Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

181–190 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#181
post #121
post #104

Earlier quoted context omitted.

>I fail to see you address the point that these kids caused harm to a business Very well. These kids caused harm to a business. So what's that change? The business screwed up, badly. The agent of destruction is quite irrelevant. Had it been a power failure, backup failure, permissions failure, data leak, or data corruption would PHPFog deserve any less blame? This need to shift some responsibility to a bunch of kids…

> This need to shift some responsibility to a bunch of kids is nauseating. They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it. Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to securi…

With security that lax at PHPFog, it was inevitable that someone would have broken in. In that sense PHPFog was lucky... had these security problems not come up now, and be exploited by little punks with no larger agenda than vandalism, there could have been much more more serious damage later. What if some cyber criminal gang had turned their attention to PHPFog, and been a bit more subtle about the breakin?

I was appalled at the frequent mentions of 'luck' in that blog post. Your job as a sysadmin is to eliminate luck. To eliminate chance. To make _sure_ everything stays running, everything stays secure, everything stays confidential.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#182
post #113
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

"you should never blame the victim of a crime just because the victim didn't take adequate steps to defend themselves."

This reasoning is not applicable when the victim is a corporation who gives implicit or explicit guarantees to their customers about security. Your example should be: if you stored your stuff at a paid storage facility and someone there accidentally left the door yo your unit open.

I wouldn't care if it's a bunch of teenagers or Chinese cyber-warfare team who breaks into my Gmail account, I'd be mad as hell with Google for letting this happen.

Pressing charges against the proprietors of the crime will not change the fact that this host acted in a very irresponsible and sloppy way, and is in short untrustworthy.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#183

Earlier quoted context omitted.

I'm now nearly 25, and the amount I have changed since I was 16 borders on the immeasurable. Teenagers are glorified children. We seem to forget how little reflective capacity we all had when we were teenagers. If I were 16 and hacking some stupid website, I would think, sure this is "wrong", and I might get in trouble, but I probably wouldn't think that it would matter 5 years from then, or 20. Truth is, a criminal…

So when they turn 21, a "be responsible" switch will magically flip in their minds? The job of parents and society is to teach children responsibility. That means having consequences for your actions. And the closer you get to adulthood, the more adult those consequences should get. When I was a teen, some real estate developers tore down a bunch of woods where I had always played and started building a house. I was…

What you're saying is fine. Its probably the better adult way to handle it - talk to the parents. Other people are suggesting FBI/Criminal law. How would you have fared/grown up if they sent you to court?

Do note that since he is tech oriented, he probably now knows what a S* storm he has kicked up - the blog response pretty much ensures that he is aware. I assume you would be sweating bricks if you knew that the FBI was coming after you AND that you had hand delivered a bullet point confession. I assume thats a pretty strong deterrent (in his specific case)

(Incidentally fighting to stick up for your woods was a kinda nice thing to do, modulo the amount of vandalism you pulled off.)

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#184
post #155

Earlier quoted context omitted.

My point is that you must treat intrusions as an inevitability when trying to counteract intrusion. And anyone who builds a sandcastle should be aware of the ocean. The kid's breaking into this account is embarrassing. Just because we can hold individual humans accountable (and should) doesn't mean we shouldn't have the perspective of "CONSTANT VIGILANCE."

You seem to be implying that since PHPFog should have defending against this, that what the teenagers did is perfectly acceptable.

I never claimed it was acceptable. Only that it was irrelevant. Why should anyone besides PHPFog's lawyer and the kids' parents care? It's because PHPFog chose to play PR guru and throw the drama into their postmortem as a distraction.

Does it matter to you if some kid in Australia is brought up on charges? No?

Does it matter to you if a hosting company is competent in securing their servers? Yes?

Any discussion of who did the hack servers no purpose other than to distract from the only issue that matters to anyone which is PHPFog's security.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#185
This post convinced me not to use PHPFog. They reveal more in their lack of foresight and security prevention measures than their response to what was otherwise a fairly trivial exploit. I am not sure this blog post was helpful in convincing customers like me that want to feel that their infrastructure providers are on top of things.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#186
post #42
post #22

Earlier quoted context omitted.

At the risk of that comment being taken as a joke, I've done a lot of work with the federal government, and I can assure you that while the level of hilarity that HBGary has generated, the typical level of talent in government cleared individuals is not necessarily great. I don't mean to impune the capabilities of the people involved (I don't know who they are,) and it isn't to say that you can't find some AMAZING ta…

Reminds me of when I was in the Navy and I went to Navy Security and Vulnerabilities Technician school. I was all excited, so I went out and bought a copy of Hackers Exposed and read through the whole thing, learning everything from how to determine what family and version of operating system a computer is running by what ports are open, to how a buffer overflow attack actually works. Fast-forward to the class, and w…

Hacking Exposed: http://www.amazon.com/dp/0072121270

Armadillo book: http://www.amazon.com/dp/0596003439

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#187
post #113
post #81

Earlier quoted context omitted.

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

This isn't a wave knocking over a sandcastle or a dog shitting in the house. These are 16 year old kids, old enough to know right from wrong, and with the knowledge and skills to exploit the system. And once the exploit worked, they didn't then responsibly disclose the problem to PHPFog; they started vandalizing, changing passwords, and the works. This is like someone finding an unlocked door to the apartment buildin…

I really like the unlocked door analogy, but there seems to be some kind of disconnect in everyone's mind when it comes to "online" crimes.

Door locks are extremely "exploitable", but if a 16 year old were to use a bump key to gain access to PHPFog's corporate office and vandalize the place, all of the sudden it's a much bigger deal.

I have a theory that it has to do with familiarity and empathy. Door locks are a pretty standard solution. We all have them on our homes, and we think to ourselves, "I've done a reasonable job of securing my home." When someone's home/office is broken in to, we can easily identify with them. We look at the scenario and realize that we could easily suffer the same. We empathize with them.

Move the playing field to the Internet and all of the sudden everyone is expected to have Fort Knox level security. When someone's infrastructure is compromised, everyone stands atop the high hill, looking down on the drowning masses as the tide comes in, but the reality is that we're all vulnerable at some point.

A startup could easily spend as much on security as they do developing their core product. Why? As a startup, I'm not going to invest in double-reinforced steel doors, bullet proof glass windows, armed guards, and a centralized vault. That's wasted money in my view, because I have a reasonable expectation that people will act with civility. If someone does break in, I'm insured, and I will report the crime to authorities who will investigate. If the criminal is caught, there are real penalties, and they'll carry the stigma of having to check "YES" next to the "Have you ever been convicted of a felony" on their job applications.

I'm not saying we should try these kids as adults, but when I was 14, some kids who shared a bus stop with me broke in to a house near our bus stop and trashed the place. They got caught and suffered some severe penalties. It was a valuable lesson for everyone involved. A couple of the kids were from really bad homes and suffered from greater influences than the threat of the law, but the other two turned their act around really quickly. Had they gotten away with it, or had the attitude been "they're just kids", I'm not sure they would have realized the impact of the crimes they committed. I think we need more of this balance in our views of internet crimes.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#188
post #81

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

Maybe then they'll stop with the half-assed apologies and recognize that there's a right way and a wrong way to do things. PHPFog built a castle out of sand and you're upset that a wave came and demolished it. I'm always surprised at how thin-skinned a lot of HN commentary is. "Oh, Zed shouldn't be so rude" "These kids' lives should be destroyed for playing games with an wholly insecure website." "I stopped reading t…

If you were walking down the street and my 9-year-old daughter were to run up to you and stab you in the eye, is it your fault for not wearing a helmet? Everything is penetrable given enough time, money and patience. I agree that PHPFog made some mistakes, but it's not like they were being willfully negligent.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#189
post #70
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

They seemed to be blaming it on "bad timing" as if these things were ever excusable. These are also things that you either do or don't do. Your systems are either secure or they're not. "They were going to be secure tomorrow" does no one any good. It doesn't look like any of the parties involved learned much of anything from this episode.

> Your systems are either secure or they're not.

[citation needed]. Security is never binary. No matter what security measures you take, there are always zero-day exploits, social engineering, physical access, heavily-researched-and-highly-targeted attack vectors, etc.

Security is the opposite of convenience and accessibility. The right thing to do is to analyze what you are trying to secure and ensure an appropriate level of security proportional to the sensitivity and business impact of the potentially-exposed system.

There's no such thing as "secure." It's a continuum and it's always a tradeoff. Would you spend $5000 to protect something that's worth $50? It sounds like this site was in beta mode, and they made an understandable decision to focus on building the product and growing a customer base in lieu of ensuring top-notch security. In retrospect it was the wrong decision, but you don't hear about the companies who follow this approach and don't get publicly hacked. If they spent all their time on security from the outset, they wouldn't have anything to protect.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#190
There is no such thing as bad publicity! Kudo's for turning lemons into a viral blog post! Although, if I understand correctly, you were reusing passwords and storing them in plain text! This is an ABC123 computer security nono. Thank goodness it was just some young script kiddies and not someone with malicious intent!
Post reply on HN