Live data from Hacker News

Basecamp was under network attack

gist.github.com

161–170 of 194 posts

Re: Basecamp was under network attack

#161
post #120

Earlier quoted context omitted.

IANAL, but I've seen this discussion come up multiple times, and the problem is that the counterattack would technically be illegal. The fact that somebody else has already broken the law in order to compromise an innocent bystander does not give anybody else the right to do the same thing. Vigilantism is as illegal on the internet as it is in the real world. This is a huge constraint for the people (e.g. at Microsof…

But this could be considered self-defense which is granted by most law systems.

Self-defense is granted only for a direct, immediate physical threat - for example, if someone is blackmailing you, defrauding you or extorting "fire insurance for your warehouse" then self-defense doesn't allow you to do anything to them; if you smash the computer of a blackmailer, it's just as any other computer-smashing.

Re: Basecamp was under network attack

#162
post #140

Earlier quoted context omitted.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

So if a pizza delivery guy gets shot on the way do you still demand better service? Just trying to see if you believe in the principle or just the practical aspect. :)

Better analogy would be if the "criminals" flooded the streets with bicycles or cars preventing the pizza delivery guy from delivering your order.

Straight up murder doesn't quite fit the situation here.

Re: Basecamp was under network attack

#163
post #37

Earlier quoted context omitted.

While I agree, the term blackmailer or extortionist would had been better.

Not all blackmail is a crime. I blackmail my kids all the time... ("Wash your hands after using the bathroom or you will put 25 cents in this jar")

That's not blackmail ... "wash you hands or I'll tell your sister that you killed her pet fish" ... is blackmail. What your describing is more like extortion.

Re: Basecamp was under network attack

#164

Earlier quoted context omitted.

CloudFlare's CEO, Matthew Prince, has made his stance on this matter very clear: CloudFlare is firm in our belief that our role is not that of Internet censor. There are tens of thousands of websites currently using CloudFlare's network. Some of them contain information I find troubling. Such is the nature of a free and open network and, as an organization that aims to make the whole Internet faster and safer, such i…

Well, do you believe that suppressing someone else's right to free speech is still free speech? Information isn't really the question here. These aren't sites telling people how to conduct DDOS attacks, these are sites where you pay them, and they run a DDOS for you. This effectively silences someone until they either give up on their message, or sign up for expensive DDOS mitigation packages (or Cloudflare). You may…

CloudFlare aren't the Free Speech Police. It's clearly not their job to guarantee everyone's right to free speech. However, it would appear that they have decided that they will not deny their customers their right to free speech unless they're breaking the law. I respect that approach.

You clearly don't and you're entitled to your opinion.

Re: Basecamp was under network attack

#165
post #3

Would CloudFlare help here?

Depends on the scale/power of attack. The latest hits (happening in the last few months) have been very large and I doubt CloudFlare would be able to successfully defend any of those while maintaining all of the current clients online. I have a client that occasionally gets this kind of blackmailing followed by attacks and they told me they use a US based company specialized in DDoS defending - until now the defense…

You're mistaken. CloudFlare has mitigated many the largest DDoS attacks in history, including some that have exceeded 400Gbps. These recent extortion-based attacks are large, but they are typically 1/10th the volume of the largest attacks we see. For instance, Meetup has publicly stated that they used our network to stop a similar attack. Many of the other recent victims have used CloudFlare as well.

Because of the unique design of our network, I'm unaware of any other service that has as much capacity that can be utilized in aggregate to mitigate large-scale attacks.

Matthew Prince Co-founder & CEO, CloudFlare

Re: Basecamp was under network attack

#166

We got hit by a DDoS about a year ago. Rackspace (who normally has amazing support) quietly null routed us and went about their day. No heads-up, trouble ticket, or any other form of notification. They didn't even put a note in our account so when we contacted their support to figure out why our servers were unresponsive outside their network the poor guy who answered the phone was just as confused as I was. We've ta…

Yep Rackspace did little to nothing to help us but null routing.

Re: Basecamp was under network attack

#167
post #67

Earlier quoted context omitted.

Actually, it’s not ‘a DDoS’ but a blackmail attempt, using a DDoS. That’s like confusing someone open-carrying a gun and an armed robbery. > This attack was launched together with a blackmail attempt that sought to have us pay to avoid this assault.

While I know this is a little pedantic, I'm pretty sure the analogy falls down a bit -- denial of service attacks are often illegal (for instance, in the US it's possible for them to be prosecuted under the Computer Fraud and Abuse Act or even under trespassing or contract laws). Even without the blackmail attempt this could still be considered a criminal act.

So are open carry in most countries. You don’t come off as pedantic, just US-centric.

Re: Basecamp was under network attack

#169
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

Are we sure it is actually a DDOS? I mean, this is a Rails app - it might just be more than three users hitting it at the same time, and it cannot cope with the load?

Re: Basecamp was under network attack

#170
post #129

I've had really negative experience with these type of criminals. I was hired as a CEO at an company ($200m+ revenue) and we were hit by this type of attack. Every second of being down cost us literally $10k, so we quickly negotiated with criminals for $5k one time payment and they stopped the attack. Unfortunataly a few weeks later we were hit by 3 new attacks. Apparently the word had spread and these new attackers…

That's a good reason why it's never a good idea to pay for DDOS threats - in many other popular extortion scenarios such as kidnapping, blackmail w. secret info or mafia 'protection money' for storefronts, the deal generally doesn't allow other, new attackers to make the same demands, so you actually are getting some protection - but here it does simply mark you as vulnerable.

Same goes when bribing a cop here. If you bribe too much you're targeted as easy money among the other cops here. Say for example you're caught driving without your insurance, you bribe and then every other cop knows you don't have insurance and squeeze you for money left and right.

Source: 3rd world south america

Post reply on HN