Live data from Hacker News

Basecamp was under network attack

gist.github.com

31–40 of 194 posts

Re: Basecamp was under network attack

#34
post #19

Although a smaller service, we were in a similar situation a couple of years ago. We assumed it was a competitor because there were not monetary requests, just a massive DDoS via torrents that lasted almost a week. Data center didn't help us in any way... it was crazy. Worst thing is that 90% of customers have no clue what a DDoS is and how hard it is to handle.

I think that is what's great about how 37signals is handling this. I am sure a large portion of their client base is not technically inclined and having DDoS explained in plain english like they did gives those customers an understanding of what is happening.

That's what i was trying to say, we did something very similar, but you still end up with a portion of your user base that will blame you for not being able to handle it. (and they are in part right, but due to the nature of the attack sometimes it's very complicated to handle it or costs a lot of money - something the same customers wouldn't want to pay extra for :)

Re: Basecamp was under network attack

#35
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

Re: Basecamp was under network attack

#36

What law enforcement do you call in these situations. I imagine it would be a waste to call local police. I don't know how you would get feds to pay attention?

I believe that the Federal Bureau of Intelligence investigates and prosecutes cyber crimes[0].

[0]: http://www.fbi.gov/sanfrancisco/press-releases/2011/charges-...

Re: Basecamp was under network attack

#37

Earlier quoted context omitted.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

While I agree, the term blackmailer or extortionist would had been better.

Re: Basecamp was under network attack

#38
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

It is criminal behaviour. It reinforces to clients that the attack is not legal, and that they are not to be tolerated.

(and as a message to the DDOSer - they're likely to be reading this too and reminding them it is criminal and law enforcement is involved might make them reconsider the attack)

Re: Basecamp was under network attack

#40

What law enforcement do you call in these situations. I imagine it would be a waste to call local police. I don't know how you would get feds to pay attention?

Assuming the ransom request wasn't fake. It's pretty likely that the attack came from outside the US. Law enforcement will probably not be able to help at all.
Post reply on HN