regulations" is something that the majority understands, so it's hard to argue against that in public. With digital security, most people lack the mental models to follow the discussion, so it's really easy for lobbyists to tell them flatout lies about how those damn dems are out to take their smart lightbulbs away from them.

Ha ha, "most people." They're so stupid, right?! Not like we, the ones who know what's really going on and how things actually work.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#253
post #241

Earlier quoted context omitted.

That’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.

A better comparison would be Cloudfront and Application Load Balancers since you can expose your own ec2 server or load balancer and be e2e encrypted (unless AWS wanted to run commands on your instance, which they could do, but that's a different threat vector entirely).

That was the model I had in mind but it’s not really a meaningful distinction since the host could almost certainly compromise those servers as well. In any case, you’re trusting a third party rather than having their involvement maliciously imposed.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#254
post #241

Earlier quoted context omitted.

That’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.

You upload your private SSL key to Cloudflare for example. And I was talking about hosting on your own hardware/colos like most large sites do (7x cheaper than AWS list prices on avg)

Please specify in detail how you believe that’s an MITM using the standard industry definition. In particular, consider whether “attack” and “voluntary business agreement” are synonyms.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#255
post #118

Earlier quoted context omitted.

The ipfs.io is just a web-based way to access IPFS, called a gateway. There are a bunch of different gateways. In addition, you can run an IPFS node locally, and then as long as just one node holds the content you're looking for you are looking for you're good. There are also browser extensions to re-write gateway URIs to localhost URIs.

So there is no central place like bittorent tracker which if down the network does not works? Or is it like DHT which does not need central tracker?

IPFS uses DHT on a fairly fundamental level.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#256
post #242
post #214

Earlier quoted context omitted.

By not moderating content largely, it was no secret what the site was letting go.

By your statement then reddit was complicit with the Russian trolls during election season because the bitcoin trolls who evolved into trump trolls were not punished in the slightest (I have a list of 300+ usernames that are still active today)

Reddit is actively moderated by both paid Admins (site wide rules) and volunteer Mods (per subreddit rules). So no, I disagree.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#257

I don't understand the goal though. What to gain ? Training for another big target ?

They already switched to Twitch and WoW. So it seems Wikipedia may just have been the first target cause it is big.

The interesting this to me was that whoever this person was knew WoW twitch personalities at least decently. Before his Twitter went down, he was using some of th phrases that people say to try and make fun of Asmongold. He was also posting screenshots from Asmon and Sodapoppin about the attack.

They were talking like twitch chat at times.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#258

Earlier quoted context omitted.

Any serious mitigation solution must be BGP based, not proxy. Besides its technical merits and convenience, it also minimizes the risk of a benevolent controller (e.g. Matthew Prince of Cloudflare) ruining your company, because it becomes your upstream provider only during the attacks. Otherwise the GRE tunnels are not in use. The IP addresses are still yours always. We used Verisign for mitigation of a 44Gbps volume…

You appear to be extremely mad Cloudflare stopped proxying a website that encouraged large gun massacres.

You appear to be extremely mad that anyone questions the power of political pressure and an angry mob.

Look, you can feel however you like about whether the high-profile takedowns are right or wrong, whether the CEO's promises after the Daily Stormer are hypocritical — but let's be clear-eyed about placing a site in a position where one outside person can do it real harm. The question you should look at is whether the risk is actually acceptable for your organization.

Post reply on HN