Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

151–160 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#151
Their response and abilty to turn the situation around is a case study in dealing with a difficult situation. Kudos! I'm saving their response and will use it when dealing with things. Being able to have a counter party to identify has definitely helped in handling the situation. I didn't realize how powerful that can be until I saw this, I learnt something new.

Its a brilliant piece and a great start/way to restore faith and recover from what must be a pretty grueling ordeal. Good job.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#152

Earlier quoted context omitted.

From the perspective of security protection, intrusions are an act of nature. You should be no more surprised at an especially strong wave than you are at an exceptionally immature child.

I don't think we're using the same definition of "act of nature": http://en.wikipedia.org/wiki/Act_of_God " Act of God is a legal term for events outside of human control, such as sudden floods or other natural disasters, for which no one can be held responsible " Do you think nobody can be held responsible for this breach?

Well, legally no - I think 16 year olds _aren't_ "held responsible" for pulling crap like this (rightly or wrongly).

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#153
post #113
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

  These are 16 year old kids, old enough to know right from
  wrong [..] 
These kids were being assholes, but that does not warrant federal charges. The problem is that we can choose between unsatisfactory public shaming or thoroughly ruining their lives. There is no middle way, where they get an appropriate punishment, fitting the damage done. If harsh punishments were a deterrent, these kids would already have been deterred, because there are plenty of examples of teenagers harshly punished for relatively minor computerrelated crimes. I'd rather see them grow up to become, probably average, members of society.

Also, whether they know right from wrong is a question whose answer definitely isn't as clear-cut as you make it out to be. There's a reason we don't consider them adults yet.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#154
Ugh, you shouldn't try writing an apology after not sleeping for days. Sleep on it first, always sleep on it. Talking about prosecution and explaining this with a framing that it was all a fluke caused by the only person who was silly enough to IM you with a confession... add one more person who will never be a customer of yours with an apology like that. Now I know you're irresponsible.

Seriously don't write official blog posts for your company while you're experiencing "I was just in the field for days trying to fix this stuff" emotions.

Calm down, then try and be graceful about the fact that you were hacked by a few clueless kids. (Clueful kids don't let you know who they are.) Then try and figure out how to protect yourself against people with a clue.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#155

Earlier quoted context omitted.

Of course. I guess I'm not clear what your point is though.

My point is that you must treat intrusions as an inevitability when trying to counteract intrusion. And anyone who builds a sandcastle should be aware of the ocean. The kid's breaking into this account is embarrassing. Just because we can hold individual humans accountable (and should) doesn't mean we shouldn't have the perspective of "CONSTANT VIGILANCE."

You seem to be implying that since PHPFog should have defending against this, that what the teenagers did is perfectly acceptable.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#156
post #43
post #38

The blog post is riddled with the words "luck" and "timing" which brings doubt into my mind that the team can actually take full responsibility for their actions. "aware of the potential security threat " but they left it for the next week, who honestly here would do that? I have also seen comments around the web of migrating to Php Fog because of how they handled the situation. If you are one of these people please…

Exactly. This post tries very hard to trivialize the security holes, and blame their problems on bad luck. They had problems because they decided not to fix glaring security holes immediately.

My understanding is that this is all caused by an unsecured failover server. Hopefully, we get a bit more details of how this came to be and learn what they intend to do with future server deployments.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#157

This feels like a business model where the lean/MVP approach isn't quite appropriate. A lot of things fall out of that decision, not the least of which is that the exposure surface area you get from an environment that allows user-sourced code on purpose is enormous. I feel for the guys going through this but there were a lot of errors in the wild all at once to allow this to happen.

IMO, in this sort of business it is important to define the right MVP.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#158
post #84
post #37

Earlier quoted context omitted.

And here's Elliot's "official statement": http://elliotspeck.com/phpfog.html And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161

Before I realized he'd posted those comments 2 days ago, I seriously considered trying to track down his parents. Do you think they even know? Their kid is arguing with people on message boards about a breach. And not arguing "I didn't do it". Crazy.

Search hard enough, and his phone number/address is available if you're really like to.

However, I won't post them here. That would be irresponsible disclosure. ;)

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#159
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

I didn't even make it through the headline before being concerned... particularly the part saying "Why it Will Never Happen Again".

I mean, yes, by all means implement measures to avoid this sort of thing from happening in the future but "It Will Never Happen Again" is a very, very bold statement on security. The kind I associate with people who still don't really "get it".

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#160
post #113
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

If the landlord leaves the master keys unprotected, he most definitely shares some of the blame when the apartments of his building are broken into.
Post reply on HN