Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

11–20 of 195 posts

Re: LulzSec: Why we do what we do

#11
post #6

>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled. This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do. I…

Blackhats can cost organizations way more than whitehats would charge in operating costs, personal identity theft, and reputation.

Whitehats are only taking advantage of the unenlightened as much as a mechanic is taking advantage of someone who doesn't know anything about cars - they provide experience and expertise and offer a service for a high price - at least, a higher price than if the client knew how to fix it themselves.

Re: LulzSec: Why we do what we do

#13

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

There is a need to develop systems that aren't subject to DDOS (at least the current generation). It used to be very easy to DOS anyone's network stack (think SYN flooding). If people hadn't shown that it was an issue by doing it, the Internet would still be running on stacks that were trivial to undermine many different ways. Saying that something is easy to do and has a tremendous impact is an engineering problem statement. Demonstrating it shows that it's also a business problem. This is how things get fixed, when people get tired of being instantly knocked of the Internet by .4% of the LulzSec DDOS capacity. The Internet still has some basic problems, ignoring them won't make it go away.

Re: LulzSec: Why we do what we do

#14

Just a question: if all they were doing was manipulating URLs (and I know they've moved beyond that) would they be doing anything illegal?

Yes. If I leave the door to my house unlocked, it doesn't mean that it is ok for you to come in without my permission.

Re: LulzSec: Why we do what we do

#15
post #14

Just a question: if all they were doing was manipulating URLs (and I know they've moved beyond that) would they be doing anything illegal?

Yes. If I leave the door to my house unlocked, it doesn't mean that it is ok for you to come in without my permission.

Can I look in the windows?

Re: LulzSec: Why we do what we do

#17
post #10
post #7

Earlier quoted context omitted.

When Anonymous attacked Visa and Mastercard via DDoS (in retaliation to them cutting off Wikileaks donations), Anonymous did actually succeed in stopping the online verification systems for both companies (SecureCode, or something, and Verified by Visa). In that case, the DDoS attacks did more than just take the site down; they financially hurt their target, which was probably the aim to begin with. I'm not justifyin…

DDoS's have a monetary impact, yes. However, what the parent is saying is that all infrastructure has limits in terms of bandwidth, etc. The point is that it's not the same class of "attack" vs. finding an exploit. The latter is more in line with the "strive for more secure sites". The former, not so much.

Then we need to fix the infrastructure so that the current generation of attacks don't work. To just say, "oh, well bandwidth is limited so there's always going to be an attack" is not useful. Think of ways you can structure the infrastructure so that it can do filtering further out, or detected spoofed connections, or detect anomalous request patterns. There are solutions, we need to find them and implement them, not just tell people not to do it or claim it's a "weak" attack. It's a strong attack if it takes minimal effort to cause maximal damage. In the real world, that's what matters. There's the idea that we're playing a game and that there are behaviors that are good form or bad form. However, when it comes down to it, what works is what works.

Re: LulzSec: Why we do what we do

#18

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

I think the point of their DDoS attack on cia.gov was in response to the US's statements that cyberwarfare would be responded to with actual warfare. They're just poking the beehive to see what it will do.

Re: LulzSec: Why we do what we do

#19
This smells to me like a hastily conjured rationalization for a series of attention-seeking acts wrought by a small group of disenfranchised industry workers who have something to say, but they're just not articulate enough to voice it so they blow shit up instead.

Re: LulzSec: Why we do what we do

#20
How do we enforce that these companies (such as banks) utilize proper security protocol (within reason of course)?

Some would say, "With your wallet!". But what happens when it's your wallet that gets stolen (electronically)?

What do you think?

Post reply on HN