Live data from Hacker News

LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

gamepro.com

91–100 of 113 posts

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#91
post #81

Earlier quoted context omitted.

Was Tor actually invented by the NSA? I didn't manage to find any sources for that, could you provide one?

Not the NSA, it came from the Navy. See here: http://www.onion-router.net/

Hmm, is the NSA a division of the Navy?

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#92
post #55
post #28

Earlier quoted context omitted.

These attacks are annoying and damaging but in the long run they make our internet stronger. If these didn't happen so often people would care a lot less about security and robustness.

Sure, and I can go around punching people in the face and tell 'em that I'm doing 'em a favour by reminding them to always wear a full-face helmet when out in public. But if nobody except me is a big enough asshole to go round punching people in the face at random...

you are ignoring the fact that China (a powerful recent player in math and physics), Russia (long time math and physics powerhouse), or any number of criminal elements have known about these security problems and have possibly been taking full advantage of them for some time, just skipping the publicity bit. LulzSec is, among other things, shaming the companies into tightening up.

Red teaming is a good thing.

Edit: to be clear, I agree there's no red-team value in DDOS. Though some have ascribed a "sit-in" utility to DDOS in certain circumstances (eg: Anonymous vs MasterCard after Wikileaks broke CableGate).

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#93
post #56
post #51

Earlier quoted context omitted.

Let's phrase this in another hyperbole, shall we? Should you rob every bank that doesn't have an alarm or leaves the vault open? No. But if a lot of banks had no policies in place to prevent those things from occurring, would you feel more secure that someone was walking into the bank, taking photos of their break-in, and not stealing the money? I don't agree with their means (it's wrong, IMO, to mess with any machin…

But if these are just DDOSes, then (a) there's no way to steal sensitive information that way, and (b) there's no real defence against 'em anyway. So this particular argument is pointless, right? There's an argument for whiteish-hat intrusions, but DDOSes must be intrinsically black-hat, right?

>DDOSes must be intrinsically black-hat, right?

No. While I agree there's no red-team contribution in a DDOS, quite a few people regarded Anonymous DDOSes on Wikileaks detractors (MasterCard, et al) as the digital equivalent of a sit-in. That seems a bit of a stretch to me also, but certainly there's some application of DDOS that's not purely black-hat.

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#94
post #6

Earlier quoted context omitted.

Not to be too cheezy, but i'd like to quote The Dark Knight here: "Some men just want to watch the world burn."

Valid point and a great quote. It's just hard to believe such people exist outside the realm of comic books.

There's something that's just...well, for lack of a better word, special, about being the on the same playing field as everyone else, but working under a completely different set of rules and deciding for yourself how the game is scored.

The best example I can give is how my brother used to grief Counterstrike on TK-enabled servers - he didn't do this by killing his own teammates, or by cheating against the other team. Rather, he would lure his teammates into killing him often enough that they got auto-banned from the server; his rationale was that everyone was too freaking good at CS anyways, might as well make the game more interesting and difficult for himself, at least. :)

When you decide for yourself which game you're actually playing, sometimes the lulz are just too tasty to resist...

That said, DDoSing a bunch of game servers for games that are completely unrelated and haven't done anything in particular worthy of retaliation is moronic. There's no poetry there, just a bunch of children playing around with the 2011 equivalent of AOHell (and yes, I realize that most of them are probably to young to even know WTF I'm talking about).

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#95
post #23

Earlier quoted context omitted.

What's to stop you? the government making it illegal to run hacking tools like "tor" (see the silk road/bitcoin post on HN from earlier) etc illegal and forcing your ISP to record any use of such and block you off the internet (see france's 3 strikes, you as a person are not allowed on the internet law) and report you and then possibly criminally prosecute you as well.

What you're suggesting is impossible. >the government making it illegal to run hacking tools like "tor" Do you think that there is nothing illegal that happens on the internet now ? How long was it illegal to export encryption? How many people actually cared? >forcing your ISP to record any use of such and block you off the internet The encryption standards that we all use are the same encryption standards that are r…

> Tor was invented by the NSA

Actually, Paul Syverson, Roger Dingledine, and Nick Mathewson orginated Tor, and Dr Syverson did the original onion routing work at the Naval Research Lab.

https://www.torproject.org/about/corepeople.html.en

I don't recall seeing "NSA" anywhere on any their resumes, in their papers, etc.

Syverson has made it pretty clear Tor is not so good for serious security, eg, trying to evade nation-states. Evading nation-states is what PGP is for. Fundamentally, if you want a pizza, the pizza delivery guy has to know your address, no matter how many intermediate stops he makes. Also, have you used Tor? Speed is a major issue.

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#98
post #33

Earlier quoted context omitted.

The attacks on the Minecraft and EVE servers were DDOS attacks. Nothing sophisticated, and the easy way to avoid them is to just get more servers, which really isn't a good solution for smaller developers. EDIT: I suspect the only reason they didn't succeed getting to Blizzard is because WoW was down for Tuesday maintenance.

I suspect the reason is simply because they don't have the resources. EVE maxes out at about 35-40k simultaneous connections, WoW is probably closer to 400-500k per region. edit - # of accounts is 360k vs 12mil.

They targeted the EVE login server however, and I doubt that is designed for 35-40k simultaneous connections, as to acomplish those conditions, all users on the server would need to log in at the same time. The same is probabaly true for WoW.

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#99

Earlier quoted context omitted.

I suspect the reason is simply because they don't have the resources. EVE maxes out at about 35-40k simultaneous connections, WoW is probably closer to 400-500k per region. edit - # of accounts is 360k vs 12mil.

They targeted the EVE login server however, and I doubt that is designed for 35-40k simultaneous connections, as to acomplish those conditions, all users on the server would need to log in at the same time. The same is probabaly true for WoW.

The login server for WoW easily and routinely handles an incredible number of simultaneous connections as huge percentages of the player base attempt to log in at the same time, particularly after a large patch. There used to be incredible issues with the login server, but these days Blizzard is an extremely tightly run ship. They know where their money comes from, and what it takes to protect the cash flow.

Re: LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers

#100

Earlier quoted context omitted.

I think it's dismissive to jump to that conclusion - they're likely turning a healthy profit by dumping lists of emails, credit card numbers, and zero-day vulnerabilities on the black market.

If they wanted to do that, then I don' think they would announce it. Offering someone a bunch of private data, 0 days, credit card info, but then making it useless in a few hours because you announce it to the world, hardly seems like a viable/profitable business.

That works under the assumption that they release everything, when they have explicitly said that they do not.

Specifically - information gained in the Bethesda http://pastebin.com/i5M0LB58 and whitehat http://pastebin.com/MQG0a130 raids has not been released.

Post reply on HN