Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

1–10 of 195 posts

Re: LulzSec: Why we do what we do

#2
Might want to change the title to something like "LulzSec actually had a point after all." They do, too, an even better one than I expected. Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero.

Re: LulzSec: Why we do what we do

#4
They seem somewhat clueless..

If the NSA can partner with ISPs to scan internet traffic for phishing, viruses, etc ...the obvious next step is Lulzsec mentions or member mentions...in IRC, email, etc..

There is no such thing as hiding when attacking the internet, sooner or later you become the bitch

Re: LulzSec: Why we do what we do

#5
I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private.

What I don't agree with is their use of DDoS attacks against sites like cia.gov.

DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections.

Sites should deploy onto an infrastructure they feel is adequate to deal with the expected load plus some additional room for growth and spikes.

I'm sure the cia.gov doesn't get hit very hard on a normal day so they didn't go crazy on infrastructure which is understandable. A DDoS proves nothing and prevents people from accessing data.

If you're going to hack, please wear a white or grey hat.

Re: LulzSec: Why we do what we do

#6
>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled.

This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do.

I don't really know what to make of it.

Re: LulzSec: Why we do what we do

#7

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

When Anonymous attacked Visa and Mastercard via DDoS (in retaliation to them cutting off Wikileaks donations), Anonymous did actually succeed in stopping the online verification systems for both companies (SecureCode, or something, and Verified by Visa). In that case, the DDoS attacks did more than just take the site down; they financially hurt their target, which was probably the aim to begin with.

I'm not justifying the attacks and I agree that they are the wrong way to go about this business, but it would be naive to suggest that the DDoS attacks are a minor inconvenience.

Re: LulzSec: Why we do what we do

#8

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

But clearly that's not what they want to do, they're not claiming that their intentions were moral or ethical, just that their having fun happens to have some arguably positive impact at times.

Re: LulzSec: Why we do what we do

#9
post #2

Might want to change the title to something like "LulzSec actually had a point after all." They do, too, an even better one than I expected. Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero.

Part of me feels that the publicity side of their argument is a little overblown. Many people do publicly disclose exploits, it's just that LulzSec has made a huge deal in the media about each one. Another part of me is happy to see them call people out on their abysmal security practices. Sony would not have upgraded/redone their security practices had there not been attacks. The only thing worse than poor security is having a false assurance that it's good.

Re: LulzSec: Why we do what we do

#10
post #7

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

When Anonymous attacked Visa and Mastercard via DDoS (in retaliation to them cutting off Wikileaks donations), Anonymous did actually succeed in stopping the online verification systems for both companies (SecureCode, or something, and Verified by Visa). In that case, the DDoS attacks did more than just take the site down; they financially hurt their target, which was probably the aim to begin with. I'm not justifyin…

DDoS's have a monetary impact, yes. However, what the parent is saying is that all infrastructure has limits in terms of bandwidth, etc. The point is that it's not the same class of "attack" vs. finding an exploit. The latter is more in line with the "strive for more secure sites". The former, not so much.
Post reply on HN