Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

161–170 of 195 posts

Re: LulzSec: Why we do what we do

#161
post #71

And I just realized what it is about LuLzSec that's bothered me. I couldn't quite put my finger on it, but now I realize deep down they are nihilists. That's a damn shame. What seemed most admirable about Anonymous is that as much as they were also in it for lulz and pure chaos, underneath there seemed to be a kind of idealism. Idealism is seductive, nihilism is off-putting.

Or maybe that Anonymous idealism was a fraud and lulz, as peers, could see the hypocrisy much clearer, as everybody in their community likely do what they do because of the thrills and ignoring the pain caused. Lulz admitting it is likely taking the high road? or is that too tortured as twist.

Perhaps anon was also pure lulz with absolutely nothing else behind it. But I vaguely recall their writing to be strongly pro freedom. And their most prominent vandalisms seemed to be an attempt to make a point about basic rights and freedoms.

When LuLzSec state that they don't care, and don't even care if they get arrested, that's definitely nihilistic and kind of sad.

Certainly they too in their juvenile ways were close to making a good point. A point about shocking incompetence when handling and storing sensitive customer data. A point about unethical behavior in government. And I believe them when they say they have stuff that they've chosen not to release. So they are not in fact true sociopaths or true nihilists. I guess that makes it even sadder when they say they don't care about anything but lulz.

Re: LulzSec: Why we do what we do

#162
post #71

And I just realized what it is about LuLzSec that's bothered me. I couldn't quite put my finger on it, but now I realize deep down they are nihilists. That's a damn shame. What seemed most admirable about Anonymous is that as much as they were also in it for lulz and pure chaos, underneath there seemed to be a kind of idealism. Idealism is seductive, nihilism is off-putting.

Note LulzSec claims to 'not be Anon' (lol). It seemed like there was idealism lurking because there was!

Good point!

Re: LulzSec: Why we do what we do

#163

Earlier quoted context omitted.

That false comparison has always bothered me. Preying on the weak for fun instead of profit doesn't make you right, it makes you sound like a sociopath.

I think everything else said in the post proves they are sociopaths. They don't seem to place value in "peons", "lulz lizards", or really any kind of human beings.

It's easy to be a sociopath on the Internet where humanity is lost.

Re: LulzSec: Why we do what we do

#164
post #90
post #64

Earlier quoted context omitted.

Is phillijw another false positive of HN spam detectors?

Maybe. Look back through his(?) comment history, and you'll see that the point where he was autokilled/hellbanned (around nine pages back) was, while a very downvoted (and nonsensical) comment, not actually malicious. Before that, he had a few comments which were downvoted maybe two or three times (you can tell by the color). It's probable that he was autokilled/hellbanned because those caused his average comment kar…

Even starting a new account doesn't work (at least it didn't in a previous instance where I notified a false positive). You also need to use a proxy. So to phillijw, email PG or start a new account using a proxy :)

Re: LulzSec: Why we do what we do

#165
post #44

Earlier quoted context omitted.

So let's think about how traffic gets onto the network and what steps might make sense to limit that. I have some "crazy" ideas about this including per device reputation enforced as close to the device as possible. Yes, if we say that anyone with any sort of device can send data to anyone then this will be a problem. There are other options including different sorts of "darknet" type things. Are there no "outside th…

It'd need the help of browsers or OS's (depending on where in the stack you put the logic), but one idea might be to require requests/packets to be signed by something that proves a sufficient amount of CPU work has been done (ala bitcoin). If the site comes under attack, they could turn this on (presumably with a middle-man service that can take high bandwidth) and up the amount of work required to reach the destina…

This really doesn't solve the DDOS problem though. It's throwing more CPU time and bandwidth at a scenario that already requires both of those. It can slow a small group of script kiddies making a thousand requests to your server per second, but it doesn't stop an actual distributed attack using a botnet or large numbers of machines.

If you're adding the signatures, you presumably need to spend CPU time to authenticate it, and bandwidth to send the data, plus the actual content. Why not just have the middle-man soak up the extra requests, cache the data, and fan it out that way?

Re: LulzSec: Why we do what we do

#166
post #26
post #14

Earlier quoted context omitted.

Yes. If I leave the door to my house unlocked, it doesn't mean that it is ok for you to come in without my permission.

Morally, it's also not just how you break in, but what you do afterwards. I.e. if you prevent more harm than you do. If you enter the unlocked door and write "HI YOU FORGOT TO LOCK YOUR DOOR" with lipstick on the bathroom window, you're alerting the owner to a bad security practice by giving them a good scare. It is A Good Thing, because you likely prevented them losing their stuff. If you enter the unlocked door and…

Morally? Isn't privacy important to you? Leaving the moral judgement up to what the intruder does with the data he finds seems a bit delayed to me. He is immoral from the get-go, by trespassing in the personal property of others. It does not matter if I forget to lock my door. People often do. It does not make it OK to open my door.

You probably have this opinion because you think it's the cool way to think, that these 'hackers' have a great function in society, but lets shift the analogy: do you think your government should be able to do the same? If there was a story about the US government doing this stuff, HN would go insane with tirades about how the government is out to get us.

But no, not if it's lulzsec, not if it's some cracker kid. It's the romantic fantasy of the teenage computer hacker, rebelling against the world and saving the day... I mean posting your nudes on facebook. Everyone here emphasizes with it so much that they're blind to the reality that it's just wrong to invade the privacy of others, under any circumstance.

The only exception I could think of would be to invade the privacy of an oppressive government.

Re: LulzSec: Why we do what we do

#167
When are the internet tough guys of the world going to tighten up their prose? This third-rate Patrick Bateman routine is so fucking old at this point. There is no easier way to mark yourself as a barely socialized child barely capable of any critical thought than to try out that ridiculous, outdated, unconvincing pose at being this cynical, wise, best-informed übermensch above all morals. It's not a good look.

Re: LulzSec: Why we do what we do

#169
post #122

Earlier quoted context omitted.

The difference is that LulzSec managed to get their word on every tech blog in the world. They also managed to get their basic message - nothing is safe, and here's proof - onto nearly every single major news site in existence, and they made their message immediately and personally important to millions of people. That's why I'm praising them. They don't need to propose a solution; that's already been done. They don'…

What they bring to the party is visibility. Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans. As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based…

On the consumer end - what needs to be done is a massive education campaign, kept reasonably simple. It was done in 2000-2003 for anti-virus and it (roughly) worked for the 80% or so of the Windows world that did what they were told (by the mainstream press).

The mainstream press has (so far) done a terrible job on password education. You see long lists of rules that nobody but a security professional or hacker would follow. It needs to be boiled down to something simple, like:

Use a password manager to assign unique, random 15 character passwords for all accounts, protecting them with a strong master password.

I put together a guide based on this concept here:

http://www.filterjoe.com/2011/04/14/passwords-guide-without-...

Unfortunately, this (and probably other) good password guide(s) get far less attention than the latest Sony exploit.

Re: LulzSec: Why we do what we do

#170

OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulzsec deserves a medal and a chest to pin it on for breaking this news to all of the people who don't have a facebook account, have never been on irc, didn't see the movie wargames, don't know anyone who plays world of warcraft, has never read the new york times…

As I mentioned below it does very much show psychopathic tendencies. These people clearly have no empathy for those they are harming. This includes far more than just the Sony executives that everyone hates (despite not knowing).

Online security is poor for the same reason airport security is. Good security would take enough time and money to make the whole thing economically unviable.

Post reply on HN