Live data from Hacker News

How LulzSec kept itself safe during the summer of 'lulz'

newscientist.com

21–30 of 34 posts

Re: How LulzSec kept itself safe during the summer of 'lulz'

#21

My understanding of cloud flare is that they null route you if any major attack comes in- Seems a little bit unfair they didnt do this for lulzsec just to get the press. If you are some boring website that gets the same attack lulzsec does, they will just disconnect/nullroute you. Correct me if any of this inaccurate, but last I checked it was not.

Hi,

We only force a site direct if the attack is too large & starts to impact other customers as well. If the attack doesn't impact other customers, then we won't force the site direct (we generally only force a few sites direct per week & these are monster attacks).

Re: How LulzSec kept itself safe during the summer of 'lulz'

#22

My understanding of cloud flare is that they null route you if any major attack comes in- Seems a little bit unfair they didnt do this for lulzsec just to get the press. If you are some boring website that gets the same attack lulzsec does, they will just disconnect/nullroute you. Correct me if any of this inaccurate, but last I checked it was not.

Also:

Clarifying that forcing direct does not mean a null route. Forcing direct = going direct to the site's server (we still resolve the DNS).

Re: How LulzSec kept itself safe during the summer of 'lulz'

#23
post #18

Earlier quoted context omitted.

Here's our internal data on this. Based on page view data (values below are page views) and using the statistics from Google DoubleClick Ad Planner ( http://www.google.com/adplanner/static/top1000/ ) we have the following for the last 30 days: Wikipedia.org 6,000,000,000 Twitter.com 5,900,000,000 Amazon.com 4,900,000,000 Aol.com 5,400,000,000 Zynga.com 460,000,000 Total 22,660,000,000 Then looking at our own internal…

Are you confident that you're comparing apples to apples there, and not e.g. pageviews to http requests?

Yes. We have detailed stats on page views, hits, bandwidth, cache hits, etc. etc. Looking at the most recent data which I get daily I see in the trailing 30 days: 27B page views and 162B hits.

Re: How LulzSec kept itself safe during the summer of 'lulz'

#24

My understanding of cloud flare is that they null route you if any major attack comes in- Seems a little bit unfair they didnt do this for lulzsec just to get the press. If you are some boring website that gets the same attack lulzsec does, they will just disconnect/nullroute you. Correct me if any of this inaccurate, but last I checked it was not.

Hi, We only force a site direct if the attack is too large & starts to impact other customers as well. If the attack doesn't impact other customers, then we won't force the site direct (we generally only force a few sites direct per week & these are monster attacks).

How was it that the Lulzsec attacks were not as large? What qualifies a sufficient size attack?

Re: How LulzSec kept itself safe during the summer of 'lulz'

#25
post #7

Nice ad Cloudfare... Wait, was it a legit article ? NewScientist took a hit in my heart in terms of credibility with this article.

Yes, it was a vendor interview piece with a linkbait-and-switch title. (Cloudfare didn't keep Lulzsec "safe", they kept their website up.) But NewScientist's primary audience is not web hosting specialists. So for their audience I expect it was mildly educational.

If I remember correctly some guy posted lulzsec member identities online after simply following them in irc..

Re: How LulzSec kept itself safe during the summer of 'lulz'

#26
post #6

My bullshit detector went off somewhere around here: "CloudFlare provides performance and security for any website online.We handle more traffic through our network now than Amazon, Wikipedia, Twitter, Zynga and Aol combined." Considering Wiki, Twitter and Amazon are all top 10 global sites, I'm having a hard time imagining someone doing more traffic than all of them put together, even disregarding the rounding error…

Here's our internal data on this. Based on page view data (values below are page views) and using the statistics from Google DoubleClick Ad Planner ( http://www.google.com/adplanner/static/top1000/ ) we have the following for the last 30 days: Wikipedia.org 6,000,000,000 Twitter.com 5,900,000,000 Amazon.com 4,900,000,000 Aol.com 5,400,000,000 Zynga.com 460,000,000 Total 22,660,000,000 Then looking at our own internal…

Much of Twitter and Zynga's "traffic" won't show up as pageviews - they'll be API calls that Ad Planner wouldn't pick up.

Regardless, that is a pretty remarkable amount of data. What makes it worth carrying at zero cost?

Re: How LulzSec kept itself safe during the summer of 'lulz'

#27

Very interesting headline followed by a total content-less fluffy press release masquerading as a news story. I am, as they say, disappoint.

I found this pretty interesting:

> "but we also saw very specific attacks targeted at vulnerabilities in the routers we used on our network. That's pretty clever; you would have to spend quite a bit of time investigating the topology in order to figure out what routers we were using."

Re: How LulzSec kept itself safe during the summer of 'lulz'

#28
post #27

Very interesting headline followed by a total content-less fluffy press release masquerading as a news story. I am, as they say, disappoint.

I found this pretty interesting: > "but we also saw very specific attacks targeted at vulnerabilities in the routers we used on our network. That's pretty clever; you would have to spend quite a bit of time investigating the topology in order to figure out what routers we were using."

If only that had gone on for more than a sentence, especially with asking permission to talk about the situation.

Re: How LulzSec kept itself safe during the summer of 'lulz'

#29

My understanding of cloud flare is that they null route you if any major attack comes in- Seems a little bit unfair they didnt do this for lulzsec just to get the press. If you are some boring website that gets the same attack lulzsec does, they will just disconnect/nullroute you. Correct me if any of this inaccurate, but last I checked it was not.

Yes. This happened to our site as well. Cloudflare buckled and sent a "sorry, can't handle it" email.

Re: How LulzSec kept itself safe during the summer of 'lulz'

#30

Very interesting headline followed by a total content-less fluffy press release masquerading as a news story. I am, as they say, disappoint.

I agree. I was hoping for some investigative reporting, but the entire story is an advertisement.
Post reply on HN