I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…
Lucas and his team are amazing. Everyone makes mistakes, and no system will be perfectly secure. So in my mind the best parts of the entire post were these: "We have hired professional white hat hackers with government level security experience to attempt regular pen tests on our system, both as regular users as well as giving them special access and seeing if they can get through." and "If you find a security flaw a…
How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
31–40 of 202 posts
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#32http://twitter.com/ReinH/status/50348989366796288
> Your password in the database is SHA512 encrypted, but we're not taking chances.
I hope he knows what he's talking about and is just tired from the past few days.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#33Never? I would be cautious about issuing a challenge like that.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#34Wait...their model is an EC2 instance per customer? The normal limits Amazon imposes are 20 reserved or on-demand instances and 100 spot instances per region. You can request more, but will Amazon really accommodate a one instance per customer model?
Amazon is happy to. The limits you cite are merely the point at which you need to have a conversation with Amazon staff. They are quite happy to accomodate _much_ heavier usage from customers.
So I had to build out a rather convoluted architecture that used the loophole of deploying to multiple regions and failing over to whichever region would give me an instance ... which gives me up to about 80 instances ... just barely enough for me to get going with a trial beta program.
Which is all just to say, it is slightly more than just a "conversation" that you need to have to get a higher limit.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#35I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…
Hire the hackers. It's what the CIA would do.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#36Here's an interesting tweet from one of their developers. http://twitter.com/ReinH/status/50348989366796288 > Your password in the database is SHA512 encrypted, but we're not taking chances. I hope he knows what he's talking about and is just tired from the past few days.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#37I mentioned this last time, but I don't think anyone was interested, but the "John" guy is compwhizii (same handle on Twitter) who runs the forums (facepunch.com) for garrysmod, a very popular game. I will be curious to see how garry (owner person) responds to this, or if he already has. Elliot is apparently VERY scared and blames John (compwhizii) (edit: not john, he blames someone else called supersnail1): http://w…
And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#38"aware of the potential security threat " but they left it for the next week, who honestly here would do that?
I have also seen comments around the web of migrating to Php Fog because of how they handled the situation. If you are one of these people please enlighten my mind as to how you came to such a logical decision or how much you get paid per year.
Also if Php Fog could enlighten us on how their terms of agreement will work in the case where our intellectual property is stolen on no fault of our own.
Save your sympathy for the sites that are still down, four days and counting
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#39What a crazy story. If the timelines are accurate there was an extremely small chance of this happening. Bad luck all around. My site is still down, guess i'm in the unlucky 1%.
Yeah but the problem with 'things planned for the near future' is that they have a tendency to stay in the future until something like this happens.
Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)
#40I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…
Hire the hackers. It's what the CIA would do.