Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

141–150 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#141
post #38

The blog post is riddled with the words "luck" and "timing" which brings doubt into my mind that the team can actually take full responsibility for their actions. "aware of the potential security threat " but they left it for the next week, who honestly here would do that? I have also seen comments around the web of migrating to Php Fog because of how they handled the situation. If you are one of these people please…

  "aware of the potential security threat " but they left it
  for the next week, who honestly here would do that?
Just about everyone. There are always 'potential security threats' that are deemed unlikely to be exploited and that you therefore do not give priority above the multitude of other tasks you have to do. They took a chance and I don't doubt everyone here does that on occasion.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#142

> Eliminate shared hosting failover server – We may never do shared hosting failover again if we can not guarantee its security. We might do a non-realtime failover to automatically launch a new instance for you, but this experience taught us what a bad idea this can be. What does realtime mean in this case? Anyway, this isn't the only option. They could keep a few bare instances of their php stack online and simply…

Realtime means a request in flight is retried if there's a failure. Said a different way, the load balancer already knows about a spare at all times. This is compared to a ~5 minute downtime if spawning a replacement EC2 instance is required.

Nice idea on the hot spare instances however.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#143
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

He is 16 and SCARED. What do you expect? A slick PR campaign? Heck in some other countries, kids aren't even considered adults at that age.

He is naive and immature and realizes what he did is wrong. To make amends, in true 16 year old fashion, he gives a bullet list of errors to try and help undo the damage.

For his inability to communicate, show restraint, maturity, planning and foresight, for the very crime of being young and immature, he gets people wanting to throw the book at him? In that case, can we please, pretty please, torch wall street?

Its quite likely that he realizes that giving an error list is BAD and STUPID, and now is trying to back pedal by putting on a brave face to ignore the bone headed-ness of his (compounding) mistakes.

Try and imagine exactly how YOU would feel if you had a huge amorphous mob saying "The FBI should come for you"? At 16 you have NO scale in your head to cope with that.

Restraint is (one of) the hallmarks of maturity. As is intelligence and not taking good faith for granted - like not sending a list of errors you can be prosecuted for.

Here is what I would do - call this kid parents and Leave it at that. Let the family know how close he is to being in BIG trouble. If you want to do one better, give him a constructive outlet. He is already probably one very, very, very, miserable and frightened kid right now. And he should be.

Its called grace forgiveness and wisdom. As adults, we are supposed to have it. You are NEVER going to deter kids from being kids. So you need to ensure that they are scared and know where the line is drawn, so that they can become effective productive Adults.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#144
post #99

Earlier quoted context omitted.

The major problem with your analogy is that storefront windows don't have hundred or thousands of bricks thrown at them everyday. Web hosts are basically under constant attack. Would you suggest that the CIA, NSA, etc. not worry too much about their computer security? If not, then I don't see why you would imply a web host shouldn't be expected to secure their servers as much as possible either. If a storefront was u…

I think you're missing the point of the analogy. Check out http://en.wikipedia.org/w/index.php?title=Victim_blaming&#38...

I'm well aware of victim blaming, but sometimes it's justified. If someone hacked into your bank account and stole your money because of a security flaw your bank decided to put off until later, surely you would lay blame on your bank as well, no?

Let me be perfectly clear, lots of the blame lies with that attacker. But it is also the responsibility of the a web host to fortify their systems sufficiently, which clearly wasn't done in this case.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#145
post #128

Earlier quoted context omitted.

Why do you think these kids would get 10-20 year sentences? Have you ever heard of a computer crime getting that high of a sentence? No one on http://en.wikipedia.org/wiki/List_of_convicted_computer_crim... has gotten more than 5 years, and they include people who have sold access to botnets of hundreds of thousands of machines. A quick Google search reveals someone sentenced to 20 years, but for stealing millions of…

There is a story along these lines, it happened recently in New Zealand. Some parents had an argument with their teenage son, and he went off in a huff taking the family car (technically without asking permission). His parents thought to themselves "I know, we'll teach him a lesson", so they reported the car stolen. They intended to later on drop the charges (which would have royally peeved the police, making a false…

Sounds like you're talking about Liam Ashley but have some of the facts twisted:

* it wasn't recent (2006)

* he was sent to prison because his parents denied bail, not because GTA is some heinous crime in NZ

http://en.wikipedia.org/wiki/Murder_of_Liam_Ashley

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#146
post #112

Earlier quoted context omitted.

I promised myself I'd avoid another analogy but... If I give the bank my money and the next day I get an email saying "Sorry, we didn't feel like locking up last night and some kids looted the vault." I'd have a hard time calling the bank the victim. And something concrete: PHPFog knew the holes existed and were negligent. I would say they even have some contributory negligence (IANAL). Especially after admitting the…

You know what we call kids who loot bank vaults? Bank robbers.

You know what we call banks who leave their vaults unsecured? Neither do I, but it's certainly not 'blameless'.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#147
post #119

Earlier quoted context omitted.

No, we call them juvenile delinquents and treat them like children. And we certainly don't call the bank the victim.

1. We don't treat them like adult criminals (necessarily), but we certainly treat them like criminals. Here are some examples (some harsher than others): Bank robber, 13, could get 21 years in US jail ( http://www.breitbart.com/article.php?id=CNG.cb17379375828ffc... ) Teen bank robber to be held for two years ( http://www.morningjournal.com/articles/2011/02/18/news/doc4d... ) Boy, 15, Charged in Armed Bank Robbery in…

Banks are absolutely considered victims, but if the victim didn't do their due diligence with respect to keeping their vault secure, then they absolutely share in the blame.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#148
post #137
post #134

Earlier quoted context omitted.

No, they are mentioned because they are the criminals who intruded and vandalized the system! Without them, none of this would have happened. There's no shifting of responsibility, since the kids who vandalized their system are responsible for their vandalism. I can't honestly imagine what kind of moral system you have in which you don't believe that criminals are responsible for their own actions. If someone breaks…

> No, they are mentioned because they are the criminals who intruded and vandalized the system! "They" are not relevant in any way! "They" are tabloid meat for an internet drama. "They" are a distraction from the fact that a hosting company had piss poor security surrounding the core product. The entire story could be told without mentioning the hackers by name, or providing any biographical information. The only rea…

Agree - creating a tangible identity to the villain is pulling heat off of PHPFrog.

Lets put it this way - a 16 year old kid who got lucky broke their site.

If it was anyone with intent, we would not know.

This is a case study in how to handle a situation like this. Its brilliantly done, inclusive of the comment where he says "the community is standing by us".

Its actually a brilliant brilliant PR piece.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#149

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

I know, they acted as if they could get away with it by apologising. However, whatever you think of PHPFog, a lot of people have invested everything they have in that project, and it could have (and still could have) done irreperable damage to their reputation and investment. Big companies can tank this crap but attacking a new startup is like punching a child.

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#150

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

He is 16 and SCARED. What do you expect? A slick PR campaign? Heck in some other countries, kids aren't even considered adults at that age. He is naive and immature and realizes what he did is wrong. To make amends, in true 16 year old fashion, he gives a bullet list of errors to try and help undo the damage. For his inability to communicate, show restraint, maturity, planning and foresight, for the very crime of bei…

Bah! Tomahawk 'em!
Post reply on HN