Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

51–60 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#51
It seems like incredible coincidence that allowed this to happen but when I think back to all of the security incidents I've been involved in, it always seems this way.

I guess the best way to think of it is that badness on the internet is like water. It will flow into every tiny crack in your wall you haven't sealed up tight. A crack in a dam doesn't leak less because its in an "obscure" location.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#52
This feels like a business model where the lean/MVP approach isn't quite appropriate. A lot of things fall out of that decision, not the least of which is that the exposure surface area you get from an environment that allows user-sourced code on purpose is enormous. I feel for the guys going through this but there were a lot of errors in the wild all at once to allow this to happen.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#53
post #42
post #22

Earlier quoted context omitted.

At the risk of that comment being taken as a joke, I've done a lot of work with the federal government, and I can assure you that while the level of hilarity that HBGary has generated, the typical level of talent in government cleared individuals is not necessarily great. I don't mean to impune the capabilities of the people involved (I don't know who they are,) and it isn't to say that you can't find some AMAZING ta…

Reminds me of when I was in the Navy and I went to Navy Security and Vulnerabilities Technician school. I was all excited, so I went out and bought a copy of Hackers Exposed and read through the whole thing, learning everything from how to determine what family and version of operating system a computer is running by what ports are open, to how a buffer overflow attack actually works. Fast-forward to the class, and w…

Yeah, military schools on scientific/technological subjects can be very disappointing. Not all of them, obviously, but computer science topics get distilled down to be accessible to the bottom 20% of attendees. Having spent over a decade in the Marines, I learned not to get excited about anything like that... unless the schools were taught by civilians.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#54
post #47
post #35

Earlier quoted context omitted.

Hiring the hackers is a terrible idea. If they had done it ethically, yes. But do you really want to hire someone who has already displayed highly unethical behavior, and is likely a ticking timebomb? There are plenty of smart, ethical hackers out there.

I don't think you can draw those conclusion from the evidence presented. I would guess that quite a lot of the top white hat hackers today sharpened their skills early with some highly unethical behavior of their own. A good example of this would be how Chris Putnam got hired at Facebook. http://www.quora.com/How-did-Chris-Putnam-get-hired-at-Faceb...

Oh wow, I just realized that Chris Putnam is the same guy who used to post on the Something Awful forums back in 2003-2004 or so.

I remember him getting trolled out of there after showing any kind of ambition beyond posting on the forums. Same thing happened to the guy who started Imageshack (originally an image host for the SA forums), Eli Hodapp (who later became one of the main TouchArcade writers), and probably some others I don't remember.

Well dang, good for him!

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#56
post #15

Earlier quoted context omitted.

Your argument could also apply to the Linux kernel.

I know the point you're trying to make, but it's a weak one. 75% of the kernel is written by corporate employees. http://apcmag.com/linux-now-75-corporate.htm

75% of the kernel is written by corporate employees.

And that implies what about the kernel?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#57
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#58
post #56

Earlier quoted context omitted.

I know the point you're trying to make, but it's a weak one. 75% of the kernel is written by corporate employees. http://apcmag.com/linux-now-75-corporate.htm

75% of the kernel is written by corporate employees. And that implies what about the kernel?

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#59
post #15

Earlier quoted context omitted.

Your argument could also apply to the Linux kernel.

I know the point you're trying to make, but it's a weak one. 75% of the kernel is written by corporate employees. http://apcmag.com/linux-now-75-corporate.htm

I bet most contributors to php are corporate employees too

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#60
post #37

Earlier quoted context omitted.

And here's Elliot's "official statement": http://elliotspeck.com/phpfog.html And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161

As soon he says "I don't believe I did a bad thing" I thought this boy needs to be prosecuted.

Personally, I'm a fan of some of his post-hoc justification:

"Following this, I took a hold of their Twitter account and posted a couple of bits to draw attention to the fact. This did two things. One, it showed people the system was insecure, but on the other hand people always subconsciously root for the underdog; I drew attention to the company and the product. I know a number of people have actually registered (or intend to register, registration is closed) for phpFog since the incident thanks to the attention drawn to it by myself."

Post reply on HN