Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

31–40 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#31
post #18
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

Lucas and his team are amazing. Everyone makes mistakes, and no system will be perfectly secure. So in my mind the best parts of the entire post were these: "We have hired professional white hat hackers with government level security experience to attempt regular pen tests on our system, both as regular users as well as giving them special access and seeing if they can get through." and "If you find a security flaw a…

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#32
Here's an interesting tweet from one of their developers.

http://twitter.com/ReinH/status/50348989366796288

> Your password in the database is SHA512 encrypted, but we're not taking chances.

I hope he knows what he's talking about and is just tired from the past few days.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#33
post #20

Never? I would be cautious about issuing a challenge like that.

They might still have a security hole big enough to drive a freight train through, but that specific attack will never happen again given that they've shut down the shared failover server.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#34
post #24

Wait...their model is an EC2 instance per customer? The normal limits Amazon imposes are 20 reserved or on-demand instances and 100 spot instances per region. You can request more, but will Amazon really accommodate a one instance per customer model?

Amazon is happy to. The limits you cite are merely the point at which you need to have a conversation with Amazon staff. They are quite happy to accomodate _much_ heavier usage from customers.

When I asked for a raise to my limit they denied me, on the basis that my usage was insufficient. Of course, my usage was low because I hadn't launched my product fully because I didn't have enough instances to serve a lot of customers ... catch 22.

So I had to build out a rather convoluted architecture that used the loophole of deploying to multiple regions and failing over to whichever region would give me an instance ... which gives me up to about 80 instances ... just barely enough for me to get going with a trial beta program.

Which is all just to say, it is slightly more than just a "conversation" that you need to have to get a higher limit.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#35
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

Hire the hackers. It's what the CIA would do.

Hiring the hackers is a terrible idea. If they had done it ethically, yes. But do you really want to hire someone who has already displayed highly unethical behavior, and is likely a ticking timebomb? There are plenty of smart, ethical hackers out there.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#36

Here's an interesting tweet from one of their developers. http://twitter.com/ReinH/status/50348989366796288 > Your password in the database is SHA512 encrypted, but we're not taking chances. I hope he knows what he's talking about and is just tired from the past few days.

Let's hope they are salted and iterated.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#37

I mentioned this last time, but I don't think anyone was interested, but the "John" guy is compwhizii (same handle on Twitter) who runs the forums (facepunch.com) for garrysmod, a very popular game. I will be curious to see how garry (owner person) responds to this, or if he already has. Elliot is apparently VERY scared and blames John (compwhizii) (edit: not john, he blames someone else called supersnail1): http://w…

And here's Elliot's "official statement": http://elliotspeck.com/phpfog.html

And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#38
The blog post is riddled with the words "luck" and "timing" which brings doubt into my mind that the team can actually take full responsibility for their actions.

"aware of the potential security threat " but they left it for the next week, who honestly here would do that?

I have also seen comments around the web of migrating to Php Fog because of how they handled the situation. If you are one of these people please enlighten my mind as to how you came to such a logical decision or how much you get paid per year.

Also if Php Fog could enlighten us on how their terms of agreement will work in the case where our intellectual property is stolen on no fault of our own.

Save your sympathy for the sites that are still down, four days and counting

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#39
post #2

What a crazy story. If the timelines are accurate there was an extremely small chance of this happening. Bad luck all around. My site is still down, guess i'm in the unlucky 1%.

Yeah but the problem with 'things planned for the near future' is that they have a tendency to stay in the future until something like this happens.

Yes, and after the fact, they sound like excuses (even when they are true and they are not meant to be excuses as in this case).

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#40
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

Hire the hackers. It's what the CIA would do.

Or do like the FBI and offer them a job, when they come for the interview they get frogmarched into the police cruiser.
Post reply on HN