Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

261–270 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#262
post #254

Earlier quoted context omitted.

You upload your private SSL key to Cloudflare for example. And I was talking about hosting on your own hardware/colos like most large sites do (7x cheaper than AWS list prices on avg)

Please specify in detail how you believe that’s an MITM using the standard industry definition. In particular, consider whether “attack” and “voluntary business agreement” are synonyms.

MITM is not a uncommon term to use when you do things like install corporate SSL certs on laptops so you can monitor people's activities.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#263
post #217
post #146

Earlier quoted context omitted.

I've never heard anyone in my life say they could rebuild MS office in a weekend. What, in your opinion, would be the work needed to go from a 100k monthly active user site to a wikipedia scale site - that would be comparable to rebuilding MS office?

The core parts of Office could be done on a weekend, but in order to get the same complexity and incompatibility it would take several "codemonkeys" several years to achieve.

Silly Microsoft wasted hundreds of people and decades of time. Why didn’t you tell them?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#264

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. During an attack, you make a BGP announcement and the traffic goes via Verisign scrubbing/tunnels. No application changes are required, no Matthew Prince selectively and benevolently enforcing CF neutrality. It's used by large banks.

Anyone that suggests that there is One True Solution TM is either biased or ignorant.

You also don't get to claim it supports 2Tbps if you've only weathered 44Gbps.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#265

Earlier quoted context omitted.

Because "physical safety regulations" is something that the majority understands, so it's hard to argue against that in public. With digital security, most people lack the mental models to follow the discussion, so it's really easy for lobbyists to tell them flatout lies about how those damn dems are out to take their smart lightbulbs away from them.

Ha ha, "most people." They're so stupid, right?! Not like we, the ones who know what's really going on and how things actually work.

Are you claiming that most people do understand computer security? My experience is that even many computer-savvy people (already a small fraction of overall population) are completely baffled by its intricacies.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#266

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

Only 85GB uncompressed for current revisions, excluding “user” pages. Not so bad!

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#267
post #45
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

There was a string of arson attacks on little free libraries in Metro Vancouver; eventually a pair of teenage boys were arrested. I suspect that the sharing of knowledge and encouragement of developing wisdom is, to some, a threatening prospect. Perhaps they have experienced learning difficulties and are struggling with shame and frustration, or perhaps they disagree strongly with the concept of an intellectually lib…

> or perhaps they disagree strongly with the concept of an intellectually liberated population. Libraries are, after all, a pillar of liberalism.

Thoughtful comment. I would agree with you if the attack is somehow organized at 4chan /b/, Kiwi Farms, or some underground IRC for mysterious or unexplained reasons. If it happens, its philosophical implications would be deep. And I won't surprise if it occurs one day.

But so far there's no evidence to suggest the attack has any ideological motivation beyond making the attacker famous.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#268
post #155

Earlier quoted context omitted.

Why do you think they are not from an English speaking country? They are likely advertising their botnet (and seems to be working rather well).

I think they might think they're not English speaking because it wasn't the English wikipedia sites that went down. Then again, they may easily have tried that too but it's larger, built to handle more traffic.

Actually the English Wikipedia went down as well, at least here in Italy.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#269

Earlier quoted context omitted.

Power users use very different workflows than read-only users. You can serve pages from a 30-minute-old cache to the 99.9% of passive readers and it doesn't hurt that much. Editors use "Recent Changes" to monitor edits, and that's much easier to render in real time because the audience is comparatively minuscule.

Yes but if someone replaces the picture on the trump article with goatse, and non power users get this version for 30 minutes until the cache clears - they are going to be pretty pissed and start yelling to power users & just generally cause a PR disaster. Additionally if vandals know their vandalism will stay for 30 min, they are much more likely to do it, which is a vicious cycle

Aren't articles like Trump write protected? If you want to edit, you shouldn't be able to, unless you have an account that's not brand new. You will be banned very quickly as soon as you start putting goatse on most visited pages.

Also, the white house PR team is actively watching and editing political figures articles. They will sort it out too.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#270
post #234
post #207

Earlier quoted context omitted.

The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings. Moreover, as they took the decision they went to great pains to explain this was an exceptional case. Going from that to 'undesired political speech will be censored' requires more of a slippery cliff than a slippery slope.

>The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?

There are multiple instances of them announcing them and implying they are follow-ups of previous discussions on 8chan.

These include the Christchurch shootings, the Poway synagogue shooting and the El Paso Walmart shootin.

The Christchurch shooter shared his Facebook stream to 8chan before the shooting started, and it was spread from there.

The Poway shooter blamed/thanked 8chan for his views.

Post reply on HN