Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

121–130 of 195 posts

Re: LulzSec: Why we do what we do

#121
post #106

OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulzsec deserves a medal and a chest to pin it on for breaking this news to all of the people who don't have a facebook account, have never been on irc, didn't see the movie wargames, don't know anyone who plays world of warcraft, has never read the new york times…

Being a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is . That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall thr…

We must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resources on computer security can and do still fall the victim to intrusions on a regular basis. Outfits that follow generally accepted best practices get successfully spearphished on a weekly or monthly basis. Startups are encouraged by the industry to throw up websites in weeks, yet the tools they're given largely do very little to prevent them from shooting themselves in the foot on a regular basis.

Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims.

The truth is that computer security isn't shit because all the noobs out there that don't have a CSO, don't hire matasano, don't have sufficient change review policies, don't have a 24x7 ops team with live instrumentaion and don't have DDOS protection are id1ots. Sure, any one of them can be pointed and laughed at and said they're losers. But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug. And also a failure of our own security industry for selling ineffective, labor intensive solutions and pricing most of the rest beyond the reach of most potential customers.

And I dare say that Lulzsec isn't going to have much of an impact on any of that.

Re: LulzSec: Why we do what we do

#122
post #2

Might want to change the title to something like "LulzSec actually had a point after all." They do, too, an even better one than I expected. Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero.

Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero. Neither of these are novel concepts: we've heard about abysmal internet security (FireSheep) and low attention spans (Nicholas Carr[0, 1] and…

The difference is that LulzSec managed to get their word on every tech blog in the world. They also managed to get their basic message - nothing is safe, and here's proof - onto nearly every single major news site in existence, and they made their message immediately and personally important to millions of people. That's why I'm praising them. They don't need to propose a solution; that's already been done. They don't need to have a new message; extant messages are good enough. What they bring to the party is visibility.

Re: LulzSec: Why we do what we do

#123

Earlier quoted context omitted.

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

I think everything else said in the post proves they are sociopaths. They don't seem to place value in "peons", "lulz lizards", or really any kind of human beings.

Having no moral doesn't make you a sociopath.

Re: LulzSec: Why we do what we do

#124

Earlier quoted context omitted.

It's always been posited that, at some point, the Internet would create a generation of pseudo-sociopaths who are so disconnected from fellow human beings, they lack empathy, much the same as someone with the clinical diagnosis. Mayhap that time has arrived.

Just like with violent video games, the internet doesn't make people feel disconnected, or turn them into sociopaths. It enables people who would rather be disconnected to disconnect themselves, and gives sociopaths the ability to do far more. The internet doesn't create people without empathy, it reveals that deep down, a lot of humanity didn't have it to begin with. The way society is starting to structure itself,…

>The internet doesn't create people without empathy, it reveals that deep down, a lot of humanity didn't have it to begin with. The way society is starting to structure itself, though, lets that shine through more clearly.

A lot? I doubt LulzSec is more than five people. For every pathological script-kiddie there are ten Free Software hackers. The Internet has revealed new ways for people to be destructive, but it has also revealed more ways that they can be constructive.

Compare:

http://www.quantcast.com/github.com

http://www.quantcast.com/4chan.org

Re: LulzSec: Why we do what we do

#125
post #122

Earlier quoted context omitted.

Not only are they making a point about how terrible security is ("Do you think every hacker announces everything they've hacked?"), but they've also called out the internet on its generally abysmal attention span. I wouldn't be surprised if they'd had this written on day zero. Neither of these are novel concepts: we've heard about abysmal internet security (FireSheep) and low attention spans (Nicholas Carr[0, 1] and…

The difference is that LulzSec managed to get their word on every tech blog in the world. They also managed to get their basic message - nothing is safe, and here's proof - onto nearly every single major news site in existence, and they made their message immediately and personally important to millions of people. That's why I'm praising them. They don't need to propose a solution; that's already been done. They don'…

What they bring to the party is visibility.

Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans.

As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based brute force techniques by, what, 10 seconds?

Re: LulzSec: Why we do what we do

#126
post #119
post #109

Earlier quoted context omitted.

The gunshot analogy fails hard. LulzSec pre-empted at least half of it, by stressing how harm occurs quietly all the time. Data gets stolen or destroyed and we just don't know it. Unlike gunshot wound, where a person lands in a hospital, or morgue, or goes missing, data can be, and indeed is, copied quietly. Of gunshots, people are informed most of the time; of security breaches, barely ever. Cops investigate most gu…

Corporations most definitely shoot people... http://en.wikipedia.org/wiki/Military

[deleted]

Re: LulzSec: Why we do what we do

#127
post #106

Earlier quoted context omitted.

Being a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is . That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall thr…

We must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resources on computer security can and do still fall the victim to intrusions on a regular basis. Outfits that follow generally accepted best practices get successfully spearphished on a weekly or monthly basis. Startups are encouraged by the industry to throw up w…

To be frank your point is bordering on meaningless, you've jumped from anyone can shoot someone to it's all a failure of the computer industry.

I find the first assertion idiotic and the last begging the question.

patio11 made a similar point about armed robbery, I mean seriously, what is wrong with you?

It's fucking stupid. If someone gets shot a lot of cops will turn up within minutes. They'll devote a lot of manpower to it. In some of your states the perpetrator will be executed.

There's a response. There's a massive immediate manhunt. Will people stop idiotically claiming that a serious, sickening crime is anything like hacking someone's server please?

And to get back on topic, if someone gets hacked it's brushed under the carpet if possible if it's even noticed. People aren't even checking if it's happened.

Where's the abnormal activity alert built into windows or linux? Or Apache or IIS?

Re: LulzSec: Why we do what we do

#128
post #106

OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulzsec deserves a medal and a chest to pin it on for breaking this news to all of the people who don't have a facebook account, have never been on irc, didn't see the movie wargames, don't know anyone who plays world of warcraft, has never read the new york times…

Being a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is . That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall thr…

I've been kept out of Sony and all this by never consuming from them.

this is the epitome of capitalism. your comment was spot on until the edit.

last sony thing I paid was a cassette walkman. then after betamax, minidisc, memory stick, etc, etc, etc... you have to be a sucker to support them. sad but true.

anyway, by not consuming from a company with low market ethic, I also avoided a company with bad network security ethic. they would be hacked? could be. but if nintendo is hacked, I can at least just change my password not my name and credit card.

for similar reasons I also avoid apple, j&j, and a few others.

Re: LulzSec: Why we do what we do

#129
post #106

Earlier quoted context omitted.

Being a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is . That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall thr…

We must have a different definition of easily avoidable. The truth is that organizations that spend a much larger than average portion of their energy and resources on computer security can and do still fall the victim to intrusions on a regular basis. Outfits that follow generally accepted best practices get successfully spearphished on a weekly or monthly basis. Startups are encouraged by the industry to throw up w…

> Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims.

And that is why this stuff is easily avoidable. Much like a lock on your door isn't going to stop a determined thief from breaking in, simple protections won't stop a determined attacker from breaking into your site. But in an age where adding CSRF tokens is simple, SQLi protection is nearly guaranteed by using an ORM and/or parameterized queries, XSS is largely mitigated by filtering on templates, etc, it's not that hard to remove the low-hanging fruit from your site. Even with these, you will still have vulnerabilities, but a drive-by attack like those executed by Lulzsec will not work.

> But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug.

It's easier than ever to write secure code without even trying. If you follow, say, a basic Django tutorial, you won't be vulnerable to XSS and SQLi unless you color outside the lines. Add in CSRF middleware, and suddenly CSRF attacks (and a large amount of reflected XSS with them) are mitigated. These are not difficult things, and the software industry is getting better and better about making secure coding the rule, not the exception.

Re: LulzSec: Why we do what we do

#130
post #114
post #49

Earlier quoted context omitted.

But, only one of them is the foundation of our society.

You mean the foundation of Taliban and Mafia society. You know, it is quite possible to make money by being good. It just doesn't grab headlines as effectively.

And quite trivial to make more money preying on the weak than being good.
Post reply on HN