Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

171–180 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#171
post #113

Earlier quoted context omitted.

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

I'm now nearly 25, and the amount I have changed since I was 16 borders on the immeasurable. Teenagers are glorified children. We seem to forget how little reflective capacity we all had when we were teenagers. If I were 16 and hacking some stupid website, I would think, sure this is "wrong", and I might get in trouble, but I probably wouldn't think that it would matter 5 years from then, or 20. Truth is, a criminal…

I see your point, but not all teenages would do this even if they thought they would not get caught.

While I agree that the full force of adult law is probably inappropriate, some punishment should be exacted. Perhaps some sort of injunction regarding limited access to the Internet for a time (to be enforced by their parents, and to include replaying any fancy 'net capable phones with a good old not-even-got-GRPS mini-brick phone for the duration).

If I left my front door open and some kids came in, raided the fridge, broke the TV and ran up a huge phone bill, I would not expect them to get away completely unpunished. I'd not want them put away, and I wouldn't want it on their permanent record unless something particularly immoral was done (harming the cat, for instance), but I would want something to be seen to be done to educate them on right/wrong and act as a deterrent to others. I would also expect to be laughed at for being daft enough to leave my front door open!

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#172
Congratulations to PHPFog. They've managed to direct the attention to the 16 year old kids rather than their own incompetence.

Is it me or no one mentions the lack of expertise of the PHPFog team in PHP and Systems Administrations.

Sure kids broke in and the way they published their findings was despicable. The fact remains that PHPFog was utterly broken to pieces and the exact essence of the problem is simply the lack of knowledge in their field.

I am very disappointed by the tone of the blog post and think PHPFog don't really have a notion of what they are doing. I would much rather seem them where they belong, in the Ruby world where their experience is.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#173
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

I didn't even make it through the headline before being concerned... particularly the part saying "Why it Will Never Happen Again". I mean, yes, by all means implement measures to avoid this sort of thing from happening in the future but "It Will Never Happen Again" is a very, very bold statement on security. The kind I associate with people who still don't really "get it".

If I was a customer of theirs, I wouldn't have really been (too) bothered about the initial intrusion. However, hearing them say "Why it will never happen again" would make me switch providers. In my mind being willing to say "it will never happen again" implies a basic misunderstanding of the security environment and is tantamount to a guarantee that it will, in fact, happen again - perhaps even regularly.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#174
post #37

Earlier quoted context omitted.

And here's Elliot's "official statement": http://elliotspeck.com/phpfog.html And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161

Hi, I'm ! My site says what city I'm from. I've written publicly to admit that I committed multiple crimes, definitely without consulting legal counsel first! I even put them in a nice bulleted list that can be copied and pasted right into a complaint. They're pressing charges, but that's bullshit. I'm 16! Not too bright, are we? Instant message the company you just hacked and bust out from behind your handle, then p…

Somebody really needs to get in touch with that kid's parents and let them know that they need to find the mute button on their kid and retain counsel.

After reading that I think it's a pretty strong argument against those claiming adult status for him. He clearly doesn't understand the situation he's in or the second order impacts of what he's done.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#175
post #113
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

While there's a lot of emotional appeal to seeking justice in this case, my inner pragmatists says that this should really be looked at as free penetration testing for PhPFog. If this kind of hacking had stiff penalties (as you desire), only those with truly malicious intent (and probably financial motive) would do it. Likewise, the consequences wouldn't be some petty vandalism, but serious financial damage.

The fact remains that the site was insecure enough for a 16-year-old to find his way in. And the contributing factors to this insecurity might not have been identified had he not performed the attack in the first place.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#176

Earlier quoted context omitted.

Hire the hackers. It's what the CIA would do.

Or do like the FBI and offer them a job, when they come for the interview they get frogmarched into the police cruiser.

Valve did that, the FBI was just the tool that was used for the job.

I'm struck by the similarity in some respects of the two cases. I would guess that the same people that got really upset about Valve doing that would be a bit saddened by this, too.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#177
post #113

Earlier quoted context omitted.

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

I'm now nearly 25, and the amount I have changed since I was 16 borders on the immeasurable. Teenagers are glorified children. We seem to forget how little reflective capacity we all had when we were teenagers. If I were 16 and hacking some stupid website, I would think, sure this is "wrong", and I might get in trouble, but I probably wouldn't think that it would matter 5 years from then, or 20. Truth is, a criminal…

So when they turn 21, a "be responsible" switch will magically flip in their minds?

The job of parents and society is to teach children responsibility. That means having consequences for your actions. And the closer you get to adulthood, the more adult those consequences should get.

When I was a teen, some real estate developers tore down a bunch of woods where I had always played and started building a house. I was ticked and I vandalized the construction site. But my crime was discovered, and I had to work carrying lumber in the hot sun and scraping glue off windows to pay back the damage. Why did I have to do this? Because the developer talked to my parents. And my parents made me do it.

This was light punishment - I wasn't taken to court, and I didn't get a criminal record. But parents are to children as legal system is to adults: they set the rules and enact the punishments. If they don't, someday the legal system will have to address their failure to do so by locking up their grown children who never learned right from wrong.

I'm not sure what the consequences here should be, but the argument "they're kids, they can't be held responsible" is silly. If they're not expected to be responsible, they won't learn to be responsible.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#178
post #81

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

Wow, never seen condescension clothed so well before. You should realize that by saying "PHPFog is the only responsible party", you are open to some perverse accusations (like, if your kid turns out to be a criminal, you and the victims are completely to blame).

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#179
post #95

Earlier quoted context omitted.

I read him being very apologetic for their security shortcomings in all of the appropriate places, and only blaming delayed fixes on timing issues. He was very contrite and forthcoming about their security issues. Accountability was all over the article.

I disagree. Lucas names these children and attempts to personify them so blame can be shifted to the "bad guys" rather than his company. Lucas's post does not say "We screwed up." He says "We got screwed by Elliot." I'm saddened most because Lucas is not embarrassed to point out he was outwitted by children. When I foul up at my job I don't send an email detailing how some nasty client did something. I summarize what…

Did you read the article?

Lucas's post says: "This was really naive and irresponsible of me." That doesn't sound like he's shifting blame to me.

You say: "I summarize what went wrong, how it should have been prevented and what steps I will be taking to prevent it in the future."

The article is essentially just that, with one exception; they didn't list steps they "will be taking" to prevent it, they listed steps they have already taken in the last 3 days.

As for Credit Card: "Credit cards – We have never stored credit cards on any PHP Fog server. There was never any possibility that credit cards could have been compromised by this attack."

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#180
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

i felt they apologized rather well. its difficult to apologize and explain what happened at the same time without sounding like you're making excuses or trying to skirt responsibility.
Post reply on HN