Live data from Hacker News

Basecamp was under network attack

gist.github.com

71–80 of 194 posts

Re: Basecamp was under network attack

#71

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

What happens when a ddos is indistinguishable from regular traffic? Or is it the case that it almost always follows a particular pattern?

Re: Basecamp was under network attack

#72
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :)

Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn't have a contingency plan).

If I'm a customer of Basecamp it looks to me like 37Signals is couching this as if they are the victims here, when really I am the victim. They're business isn't being disrupted... mine is! I pay them to abstract me away from the gory details... if I wanted to deal with that stuff I'd pay people to build it in house. My job as a customer isn't to sympathize with an outage, it's to move to a service that won't have one.

After turning in a term paper a day late a wise professor once told me "It doesn't matter if your excuse is true, it's still an excuse." The basic facts are the job didn't get done, and the person to blame is the person who didn't get the job done. Any modern web service that doesn't take the simple effort to sign up for cloudflare or their ilk to reduce attack surface doesn't deserve my money. (Admittedly a harsh perspective to take, but one many do take)

Re: Basecamp was under network attack

#73
Something along the lines of CloudFlare could be an option here. However, if the attacker does indeed know the actual IP of the Bootcamp servers (and Bootcamp allows traffic from IPs other than CF) that point is moot.

Set up CF, only allow traffic from CF.

On another note, having CF monitor an attack like this could help them do more research into mitigating these attacks in general and allow them to try and hunt the attacker. They tend to make things like this public which would benefit everyone.

Re: Basecamp was under network attack

#74
post #63
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I agree, though blackmail seems inaccurate. I've always understood blackmail to be a demand backed by a threat to reveal secret information[1]; this sounds more like an extortion racket[2]. [1] http://en.wikipedia.org/wiki/Blackmail#United_States [2] http://en.wikipedia.org/wiki/Extortion_racket

It is extortion, not blackmail. While blackmail is a form of extortion, it's as you say - threats to reveal potentially damaging information.

Re: Basecamp was under network attack

#75
post #61

Earlier quoted context omitted.

Some great language there It is. Only 4 words into the DDoS announcement and I rolled my eyes. I think that's a record for DHH.

Sounds like your issue is with DHH and not necessarily the copy.

Totes true. His selection of words is in one of the bombastic veins that rubs me the wrong way. It goes beyond just one piece of writing, that does make my issue with the writer.

Re: Basecamp was under network attack

#76

What law enforcement do you call in these situations. I imagine it would be a waste to call local police. I don't know how you would get feds to pay attention?

I believe that the Federal Bureau of Intelligence investigates and prosecutes cyber crimes[0]. [0]: http://www.fbi.gov/sanfrancisco/press-releases/2011/charges-...

Investigation, not intelligence. CIA does intelligence.

Or you could've just typed FBI, like a normal person.

Re: Basecamp was under network attack

#77
post #63
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I agree, though blackmail seems inaccurate. I've always understood blackmail to be a demand backed by a threat to reveal secret information[1]; this sounds more like an extortion racket[2]. [1] http://en.wikipedia.org/wiki/Blackmail#United_States [2] http://en.wikipedia.org/wiki/Extortion_racket

Yea, extortion seems more apt here. It's like a square and rectangle. All blackmail involves extortion, but not all extortion is blackmail.

Re: Basecamp was under network attack

#78
post #67

Earlier quoted context omitted.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

Actually, it’s not ‘a DDoS’ but a blackmail attempt, using a DDoS. That’s like confusing someone open-carrying a gun and an armed robbery. > This attack was launched together with a blackmail attempt that sought to have us pay to avoid this assault.

While I know this is a little pedantic, I'm pretty sure the analogy falls down a bit -- denial of service attacks are often illegal (for instance, in the US it's possible for them to be prosecuted under the Computer Fraud and Abuse Act or even under trespassing or contract laws). Even without the blackmail attempt this could still be considered a criminal act.

Re: Basecamp was under network attack

#79

What law enforcement do you call in these situations. I imagine it would be a waste to call local police. I don't know how you would get feds to pay attention?

Assuming the ransom request wasn't fake. It's pretty likely that the attack came from outside the US. Law enforcement will probably not be able to help at all.

Why not? The US. Law enforcement obviously doesn't have jurisdiction, but as long as a DOS is illegal in the country that the attacker sits in, the US Law enforcement should investigate and hand off to a partner agency in that country, acting as liaison and serving a request for extradition.

It's a different matter if the attacker is based in a country where DOS are legal or that doesn't have any extradition treaty with the US, but that still needs to be established.

Re: Basecamp was under network attack

#80

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

IMO if your business depends in your site being up, DDOS protection should be mandatory. You should budget for it and have it on or ready to go on short notice.

It just shouldn't be a surprise anymore that DDOS's happen.

Post reply on HN