Live data from Hacker News

Basecamp was under network attack

gist.github.com

91–100 of 194 posts

Re: Basecamp was under network attack

#91
post #70

Earlier quoted context omitted.

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

it's just framing the scenario in good guys vs bad guys terms, it's childish regardless of how accurately the term describes the actors involved..

I agree with your general sentiment wrt to good and bad, but saying these people are criminals is just plainly accurate, and specifically not attributing "badness" at all. It's extortion, which is forbidden for very good reasons and as far as I know, uncontroversially so.

I was actually marveling at how precise the wording is in this piece. Curious how different these things can come across.

Re: Basecamp was under network attack

#92

Something along the lines of CloudFlare could be an option here. However, if the attacker does indeed know the actual IP of the Bootcamp servers (and Bootcamp allows traffic from IPs other than CF) that point is moot. Set up CF, only allow traffic from CF. On another note, having CF monitor an attack like this could help them do more research into mitigating these attacks in general and allow them to try and hunt the…

I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.

Re: Basecamp was under network attack

#93
post #70

Earlier quoted context omitted.

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

it's just framing the scenario in good guys vs bad guys terms, it's childish regardless of how accurately the term describes the actors involved..

Why is it childish to point out when someone is acting criminally — in a literal sense being a bad guy? Is it somehow more adult to act as though you are morally equivalent to an extortionist?

Re: Basecamp was under network attack

#94
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

Reasonable people realize that unforeseen things happen, and might empathize with someone being targeted by a criminal enterprise a bit more than someone who just forgot to pay the electricity bill.

There is an entire movement in Sicily dedicated to highlighting and frequenting businesses that refuse to pay protection money, because in the past, paying was the norm.

http://www.addiopizzo.org/

Since that's not the kind of society I want to live in, I'd rather stand firm behind a company that refuses to deal with criminals. If companies give in as a matter of convenience to retain customers who turn a blind eye, that will only make the criminals stronger.

Now, certainly, there are measures they can take to mitigate the problem, but with all the things to do in a business, I suppose it's the kind of thing that might not be on the front burner until it happens. There are all kinds of bad, destructive things that could happen in the world, but if you spend all your time worrying about what could happen, you won't have a viable business. It's a tricky balancing act, and I'm willing to cut some slack to someone being targeted by criminals.

Re: Basecamp was under network attack

#95

Earlier quoted context omitted.

Not sure that your missile analogy holds. Most DDoS attacks do not attempt to crack logins to servers, but rather try to flood the servers with as much garbage as possible. Besides, even if they were trying to crack the SSH password, a properly secured server (long passwords/public key auth + fail2ban) should be fine.

Okay here is a better one. Just because people are blocking each other trying to run into your front door doesn't mean they (or somebody else) aren't cutting open your windows, picking the lock on your garage door, or trying to climb down your chimney.

[deleted]

Re: Basecamp was under network attack

#96
post #20
post #3

Would CloudFlare help here?

It depends if this attack is on basecamp.com or the IPs that basecamp.com resolves to. It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.

> so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP.

Why would it be easier for the attacker to find their direct servers if they only have a /23 - doesn't Cloudflare obscure the identity/location/IP of the server on the other side?

Re: Basecamp was under network attack

#97
post #11

Although a smaller service, we were in a similar situation a couple of years ago. We assumed it was a competitor because there were not monetary requests, just a massive DDoS via torrents that lasted almost a week. Data center didn't help us in any way... it was crazy. Worst thing is that 90% of customers have no clue what a DDoS is and how hard it is to handle.

"Worst thing is that 90% of customers have no clue what a DDoS is and how hard it is to handle." Otoh that's where the opportunity is. The fact that "customers have no clue". People pay you for something that they can't do themselves or that you make easier for them to do.

Pardon the off-topic reply, but I'd like to connect with you. In the breadbox article the other day, you mentioned there's an opportunity to compete with GrubHub on price. Check out forkable.com. You can reach me at joe at forkable dot com.

Re: Basecamp was under network attack

#98

Something along the lines of CloudFlare could be an option here. However, if the attacker does indeed know the actual IP of the Bootcamp servers (and Bootcamp allows traffic from IPs other than CF) that point is moot. Set up CF, only allow traffic from CF. On another note, having CF monitor an attack like this could help them do more research into mitigating these attacks in general and allow them to try and hunt the…

I personally wouldn't do any business with cloudflare, while they're still hosting the various booter sites where you can pay to run these attacks.

CloudFlare is hosting booter sites?

Re: Basecamp was under network attack

#99
A speculative thought:

Apart from being distributed, the insidious power of DDoS appears to lie in "subscriber-calling-server". Why not go the other way around? At least only for specific subscription services, not general purpose web access.

The situation of a DDoS attack is first communicated by the web service provider texting a subscriber, who texts back their present IP address. The web service provider then "calls" the subscriber from a hitherto unknown IP address. Of course, that address could be leaked too, but at least it's not obvious public knowledge like a DNS entry.

Sounds like circuit switched telephony/modems rather than packet switching, but can it be implemented in software?

Re: Basecamp was under network attack

#100
post #94

Earlier quoted context omitted.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

Reasonable people realize that unforeseen things happen, and might empathize with someone being targeted by a criminal enterprise a bit more than someone who just forgot to pay the electricity bill. There is an entire movement in Sicily dedicated to highlighting and frequenting businesses that refuse to pay protection money, because in the past, paying was the norm. http://www.addiopizzo.org/ Since that's not the kin…

I more or less agree with you, but that's kind of a false dichotomy, isn't it? Signing up for cloudflare or using a CDN isn't giving in, it's taking measures to protect yourself (and that's ignoring the other benefits you get). The unfortunate fact is DDOS attacks are becoming a daily occurrence, and if you have something to lose you should probably take measures to counteract any possible threats.

If 37Signals was a bitcoin exchange, aka a known target of DDOS attacks, the mood here would be drastically different... yet we've hit a tipping point where it seems everyone is equally at risk. DDOS attacks have become a sad cost of doing business on the internet, and just because you acknowledge that fact and try to prevent yourself from being a target doesn't mean you're capitulating to the criminal enterprise.

In fact, I don't see a better way of sticking it to the thugs than responding with "Hahaha, do your worst. We'd love to see if the money we're paying X COMPANY is worth it." And then you get to write a totally different blog post, one where you get to brag about your excellent foresight and how you have proven to your customers that the money they pay you buys a top-notch service.

Post reply on HN