Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

111–120 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#111
post #82

Earlier quoted context omitted.

I downvoted this too, but wish I hadn't. He has a point.

He could have made his point in a more intelligent way.

You're judging a point by the way it was made rather than its ultimate goal?

I mean, I'm all for praising gymnastics, but if we're trying for truth here shouldn't endgame be valued over execution?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#112
post #105

Earlier quoted context omitted.

Let's not forget that the victim here is PHPFog's (potential) customers and not PHPFog itself.

I can agree with you that PHP Fog's customers were affected and are thus victims. I don't understand how PHP Fog isn't a victim here though.

I promised myself I'd avoid another analogy but...

If I give the bank my money and the next day I get an email saying "Sorry, we didn't feel like locking up last night and some kids looted the vault." I'd have a hard time calling the bank the victim.

And something concrete: PHPFog knew the holes existed and were negligent. I would say they even have some contributory negligence (IANAL). Especially after admitting they knew they were vulnerable.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#113
post #81

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works.

This is like someone finding an unlocked door to the apartment building's maintenance office, taking the master keys from there, rifling through a bunch of people's personal belongings, sticking signs in the windows saying "this building's landlords suck," and changing the locks on some of the doors to make it hard to clean up the whole mess.

They absolutely are the responsible party; you should never blame the victim of a crime just because the victim didn't take adequate steps to defend themselves. If I accidentally leave my door unlocked one day, that does not make it suddenly OK to come in and take my stuff and it's my fault for not having locked my door, instead of yours for taking my stuff.

Now, in this case PHPFog does bear some responsibility, because they have a duty to protect their customers as well as possible, and from reading about how this happened, it sounds like they were amazingly sloppy and irresponsible about it (passwords stored in the clear on the server, passwords shared between various accounts, leaving unsecured shared systems running after beta launch, etc). But that doesn't reduce the culpability of the attackers; they acted maliciously, with full knowledge of what they were doing, vandalized systems, changed passwords, and bragged about it.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#114
post #21

I mentioned this last time, but I don't think anyone was interested, but the "John" guy is compwhizii (same handle on Twitter) who runs the forums (facepunch.com) for garrysmod, a very popular game. I will be curious to see how garry (owner person) responds to this, or if he already has. Elliot is apparently VERY scared and blames John (compwhizii) (edit: not john, he blames someone else called supersnail1): http://w…

Reading through those forum posts, I have less and less sympathy for these guys.

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#115
Wow, that is quite the list of security measures that they had almost but not completely/correctly implemented, or hadn't got around to yet.

I guess the real moral of the story is to finish what you begin, or don't keep putting security off until it is convenient for you.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#116

Earlier quoted context omitted.

From the perspective of security protection, intrusions are an act of nature. You should be no more surprised at an especially strong wave than you are at an exceptionally immature child.

I don't think we're using the same definition of "act of nature": http://en.wikipedia.org/wiki/Act_of_God " Act of God is a legal term for events outside of human control, such as sudden floods or other natural disasters, for which no one can be held responsible " Do you think nobody can be held responsible for this breach?

You're right, we're not using the same definition. That doesn't mean I don't have a point.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#117
post #33
post #20

Never? I would be cautious about issuing a challenge like that.

They might still have a security hole big enough to drive a freight train through, but that specific attack will never happen again given that they've shut down the shared failover server.

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#118
post #112

Earlier quoted context omitted.

I can agree with you that PHP Fog's customers were affected and are thus victims. I don't understand how PHP Fog isn't a victim here though.

I promised myself I'd avoid another analogy but... If I give the bank my money and the next day I get an email saying "Sorry, we didn't feel like locking up last night and some kids looted the vault." I'd have a hard time calling the bank the victim. And something concrete: PHPFog knew the holes existed and were negligent. I would say they even have some contributory negligence (IANAL). Especially after admitting the…

You know what we call kids who loot bank vaults? Bank robbers.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#119
post #112

Earlier quoted context omitted.

I promised myself I'd avoid another analogy but... If I give the bank my money and the next day I get an email saying "Sorry, we didn't feel like locking up last night and some kids looted the vault." I'd have a hard time calling the bank the victim. And something concrete: PHPFog knew the holes existed and were negligent. I would say they even have some contributory negligence (IANAL). Especially after admitting the…

You know what we call kids who loot bank vaults? Bank robbers.

No, we call them juvenile delinquents and treat them like children.

And we certainly don't call the bank the victim.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#120

Earlier quoted context omitted.

I don't think we're using the same definition of "act of nature": http://en.wikipedia.org/wiki/Act_of_God " Act of God is a legal term for events outside of human control, such as sudden floods or other natural disasters, for which no one can be held responsible " Do you think nobody can be held responsible for this breach?

You're right, we're not using the same definition. That doesn't mean I don't have a point.

Of course. I guess I'm not clear what your point is though.
Post reply on HN