Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

271–280 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#271
post #19

Earlier quoted context omitted.

How interesting. Could you post some evidence? Thanks!

Extraordinary claims require extraordinary evidence, so by that symmetry this shouldn’t require much evidence.

if something is repeated a lot, it doesn't make it true. Though it does make it more believable to common folk according to Goebbels https://www.azquotes.com/author/5626-Joseph_Goebbels

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#272

Are there non-malicious attacks? Doesn't the word "attack" imply maliciousness?

"Attack" is a technical term and doesn't imply malicious intent. Many attacks are accidental or the result of negligence. Some are performed by researchers in purpose but without malicious intent (e.g. the attacker wants to prove that something is possible without actually doing any damage).

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#273
post #234
post #207

Earlier quoted context omitted.

The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings. Moreover, as they took the decision they went to great pains to explain this was an exceptional case. Going from that to 'undesired political speech will be censored' requires more of a slippery cliff than a slippery slope.

>The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?

The direct link is that they announced these attacks there.

Beyond that, given the announcement there, it stands to reason they were convinced to do it there.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#274
post #234
post #207

Earlier quoted context omitted.

The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings. Moreover, as they took the decision they went to great pains to explain this was an exceptional case. Going from that to 'undesired political speech will be censored' requires more of a slippery cliff than a slippery slope.

>The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?

> What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?

Legally, a "direct link" is irrelevant, you can rarely find a "direct link" between two of anything. What matters legally is whether 8chan was a "proximate cause" in creating the mass shootings. Whether one thing is the "proximate cause" of another is often pretty difficult to discern.

However, as a helpful guide towards determining proximate cause, lawyers ask whether one thing was the "but for" cause of another, i.e., would the mass shootings occur "but for" 8Chan? Put another way, if 8Chan did not exist, would these shootings occur?

Unfortunately, we do not have an alternative reality to play out events without 8Chan, so we cannot know for certain, but we can use evidence (e.g., 8Chan chats, how the shooter interacted with 8Chan and others on the service, etc) to try to simulate that alternative reality. All of this analysis also needs to consider related issues like freedom of speech on public forums and any commercial interests.

I'm not saying 8Chan is guilty or innocent, just that the existence (or lack thereof) of a "direct link" is pretty meaningless.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#275

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

It looks like a volumetric attack from this tweet. Wikipedia needs to use Verisign BGP mitigation. They create GRE tunnels to your routers and are capable of handling 2Tbps. During an attack, you make a BGP announcement and the traffic goes via Verisign scrubbing/tunnels. No application changes are required, no Matthew Prince selectively and benevolently enforcing CF neutrality. It's used by large banks.

> no Matthew Prince selectively and benevolently enforcing CF neutrality.

Is this a slippery slope argument.

Because there is a world in difference from discontinuing a few extremists customers, to discontinuing service for something akin to Wikipedia.

I'm not sure every slight compromise of principals is a slippery slope. It seems to me that CF generally aims at being neutral.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#276
post #254

Earlier quoted context omitted.

Please specify in detail how you believe that’s an MITM using the standard industry definition. In particular, consider whether “attack” and “voluntary business agreement” are synonyms.

MITM is not a uncommon term to use when you do things like install corporate SSL certs on laptops so you can monitor people's activities.

Breaking open encryption to monitor activity between users and other sites is a completely different thing than having a provider handle hosting for your site.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#277
post #254

Earlier quoted context omitted.

You upload your private SSL key to Cloudflare for example. And I was talking about hosting on your own hardware/colos like most large sites do (7x cheaper than AWS list prices on avg)

Please specify in detail how you believe that’s an MITM using the standard industry definition. In particular, consider whether “attack” and “voluntary business agreement” are synonyms.

[deleted]

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#278

Earlier quoted context omitted.

You appear to be extremely mad Cloudflare stopped proxying a website that encouraged large gun massacres.

The originalcontent was posted on IG. 8ch took the reposts down when it became known that it was connected to the real shooting. Watch the video with the 8ch founder explaining (unless YouTube took it down too). Matt was preparing for the IPO.

As a decent human being you should defend free speech regardless if it was IG first or not.

But

I've seen zero evidence it was IG first and IG denied it and Jim Watkins has shown no proof otherwise, no logs and no statement how or why he even thinks it was on IG first.

He stated it as fact, without even a backstory. IG have looked into it and said the account wasn't used for a year and I've seen nothing about any second account. Even 8chan/pol considered it fake news the IG first theory (As best they can agreed on anything)

https://www.cnet.com/news/8chan-owner-says-el-paso-shooter-d...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#279

Earlier quoted context omitted.

Genocide has been and still is a political tool. It is extreme, but ultimately something that people consider and carry out as part of political processes, not a special category of its own. And realpolitik is to continue dealing with countries that practice genocide. Consider Burma or China. Cloudflare simply has the luxury of choosing which politically disagreeable parties they do not want to associate with because…

I didn’t say it wasn’t political, but it’s not just undesirable for immediate political reasons — it’s undesirable for nearly universally-agreed moral and ethical reasons. So implying it’s only inconvenient for politics is, in my opinion, misleading.

The political tends to encompass or at least subsume the moral and ethical aspects, as I tried to allude to with the realpolitik aspect.

But again, this is just a tangent. The core argument is that it is best not to rely on providers that have the freedom to make political/moral decisions who they deal with because that freedom makes them susceptible to moral denial of service attacks. You are one moral outrage away from being deplatformed.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#280
post #104

Earlier quoted context omitted.

Agreed. I can see that other Wikipedia languages are crawled - https://wiki.kiwix.org/wiki/Content_in_all_languages shows dozens of updates this week - but the best leads I have involve poking around the openZIM Github org, https://github.com/openzim . There might be a running "zimfarm" somewhere?

Looks like you are right, you may be able to join the farm to help ( i have not tested as I am away from my computer at the moment ) https://github.com/openzim/zimfarm/blob/master/worker/README...

Someone should ask drone.io or packet.net for an Epyc machine to do this.
Post reply on HN