Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

101–110 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#101
post #86

Earlier quoted context omitted.

Just, do be aware that there are a lot of people that fit the description he gave; they are particularly numerous among the people who use the words "white hat" or "hacker" (with any modifier) in their services.

Downvotes because of phrasing? Here. So called 'white hat hackers' tend to be fraudulent script kiddies who couldn't hack their way out of a gibs0n. They often attend classes like this http://www.infosecinstitute.com/blog/ethical_hacking_compute... and read a book or two like this http://www.google.com/products/catalog?q=hacking+exposed&#38... . Some times they'll even have a sweet certification like this https://www…

Thanks for rephrasing. It really does make a difference. I actually got some value out of this comment, whereas from your previous comment I got none.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#102
post #99

Earlier quoted context omitted.

> PHPFog built a castle out of sand and you're upset that a wave came and demolished it. Technology analogies invariably suck, but I'm pretty sure this is provably better: When a teenager smashes in a storefront window, do we say they should've had bars over it?

The major problem with your analogy is that storefront windows don't have hundred or thousands of bricks thrown at them everyday. Web hosts are basically under constant attack. Would you suggest that the CIA, NSA, etc. not worry too much about their computer security? If not, then I don't see why you would imply a web host shouldn't be expected to secure their servers as much as possible either. If a storefront was u…

I think you're missing the point of the analogy. Check out http://en.wikipedia.org/w/index.php?title=Victim_blaming&#38...

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#103
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

Security has nothing to do with feelings. Given the amount of should-haves in their explanation this should be a welcome wake-up call to them, a free audit. Other than playing the victim card, they handled it quite well.

Nothing better to sharpen your skills and higher your standards than a _good crisis_

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#104
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

I'm sorry, but in between your Straw Man argument and your indirect Ad Hominem attack, I fail to see you address the point that these kids caused harm to a business. Nowhere did I say that PHPFog bears no responsibility for the security of their service, but that doesn't excuse what these kids did one bit. I'm just much more impressed with the way that PHPFog is handling their business after the fact than these kids…

>I fail to see you address the point that these kids caused harm to a business

Very well. These kids caused harm to a business. So what's that change? The business screwed up, badly. The agent of destruction is quite irrelevant. Had it been a power failure, backup failure, permissions failure, data leak, or data corruption would PHPFog deserve any less blame? This need to shift some responsibility to a bunch of kids is nauseating.

>I'm just much more impressed with the way that PHPFog is handling their business after the fact than these kids are.

This is another example of the weird HN mentality when it comes to companies "apologizing" (Like WakeMate blaming their Chinese manufacturer for flunky power supplies). Are you actually impressed that a corporation has better PR than a bunch of children? Does that even make sense to you? I'd be impressed if they had managed to actually apologize while accepting all the blame without trying to pawn off the responsibility for their mistakes on some kids.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#105
post #99

Earlier quoted context omitted.

The major problem with your analogy is that storefront windows don't have hundred or thousands of bricks thrown at them everyday. Web hosts are basically under constant attack. Would you suggest that the CIA, NSA, etc. not worry too much about their computer security? If not, then I don't see why you would imply a web host shouldn't be expected to secure their servers as much as possible either. If a storefront was u…

I think you're missing the point of the analogy. Check out http://en.wikipedia.org/w/index.php?title=Victim_blaming&#38...

Let's not forget that the victim here is PHPFog's (potential) customers and not PHPFog itself.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#107
post #105

Earlier quoted context omitted.

I think you're missing the point of the analogy. Check out http://en.wikipedia.org/w/index.php?title=Victim_blaming&#38...

Let's not forget that the victim here is PHPFog's (potential) customers and not PHPFog itself.

I can agree with you that PHP Fog's customers were affected and are thus victims. I don't understand how PHP Fog isn't a victim here though.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#108
post #83
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

" PHPFog built a castle out of sand and you're upset that a wave came and demolished it. " Your analogy is slightly off. A wave is an act of nature: this is more along the lines of a jealous kid who knocks down someone else's sandcastle because he can't build his own. " I don't get angry at my dog when he shits in the house. Being angry at something that can't understand only satisfies the urge to shift blame. " Whil…

From the perspective of security protection, intrusions are an act of nature. You should be no more surprised at an especially strong wave than you are at an exceptionally immature child.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#109
post #83

Earlier quoted context omitted.

" PHPFog built a castle out of sand and you're upset that a wave came and demolished it. " Your analogy is slightly off. A wave is an act of nature: this is more along the lines of a jealous kid who knocks down someone else's sandcastle because he can't build his own. " I don't get angry at my dog when he shits in the house. Being angry at something that can't understand only satisfies the urge to shift blame. " Whil…

From the perspective of security protection, intrusions are an act of nature. You should be no more surprised at an especially strong wave than you are at an exceptionally immature child.

I don't think we're using the same definition of "act of nature":

http://en.wikipedia.org/wiki/Act_of_God

"Act of God is a legal term for events outside of human control, such as sudden floods or other natural disasters, for which no one can be held responsible"

Do you think nobody can be held responsible for this breach?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#110
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

The problem with pressing charges as a detterrent is that it is fundamentally unjust, because the punishment is set up as a detterrent and is disproportionate to the crime.

Example: imagine the country of Dictatoria where if you jaywalk you are publicly tortured for a couple of weeks and then put to death. "As a detterrent"

A little extreme? Well, consider the 10-20 (or more) year sentences for cyber-terrorism these teenagers are going to get if the FBI throws the book at them.

That kind of law enforcement agency doesn't understand the concept of restraint - they are set up to go for the kill, for the maximum charge, for the maximum sentence every time.

You can lay charges thinking to give them a slap on the wrist, but the steam roller that gets set in motion is designed to crush them flat with no mercy.

Post reply on HN