Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

31–40 of 195 posts

Re: LulzSec: Why we do what we do

#31
post #13

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

There is a need to develop systems that aren't subject to DDOS (at least the current generation). It used to be very easy to DOS anyone's network stack (think SYN flooding). If people hadn't shown that it was an issue by doing it, the Internet would still be running on stacks that were trivial to undermine many different ways. Saying that something is easy to do and has a tremendous impact is an engineering problem s…

DDOS attacks are terribly hard to stem. I remember Softlayer having a Cisco Guard they claimed helped against DDoS attacks, but it seems to cut off and block a good amount of legitimate traffic as well.

Re: LulzSec: Why we do what we do

#32
post #13

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

There is a need to develop systems that aren't subject to DDOS (at least the current generation). It used to be very easy to DOS anyone's network stack (think SYN flooding). If people hadn't shown that it was an issue by doing it, the Internet would still be running on stacks that were trivial to undermine many different ways. Saying that something is easy to do and has a tremendous impact is an engineering problem s…

See, is there a practical way to "fix" the problem behind a DDOS? More specific attacks (slowloris, SYN flood, ping of death, smurf, and a laundry list of other stuff) can be fixed by simply introducing changes to the infrastructure that makes such things possible.

But a DDOS attack is, at heart, nothing more than a brute-force attack - flooding a single website / IP with so much traffic that it can't respond. No matter how much fancy technology you add, if you have a 100Mbps link, and someone's sending 1Gbps of data at you, you're out of luck.

And, yes, I realize that there are companies that specialize in protecting against DDOS attacks - generally, they move content to a CDN and use some intelligent filtering to drop packets (i.e. people that request multiple times in succession, etc.). But this still is reliant on the fact that their connections are large enough that they can actually process all this data.

If a large country decided to use all it's available Internet bandwidth to DDOS, there's not much anyone can do about it.

In short: DDOS attacks will likely always be around - they might require higher bandwidth (country-scale or thereabouts), but it's not "fixable".

Re: LulzSec: Why we do what we do

#35

This smells to me like a hastily conjured rationalization for a series of attention-seeking acts wrought by a small group of disenfranchised industry workers who have something to say, but they're just not articulate enough to voice it so they blow shit up instead.

They can voice it perfectly well. The problem is that they can't be heard in the mass media without some large event to draw attention. The last month has been their big event, and now they have the attention they needed. They had a good plan and it was executed perfectly.

[Edit: by "good plan" I mean that their plan had a good chance of success, not that it was beneficial. That part is still up for debate.]

Re: LulzSec: Why we do what we do

#36
post #7

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

When Anonymous attacked Visa and Mastercard via DDoS (in retaliation to them cutting off Wikileaks donations), Anonymous did actually succeed in stopping the online verification systems for both companies (SecureCode, or something, and Verified by Visa). In that case, the DDoS attacks did more than just take the site down; they financially hurt their target, which was probably the aim to begin with. I'm not justifyin…

It also led to Paypal allowing Wikileaks to retrieve the money they already had before they suspended their account.

Re: LulzSec: Why we do what we do

#37
post #2

Might want to change the title to something like "LulzSec actually had a point after all." They do, too, an even better one than I expected. Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero.

That's not the most important thing I took away from the submitted link.

To me, the important thing is that LulzSec says that it derives pleasure from causing harm to people -- like the people who used to add poison to bottles of Tylenol, package the Tylenol back up again and place it back on the supermarket shelf. Although they could be saying that to cover up their real agenda, most writers (and especially most writers who have the tech skills needed to do what LulzSec has done) could not fake an admission of this sort as well as this text would have to have been faked.

Since it is natural human behavior to rationalize an antisocial motivation with a more socially-acceptable cover story, you would expect LulzSec to say things like, "We are doing this to bring public attention to how terrible security is." But if it is a rationalization, and it sure seems that way to me, surely it would be a mistake to focus on it and not the true motivations.

>they've also called out the internet on its generally abysmal attention span.

What an surprizing interpretation! I interpreted the parts about boredom as a continuation of the author's honestly disclosing his own motivations, not anything about internet users in general.

Re: LulzSec: Why we do what we do

#38
post #6

>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled. This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do. I…

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

Preying on the weak for fun

Preying on the weak for profit

They both kind of have a sociopath sound to them

Re: LulzSec: Why we do what we do

#39
post #20

How do we enforce that these companies (such as banks) utilize proper security protocol (within reason of course)? Some would say, "With your wallet!". But what happens when it's your wallet that gets stolen (electronically)? What do you think?

Unfortunately, I've never seen "vote with your wallet" concept work[1], neither in the Internet, nor in real life. When a company misbehaves, there's usually a big group of their customers which doesn't know about it, and another (maybe little smaller) group, that doesn't care at all (or enough[2]). It's an interesting issue I have no idea how to fix...

[1] - if you know any examples, I'd be glad to hear them.

[2] - "Maybe this company is bad, but hell, the competition is 10 minutes further walking from me...", etc.

Re: LulzSec: Why we do what we do

#40
post #6

>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled. This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do. I…

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

I think everything else said in the post proves they are sociopaths. They don't seem to place value in "peons", "lulz lizards", or really any kind of human beings.
Post reply on HN