Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

41–50 of 195 posts

Re: LulzSec: Why we do what we do

#41
post #6

>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled. This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do. I…

It's a bit of a silly way to respond though - they could either be whitehats themselves and charge a more reasonable amount; or charge the same amount and donate whatever they think is reasonable to education campaigns or whatever.

Re: LulzSec: Why we do what we do

#42
post #29
post #16

Raise your hand if you're hesitant to write what's on your mind for fear of receiving some special attention from Anonymous, LulzSec, and friends.

The impact of their attacks has more been a strong motivation to "get my house in order". I'd been using LastPass for some time but decided that I should get the YubiKey for two factor auth. I also started becoming quite a bit more vocal at work about the sorts of things it might be a good idea to take a closer look at. This is a wake up call for what's already happening. They just decided to do it and tell the publi…

Wasn't LastPass hacked earlier this year?

Re: LulzSec: Why we do what we do

#43
post #13

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

There is a need to develop systems that aren't subject to DDOS (at least the current generation). It used to be very easy to DOS anyone's network stack (think SYN flooding). If people hadn't shown that it was an issue by doing it, the Internet would still be running on stacks that were trivial to undermine many different ways. Saying that something is easy to do and has a tremendous impact is an engineering problem s…

> There is a need to develop systems that aren't subject to DDOS

Some protocols are immune to DDOS: like BitTorrent and Freenet. HTTP wasn't designed to deal with DDOS.

Re: LulzSec: Why we do what we do

#44
post #13

Earlier quoted context omitted.

There is a need to develop systems that aren't subject to DDOS (at least the current generation). It used to be very easy to DOS anyone's network stack (think SYN flooding). If people hadn't shown that it was an issue by doing it, the Internet would still be running on stacks that were trivial to undermine many different ways. Saying that something is easy to do and has a tremendous impact is an engineering problem s…

See, is there a practical way to "fix" the problem behind a DDOS? More specific attacks (slowloris, SYN flood, ping of death, smurf, and a laundry list of other stuff) can be fixed by simply introducing changes to the infrastructure that makes such things possible. But a DDOS attack is, at heart, nothing more than a brute-force attack - flooding a single website / IP with so much traffic that it can't respond. No mat…

So let's think about how traffic gets onto the network and what steps might make sense to limit that. I have some "crazy" ideas about this including per device reputation enforced as close to the device as possible. Yes, if we say that anyone with any sort of device can send data to anyone then this will be a problem. There are other options including different sorts of "darknet" type things. Are there no "outside the box" type solutions that you can think through the tradeoffs for? I think the underlying assumption you're working with, that anyone anywhere on the network should be able to drop an unlimited amount of data onto the link headed to me as a rule of how things must forever work needs to be justified.

Re: LulzSec: Why we do what we do

#45

This smells to me like a hastily conjured rationalization for a series of attention-seeking acts wrought by a small group of disenfranchised industry workers who have something to say, but they're just not articulate enough to voice it so they blow shit up instead.

a small group of disenfranchised industry workers

Do you really think they're industry workers? I'd peg most of them as high school kids. Probably with the occasional creepy thirty-something thrown in for good measure.

Re: LulzSec: Why we do what we do

#46
post #6

>People who can make things work better within this rectangle have power over others; the whitehats who charge $10,000 for something we could teach you how to do over the course of a weekend, providing you aren't mentally disabled. This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do. I…

Blackhats can cost organizations way more than whitehats would charge in operating costs, personal identity theft, and reputation. Whitehats are only taking advantage of the unenlightened as much as a mechanic is taking advantage of someone who doesn't know anything about cars - they provide experience and expertise and offer a service for a high price - at least, a higher price than if the client knew how to fix it…

I love it when the economically illiterate attack others for "price gouging" as if the third party doesn't have a choice in the matter or they aren't "unenlightened" enough to properly appraise the value of what they are buying.

How do I know that my jeweler isn't gouging me on my fiancee's 2 caret diamond ring? Because I know that there's a fixed quantity of available diamonds, and almost everyone would buy them at a given price. And if I need to verify that, I can go to the jeweler down the street. Everyone would buy security consulting at a given price, but that quantity is even more limited than 2 caret diamonds.

Why is my house worth a third less than what it was 3 years ago? Because there's at least a third fewer potential buyers than there was when I bought it. I wasn't "price gouged" or fooled in either instance.

Whitehats specialize in security and it frees up our time to specialize and produce excess value for others. It's not a conspiracy. If Steve Jobs and LeBron James aren't tricking people into giving them money, neither are whitehats. It's the free market and, believe it or not, it produces wealth.

Re: LulzSec: Why we do what we do

#47
post #35

This smells to me like a hastily conjured rationalization for a series of attention-seeking acts wrought by a small group of disenfranchised industry workers who have something to say, but they're just not articulate enough to voice it so they blow shit up instead.

They can voice it perfectly well. The problem is that they can't be heard in the mass media without some large event to draw attention. The last month has been their big event, and now they have the attention they needed. They had a good plan and it was executed perfectly. [Edit: by "good plan" I mean that their plan had a good chance of success, not that it was beneficial. That part is still up for debate.]

No, they cannot voice it perfectly well, if they have to resort to stealing user information to get their message across.

Their plan was not good, insofar as it caused pain for a great many people. What they did was not okay, and should not be lauded as a positive thing for the Internet at large.

The problem is that their antics are even being considered as anything other than the terroristic (in the real sense of the word, not the post 9/11 hyped up nonmeaning it tends to carry today) acts that they are.

If someone broke into a hospital and flung all of the patient records out onto the street, we wouldn't be having this discussion; they'd absolutely be considered criminals. So what if the glass they broke to get into the hospital wasn't shatter-proof? Sure, the hospital security would be improved, but there are a great many ways to go about fixing the problem without compromising the privacy if hundreds of thousands of people.

Re: LulzSec: Why we do what we do

#48
post #7

Earlier quoted context omitted.

When Anonymous attacked Visa and Mastercard via DDoS (in retaliation to them cutting off Wikileaks donations), Anonymous did actually succeed in stopping the online verification systems for both companies (SecureCode, or something, and Verified by Visa). In that case, the DDoS attacks did more than just take the site down; they financially hurt their target, which was probably the aim to begin with. I'm not justifyin…

It also led to Paypal allowing Wikileaks to retrieve the money they already had before they suspended their account.

I was not aware of this. Can you cite a source?

Re: LulzSec: Why we do what we do

#49
post #38

Earlier quoted context omitted.

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

Preying on the weak for fun Preying on the weak for profit They both kind of have a sociopath sound to them

But, only one of them is the foundation of our society.

Re: LulzSec: Why we do what we do

#50
post #14

Earlier quoted context omitted.

Yes. If I leave the door to my house unlocked, it doesn't mean that it is ok for you to come in without my permission.

Can I look in the windows?

I think a reasonable comparison to the Citibank security flaw is leaving bank statements on a table in front of the window.
Post reply on HN