Live data from Hacker News

Basecamp was under network attack

gist.github.com

61–70 of 194 posts

Re: Basecamp was under network attack

#61
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

Some great language there It is. Only 4 words into the DDoS announcement and I rolled my eyes. I think that's a record for DHH.

Sounds like your issue is with DHH and not necessarily the copy.

Re: Basecamp was under network attack

#62
post #21

Earlier quoted context omitted.

Explain please.

The problem he may have is its a bit to reassuring. They claim user data is safe while being under attack. This is conceptually very similar to teaching kids that if you duck and cover during an ICBM strike you'll be fine. >This is like a bunch of people blocking the front door and not letting you into your house. The contents of your house are safe -- you just can’t get in until they get out of the way. If this is t…

Not sure that your missile analogy holds. Most DDoS attacks do not attempt to crack logins to servers, but rather try to flood the servers with as much garbage as possible. Besides, even if they were trying to crack the SSH password, a properly secured server (long passwords/public key auth + fail2ban) should be fine.

Re: Basecamp was under network attack

#63
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I agree, though blackmail seems inaccurate. I've always understood blackmail to be a demand backed by a threat to reveal secret information[1]; this sounds more like an extortion racket[2].

[1] http://en.wikipedia.org/wiki/Blackmail#United_States

[2] http://en.wikipedia.org/wiki/Extortion_racket

Re: Basecamp was under network attack

#64
We got hit by a DDoS about a year ago. Rackspace (who normally has amazing support) quietly null routed us and went about their day. No heads-up, trouble ticket, or any other form of notification. They didn't even put a note in our account so when we contacted their support to figure out why our servers were unresponsive outside their network the poor guy who answered the phone was just as confused as I was.

We've taken some steps since then to hopefully reduce our vulnerability. I'd be really interested in a DDoS protection best practices guide for small SaaS businesses.

Re: Basecamp was under network attack

#65
post #60

Crime, crime, crime, criminal. While technically (and probably also morally) true, was I the only one to find the emphasize weird?

I thought it was weird until he mentioned the blackmail. DDoS-ing for the lulz is one thing, doing it and then blackmailing the victim to get it to stop is a whole other level.

Re: Basecamp was under network attack

#66

What law enforcement do you call in these situations. I imagine it would be a waste to call local police. I don't know how you would get feds to pay attention?

Assuming the ransom request wasn't fake. It's pretty likely that the attack came from outside the US. Law enforcement will probably not be able to help at all.

Kim Dotcom would like a word.

Re: Basecamp was under network attack

#67
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Actually, it’s not ‘a DDoS’ but a blackmail attempt, using a DDoS. That’s like confusing someone open-carrying a gun and an armed robbery.

> This attack was launched together with a blackmail attempt that sought to have us pay to avoid this assault.

Re: Basecamp was under network attack

#68

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

I have a service on OVH myself.

Though a friend at another related service had been kicked from two VPS providers due to receiving a few DDoS attacks. These providers claimed it was against their Terms of Service and ejected him as a customer. That day he learned it is best to keep offsite-cross-company backups of everything, since he did not get a single byte from his machines.

Re: Basecamp was under network attack

#69
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

[deleted]

Re: Basecamp was under network attack

#70

Earlier quoted context omitted.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

it's just framing the scenario in good guys vs bad guys terms, it's childish regardless of how accurately the term describes the actors involved..
Post reply on HN