Live data from Hacker News

LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

thenextweb.com

141–150 of 156 posts

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#141
It appears that LulzSec isn't directly responsible for this. Although, since they called for the hacking of every government agency in the world with their "anti-sec" call to arms it's a bit disengeneous for them to rock back on their heels in shock and confusion.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#142
post #139

Earlier quoted context omitted.

> For SQL use prepared statements exclusively (never let "oh, it's just a number so I don't need to" fool you) I cannot vote this up enough. Also, depending on what database you are using (eg Oracle) if you don't use prepared statements (aka bind variables) you are guarantee killing your DB performance. People have argued with me in the past that for things like sorting the data they cannot use bind variables. In tha…

The way I write software, such values of user_select_sort would never even be possible... It's much slower to compare strings than to compare numbers, and passing long descriptive values that are actually booleans or short enums is just a waste of bandwidth (assuming they are passed as GET/POST variables). Why not just pass numbers instead?

Numbers or strings wasn't the point really. You can do 'order by 1' or 'order by 2' in SQL to order by the first or second selected col etc, but if you used used the number passed directly from the user in the SQL statement, you are open to SQL injection. Feel free to use the number in a case statement to select the order by string to concat into your SQL however.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#143

Earlier quoted context omitted.

There are no ideals, and it's not a conspiracy. That's the impression I have of a lot of contemporary political and business interests: "There are no ideals, and it's not a conspiracy. It's just business." Some do it for the lulz. Some do it for the bottom line. LulzSec's tactics may be callous or juvenile, but they also somehow see a fitting expression for some of the inchoate disenchantment that I feel. When I paus…

but they also somehow see a fitting expression for some of the inchoate disenchantment that I feel. I've been curious about this feeling as it certainly seems to me that you're not alone. What is it that they've done that makes them hit a chord with you? What I see when I look at lulzsec is mostly behvior that hurts a random collection of common people - like dropping emails, hashes, personal info of people who just…

What is it that they've done that makes them hit a chord with you?

As an American, I have a demoralizing sense that the country has given up on doing great things and, more specifically, turned its back on underdogs. I could make a more detailed case, starting with my view of human nature and extending to the latest Supreme Court decisions and the drivel I see nosing around Twitter and Facebook, but that would be sort of beside the point here.

Why gamers and book forum readers? I don't have anything against them personally and I agree there are probably more suitable targets. At the same time, obsessive game-players and score-keeping book-readers offer an obvious illustration for the kind of obliviousness and escapism that I can find symptomatic of larger social problems.

I suspect Lulzsec owes part of its style to The Joker from the last Batman movie. Remember that scene when the Joker lights the pile of money on fire? I agree Anonymous is a more constructive example of civil disobedience. But Lulzsec, in its aimlessness, may be the more potent symbol. I see it as a form of satire as much as anything.

Would my attitude would change if, say, they deleted my gmail account? Probably. But then maybe there would be something constructive in that, too.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#144

Earlier quoted context omitted.

but they also somehow see a fitting expression for some of the inchoate disenchantment that I feel. I've been curious about this feeling as it certainly seems to me that you're not alone. What is it that they've done that makes them hit a chord with you? What I see when I look at lulzsec is mostly behvior that hurts a random collection of common people - like dropping emails, hashes, personal info of people who just…

What is it that they've done that makes them hit a chord with you? As an American, I have a demoralizing sense that the country has given up on doing great things and, more specifically, turned its back on underdogs. I could make a more detailed case, starting with my view of human nature and extending to the latest Supreme Court decisions and the drivel I see nosing around Twitter and Facebook, but that would be sor…

Thanks for taking the time to respond.

I was thinking of saying something along the lines of I'd be surprised if they view their own actions so introspectively. Perhaps comparing it to the classic english teacher interpreting meaning behind a work for he class that the author never intended.

But I suppose it really doesn't matter - if people get something from a work it really makes no difference if the intent was there with the creation.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#145
post #125

Earlier quoted context omitted.

When you post a tweet, how much information does twitter have about you? An IP adress, what platform you use, etc. I'm just curious, because Lulzsec posts frequently and I wonder if law enforcement could subpoena twitter in attempts to catch these people.

During the 'hunt' for Wikileaks the U.S. has subpoenaed Twitter for info about supposed supporters.[1] In the case of Lulzsec this will have very little use though, as they use VPN's to hide their IP [2]. [1] http://www.wired.com/threatlevel/2011/01/twitter/ [2] http://lulzsecexposed.blogspot.com/2011/06/scared-puppies.ht...

they use VPN's to hide their IP

The FBI routinely uses software exploits to install something called CIPAV on the remote client computer to retrieve forensics data and negate the effect of proxies, vpns, tor, etc.

http://www.wired.com/threatlevel/2007/07/fbi-spyware-how/

Twitter almost assuredly has the ability to push a custom iframe or similar based on who is logged on to support these kinds of government payloads. In the case the wired article references myspace directly assisted.

Surely being more security paranoid than usual should make it harder for an attack like this to succeed, but if the feds get pissed enough it's not unthinkable that they could get access to a targeted zero day to use.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#146

Earlier quoted context omitted.

What is it that they've done that makes them hit a chord with you? As an American, I have a demoralizing sense that the country has given up on doing great things and, more specifically, turned its back on underdogs. I could make a more detailed case, starting with my view of human nature and extending to the latest Supreme Court decisions and the drivel I see nosing around Twitter and Facebook, but that would be sor…

Thanks for taking the time to respond. I was thinking of saying something along the lines of I'd be surprised if they view their own actions so introspectively. Perhaps comparing it to the classic english teacher interpreting meaning behind a work for he class that the author never intended. But I suppose it really doesn't matter - if people get something from a work it really makes no difference if the intent was th…

I agree. I expect their actions are not introspective but reactionary. Nevertheless, I think there's a logic behind them consistent with the sort explored by behavioral economists.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#147
post #19

I don't like where this is going.

Whats worrying about the apparent proliferation of security breaches like this is that as the attacks get more sophisticated, so do the prevention methods. This could get to the point whereby the skill level required to protect an application or server goes way higher than the skill level of many developers. The result being that independent development is impossible as you would need to hire ever more expensive secu…

Surely Web frameworks do a lot to help solve this. Im sure django isnt't perfect; but its more secure than anything I could do.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#148

Earlier quoted context omitted.

but they also somehow see a fitting expression for some of the inchoate disenchantment that I feel. I've been curious about this feeling as it certainly seems to me that you're not alone. What is it that they've done that makes them hit a chord with you? What I see when I look at lulzsec is mostly behvior that hurts a random collection of common people - like dropping emails, hashes, personal info of people who just…

What is it that they've done that makes them hit a chord with you? As an American, I have a demoralizing sense that the country has given up on doing great things and, more specifically, turned its back on underdogs. I could make a more detailed case, starting with my view of human nature and extending to the latest Supreme Court decisions and the drivel I see nosing around Twitter and Facebook, but that would be sor…

Doesn't seem too different than the usual teenage hubris. Kids think adults are boring on purpose and try to disrupt the social order to make life more interesting. They don't realize order and a good life is actually quite hard to maintain, and a bit of boring is the cost of living well.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#149

According to their Twitter, they haven't hacked the Census. Seems like someone was spreading false information... See: https://twitter.com/#!/LulzSec/status/83168314527981568 https://twitter.com/#!/LulzSec/status/83167715799470080 EDIT: Those tweets were deleted. Here's the official word: "Just saw the pastebin of the UK census hack. That wasn't us - don't believe fake LulzSec releases unless we put out a tweet first…

When you post a tweet, how much information does twitter have about you? An IP adress, what platform you use, etc. I'm just curious, because Lulzsec posts frequently and I wonder if law enforcement could subpoena twitter in attempts to catch these people.

It's no secret that the @lulzsec account is controlled by former Anonymous spokesperson Topiary (http://twitter.com/atopiary), whose identity is not publicly known, though it has been anonymously claimed that he or she is Daniel Ackerman Sandberg.

Re: LulzSec supposedly claims its biggest coup yet: The entire UK 2011 Census

#150
post #51

Earlier quoted context omitted.

It did ask for the household annual income. It also asks for the job title of the various householders so with a small bit of market info you could easily discern who earns what. Regardless, salary info would be the least of my concerns.

Oh. I can't see that question on http://www.ons.gov.uk/census/2011-census/2011-census-questio...

Q34-40

Job title, Occupation, Employees managed.

You didn't look very well ;0)>

I remember particularly as this sort of question is hard for me as I don't really have a job title, my occupation is extremely varied.

Post reply on HN