Live data from Hacker News

Please Stop Attacking MIT's Network

blog.achernya.com

51–60 of 220 posts

Re: Please Stop Attacking MIT's Network

#52
post #46

If the students have failed to vehemently distance themselves and protest to the administration, or even quit MIT for somewhere else, then they are just as guilty. Their attendance abets the status quo. Especially since it's a private university. Quit whining.

Really?... It's not their battle. Why does a student at MIT have to have a position on this at all?

What, do you think people have no social responsibility towards the institutions they support?

If you belonged to the Westboro Baptist Church or some other group it'd be legit to claim you're responsible for their actions to a certain degree.

Why do MIT students get a special exemption from the chain of responsibility that applies to everyone else?

If you are a member of a collectivist institution it's also your responsibility to take what action you can to shape its moral aspect. And to be silent is to abet.

Re: Please Stop Attacking MIT's Network

#53
post #47

Earlier quoted context omitted.

Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it. Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF? (Strangely enough, I am able to read the page w/o js, but responding in genera…

I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from tags, why do you feel OK with images enabled?

There have been hundreds (thousands?) of javascript exploits. Javascript is also a major component in user tracking. Go to a news site and you'll see a dozen trackers most likely against your wishes, reducing privacy and performance. It's a hostile internet out there.

Hostile images may exist but they are an order of mag. or two less common of a threat. Of course, where to draw the line is subjective, but the idea that blocking js by default is silly is misguided, imho.

Re: Please Stop Attacking MIT's Network

#54
My guess is someone wants to "send a message" to MIT and so they're attacking the most vulnerable, most exploitable part of MIT's infrastructure: a non-critical system run by student volunteers. I doubt it's anything personal against Alex or other MIT students.

Imagine if a thousand members of Anonymous staged a non-violent protest at MIT, marching across campus. This would inconvenience some students, possibly even prevent them from attending class. Should this protest be condemned as an unconscionable attack on students? Of course not. It's a perfectly acceptable form of civil disobedience. Why shouldn't this extend to online protests via DDoS?

Re: Please Stop Attacking MIT's Network

#55
To me this feels a bit like a lunch counter cook complaining all these black people showing up in his restaurant are causing him extra work.

The whole point of a protest is to put pressure on the system your trying to change. Start a walkout/go on strike if you dont want to deal with the problems the organization you're working for caused.

The school only gets power from its students. Without the students there is no school. You have more power then you think. Take a stand, make a difference.

Re: Please Stop Attacking MIT's Network

#56
post #45

As I'd mentioned on an earlier submission about W3C's site being inaccessible: A cool thing about Aaron's activism was that it involved building things, circumventing censorship, and spreading information, rather than sabotage and denial-of-service.

True but Aaron's activism resulted in him being bullied until he took his own life. It's a difficult topic.

If you assume that ddos from a collective is similar to blocking a road by a collective during a strike or manifestation then I must say that some people won't be able to get to work that day and in general nobody would get hurt.

This sort of pacific interruption raises awareness, which by itself is very important for a functioning democracy.

Re: Please Stop Attacking MIT's Network

#57
post #47

Earlier quoted context omitted.

Yeah, how silly to disable anonymous remote code execution by default. ;) Flashy pages that eschew compatibility and separation of concerns (even accessibility, seo at times) are the new standard, get used to it. Would you accept a Word.doc that required scripting to display itself? Shouldn't the response to a non-visible blog post be WTF? (Strangely enough, I am able to read the page w/o js, but responding in genera…

I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from tags, why do you feel OK with images enabled?

[deleted]

Re: Please Stop Attacking MIT's Network

#58
post #45

As I'd mentioned on an earlier submission about W3C's site being inaccessible: A cool thing about Aaron's activism was that it involved building things, circumventing censorship, and spreading information, rather than sabotage and denial-of-service.

[deleted]

Re: Please Stop Attacking MIT's Network

#59
post #47

Earlier quoted context omitted.

I wouldn't accept the word scripting because I don't trust their security model; I expect there to be a very high chance of getting a virus from MS Office scripting. I see a very low chance of getting a virus from js; there have also been 0-day exploits from tags, why do you feel OK with images enabled?

There have been hundreds (thousands?) of javascript exploits. Javascript is also a major component in user tracking. Go to a news site and you'll see a dozen trackers most likely against your wishes, reducing privacy and performance. It's a hostile internet out there. Hostile images may exist but they are an order of mag. or two less common of a threat. Of course, where to draw the line is subjective, but the idea th…

Can you link to a recent (for any reasonable value of the word) remote code execution vulnerability with JavaScript? Because my observation has been that RCE through codecs has been a much bigger vector for compromised systems.

Re: Please Stop Attacking MIT's Network

#60
post #46

Earlier quoted context omitted.

Really?... It's not their battle. Why does a student at MIT have to have a position on this at all?

What, do you think people have no social responsibility towards the institutions they support? If you belonged to the Westboro Baptist Church or some other group it'd be legit to claim you're responsible for their actions to a certain degree. Why do MIT students get a special exemption from the chain of responsibility that applies to everyone else? If you are a member of a collectivist institution it's also your resp…

What makes you think students at MIT aren't trying to make a difference? Do you expect something to happen within days of a tragedy? This takes organization, and outrage, and discussion. People searching for solutions. The wrong message would be to attack students, who are also ultimately victims of information monopoly.

I fear you're cutting off the nose to spite the face.

And these frequent DDoS attacks are partly to blame for Aaron's death, it's the reason why prosecutors are so hardcore about "hacking" or anything vaguely similar to it.

Post reply on HN