Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

51–60 of 195 posts

Re: LulzSec: Why we do what we do

#51

I agree with showing how poorly secured websites are and how easily our information is distributed even when we think it's private. What I don't agree with is their use of DDoS attacks against sites like cia.gov. DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections. Sites should deploy onto an infrastructure they feel is adequate to deal wi…

DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections.

This point was raised a few months back in relation to PayPal and Visa getting DDoSed because of Wikileaks: DDoS attacks could be the new digital age version of a protest, a disruption of normal activities to draw attention to a particular cause (whether or not that cause is worthy is secondary). In that sense, DDoS attacks are very relevant.

Re: LulzSec: Why we do what we do

#52
post #29

Earlier quoted context omitted.

The impact of their attacks has more been a strong motivation to "get my house in order". I'd been using LastPass for some time but decided that I should get the YubiKey for two factor auth. I also started becoming quite a bit more vocal at work about the sorts of things it might be a good idea to take a closer look at. This is a wake up call for what's already happening. They just decided to do it and tell the publi…

Wasn't LastPass hacked earlier this year?

They saw some things they believed might be brute force attacks against weak passwords, so they reset the passwords of people who the attempts had been directed against. They also changed they way they handled repeated password failures to be even more strick. The basic database was not compromised and the passwords in the database are encrypted with the master password for the account so they'd have to be broken account by account.

Re: LulzSec: Why we do what we do

#53
post #44

Earlier quoted context omitted.

See, is there a practical way to "fix" the problem behind a DDOS? More specific attacks (slowloris, SYN flood, ping of death, smurf, and a laundry list of other stuff) can be fixed by simply introducing changes to the infrastructure that makes such things possible. But a DDOS attack is, at heart, nothing more than a brute-force attack - flooding a single website / IP with so much traffic that it can't respond. No mat…

So let's think about how traffic gets onto the network and what steps might make sense to limit that. I have some "crazy" ideas about this including per device reputation enforced as close to the device as possible. Yes, if we say that anyone with any sort of device can send data to anyone then this will be a problem. There are other options including different sorts of "darknet" type things. Are there no "outside th…

Yes, that would be a valid solution - authenticate every device, or provide a per-device reputation. But this has a couple of problems that I can think of:

1. Per-device reputation removes the concept of anonymity. If I can look up the "reputation" of the device that sent me a packet, I can track it perfectly too.

2. Authenticating every device (beside the practical challenges) is very inconvenient. What happens if I move countries? Buy a new phone? Or a new network card?

And there's more issues that I won't list :)

Problems aside, I agree with the statement: "the underlying assumption [...] that anyone anywhere on the network should be able to drop an unlimited amount of data onto the link headed to me [...] needs to be justified".

I think the most practical solution to this would simply be forcing ISPs (through legislation would be best) to look a little closer at their traffic. If I'm running an ISP, and I see a computer making 100 requests/second to a single website for more than a minute, I'm immediately thinking "DDOS". Yes, there's privacy issues, but most ISPs already do some sort of traffic shaping (see: Sandvine), so it shouldn't be that much of a stretch.

Arguments welcome ;-)

Re: LulzSec: Why we do what we do

#54

Earlier quoted context omitted.

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

I think everything else said in the post proves they are sociopaths. They don't seem to place value in "peons", "lulz lizards", or really any kind of human beings.

It's always been posited that, at some point, the Internet would create a generation of pseudo-sociopaths who are so disconnected from fellow human beings, they lack empathy, much the same as someone with the clinical diagnosis.

Mayhap that time has arrived.

Re: LulzSec: Why we do what we do

#55
post #35

Earlier quoted context omitted.

They can voice it perfectly well. The problem is that they can't be heard in the mass media without some large event to draw attention. The last month has been their big event, and now they have the attention they needed. They had a good plan and it was executed perfectly. [Edit: by "good plan" I mean that their plan had a good chance of success, not that it was beneficial. That part is still up for debate.]

No, they cannot voice it perfectly well, if they have to resort to stealing user information to get their message across. Their plan was not good, insofar as it caused pain for a great many people. What they did was not okay, and should not be lauded as a positive thing for the Internet at large. The problem is that their antics are even being considered as anything other than the terroristic (in the real sense of th…

People have been trying for years to get the point across that we need to have better security. None of them have managed it. If anything, security is getting worse because cracking tools are becoming more sophisticated. Someone had to get word out, what people were doing to raise publicity wasn't working, there was a way to get attention, and LulzSec did it. Bad as what they did is, they successfully raised media awareness of the fact that those patient records were in a clearly-labeled manila folder taped to the front door.

Re: LulzSec: Why we do what we do

#56
post #29

Earlier quoted context omitted.

The impact of their attacks has more been a strong motivation to "get my house in order". I'd been using LastPass for some time but decided that I should get the YubiKey for two factor auth. I also started becoming quite a bit more vocal at work about the sorts of things it might be a good idea to take a closer look at. This is a wake up call for what's already happening. They just decided to do it and tell the publi…

Wasn't LastPass hacked earlier this year?

Additional information can be found here: http://blog.lastpass.com/2011/05/lastpass-security-notificat...

Re: LulzSec: Why we do what we do

#57
post #17
post #10

Earlier quoted context omitted.

DDoS's have a monetary impact, yes. However, what the parent is saying is that all infrastructure has limits in terms of bandwidth, etc. The point is that it's not the same class of "attack" vs. finding an exploit. The latter is more in line with the "strive for more secure sites". The former, not so much.

Then we need to fix the infrastructure so that the current generation of attacks don't work. To just say, "oh, well bandwidth is limited so there's always going to be an attack" is not useful. Think of ways you can structure the infrastructure so that it can do filtering further out, or detected spoofed connections, or detect anomalous request patterns. There are solutions, we need to find them and implement them, no…

They can certainly protect against this but it's not a good idea.

I pay US taxes and I don't want the cia.gov site to be on the same type of hardware as say Google just to be DDoS "proof".

They shouldn't be connected with a 33.6 modem but to ask all sites to upgrade everything to prevent DDoS is insane.

Who could afford to start a web site if they had to lay out all of that cost?

Re: LulzSec: Why we do what we do

#58
post #46

Earlier quoted context omitted.

Blackhats can cost organizations way more than whitehats would charge in operating costs, personal identity theft, and reputation. Whitehats are only taking advantage of the unenlightened as much as a mechanic is taking advantage of someone who doesn't know anything about cars - they provide experience and expertise and offer a service for a high price - at least, a higher price than if the client knew how to fix it…

I love it when the economically illiterate attack others for "price gouging" as if the third party doesn't have a choice in the matter or they aren't "unenlightened" enough to properly appraise the value of what they are buying. How do I know that my jeweler isn't gouging me on my fiancee's 2 caret diamond ring? Because I know that there's a fixed quantity of available diamonds, and almost everyone would buy them at…

Also foolish to forget that time is money, you pay knowledge workers for the time they spent studying. You too can "save" $10,000 by doing security yourself, but only if you spend several years training and understanding the domain.

Re: LulzSec: Why we do what we do

#59
post #46

Earlier quoted context omitted.

Blackhats can cost organizations way more than whitehats would charge in operating costs, personal identity theft, and reputation. Whitehats are only taking advantage of the unenlightened as much as a mechanic is taking advantage of someone who doesn't know anything about cars - they provide experience and expertise and offer a service for a high price - at least, a higher price than if the client knew how to fix it…

I love it when the economically illiterate attack others for "price gouging" as if the third party doesn't have a choice in the matter or they aren't "unenlightened" enough to properly appraise the value of what they are buying. How do I know that my jeweler isn't gouging me on my fiancee's 2 caret diamond ring? Because I know that there's a fixed quantity of available diamonds, and almost everyone would buy them at…

>Because I know that there's a fixed quantity of available diamonds

Meanwhile...

http://en.wikipedia.org/wiki/Chemical_vapor_deposition_of_di...

Re: LulzSec: Why we do what we do

#60

Adorable. They're bullies and proud of it. It's one thing to call out security exploits, and quite another to take great joy in causing others pain.

> to take great joy in causing others pain

This happens far more often than people realise.

Post reply on HN