Live data from Hacker News

Please Stop Attacking MIT's Network

blog.achernya.com

41–50 of 220 posts

Re: Please Stop Attacking MIT's Network

#41

I suppose the one silver lining is that this could be useful data for MIT admins to locate weaknesses in their network.

It's not supposed to be a hardened network that freaks out whenever anyone connects to it. Or is that the goal? To make MIT stop being so open?

I think that's a false dichotomy. It's possible to make the network and the attached services more resilient to a DoS without making it less open.

Re: Please Stop Attacking MIT's Network

#42
post #36

Earlier quoted context omitted.

Seriously? Still on the disable-JavaScript kick? scratches head

Yep. http://threatpost.com/en_us/blogs/yahoo-mail-cross-site-scri... http://news.softpedia.com/news/Yahoo-Users-Accounts-Still-No...

I see an obvious solution to this without disabling JS...

Re: Please Stop Attacking MIT's Network

#43

Please let me read your blog page without needed to turn on lots of javascript. The page is blank without whitelisting JS content.

Seriously? Still on the disable-JavaScript kick? scratches head

Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it.

Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF?

(Strangely enough, I am able to read the page w/o js, but responding in general to this type of comment I see on HN frequently.)

Re: Please Stop Attacking MIT's Network

#44
post #14

I do not condone the attacks that may be occurring. However, if you are trying to get someone's attention- it makes more sense to get the attention of the students rather than the administration. Today's MIT students are tomorrow's death-ray designers, robot-maintainers, and policy makers. They are tomorrow's administration- and they may not have made up their minds yet about ethical issues of intellectual property o…

As a first guess, MIT students are very unlikely to react to someone causing them trouble by become more sympathetic with the people causing them trouble. Especially if the message of the attackers is "people who break into the network shouldn't have the cops called on them." (Although we should wait for Hal Abelson's report to find out what happened behind the scenes.)

I think "very unlikely" might be an understatement.

Re: Please Stop Attacking MIT's Network

#45
As I'd mentioned on an earlier submission about W3C's site being inaccessible:

A cool thing about Aaron's activism was that it involved building things, circumventing censorship, and spreading information, rather than sabotage and denial-of-service.

Re: Please Stop Attacking MIT's Network

#46

If the students have failed to vehemently distance themselves and protest to the administration, or even quit MIT for somewhere else, then they are just as guilty. Their attendance abets the status quo. Especially since it's a private university. Quit whining.

Really?... It's not their battle. Why does a student at MIT have to have a position on this at all?

Re: Please Stop Attacking MIT's Network

#47

Earlier quoted context omitted.

Seriously? Still on the disable-JavaScript kick? scratches head

Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it. Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF? (Strangely enough, I am able to read the page w/o js, but responding in genera…

I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from tags, why do you feel OK with images enabled?

Re: Please Stop Attacking MIT's Network

#49

Please let me read your blog page without needed to turn on lots of javascript. The page is blank without whitelisting JS content.

Seriously? Still on the disable-JavaScript kick? scratches head

Not disabled, white-listed.

The internet is way better when you don't allow all of the annoying to dangerous JS to run.

Re: Please Stop Attacking MIT's Network

#50
post #26
post #10

I don't go to MIT, but a commenter on a previous article about this said that MIT's network had been having trouble for weeks. That is, before the Aaron Swartz tragedy. Is there some other reason why someone would be DDOS'ing MIT?

That was me, I think, and I believe we now know that they are uncorrelated (although I'm not paying as much attention to all of this as I should). If I recall correctly, the symptoms from a few weeks ago were with the ISPs MIT connects to, not internal to MIT's own network.

I've noticed some really weird blips with ISPs in general in the past several months. Nothing I can pin down, but my working knowledge is incredibly low, so I don't know the tools. For instance, I run a Mumble server on a Linode, nothing special, and last night, all of my SF/BayArea friends had a storm of disconnect-reconnects. I didn't have time to diagnose at the time, but I doubt I would have found anything either.
Post reply on HN