Live data from Hacker News

Basecamp was under network attack

gist.github.com

171–180 of 194 posts

Re: Basecamp was under network attack

#171
post #129

I've had really negative experience with these type of criminals. I was hired as a CEO at an company ($200m+ revenue) and we were hit by this type of attack. Every second of being down cost us literally $10k, so we quickly negotiated with criminals for $5k one time payment and they stopped the attack. Unfortunataly a few weeks later we were hit by 3 new attacks. Apparently the word had spread and these new attackers…

Why did it fall on your shoulders and not the CTO / tech team? How did they let you go in a few days? They called a board meeting immediately after to fire you?

Re: Basecamp was under network attack

#172

We got hit by a DDoS about a year ago. Rackspace (who normally has amazing support) quietly null routed us and went about their day. No heads-up, trouble ticket, or any other form of notification. They didn't even put a note in our account so when we contacted their support to figure out why our servers were unresponsive outside their network the poor guy who answered the phone was just as confused as I was. We've ta…

I'm running a small SaaS business. I'm curious to hear what steps you took to reduce your vulnerability. Could you please share so others can take the same steps?

Re: Basecamp was under network attack

#173
post #144

Earlier quoted context omitted.

Why is it childish to point out when someone is acting criminally — in a literal sense being a bad guy? Is it somehow more adult to act as though you are morally equivalent to an extortionist?

I think people might be being offended-by-proxy by a sort of status-shift 37s is trying to work into its language. Calling someone "an extortionist" still implies a sort of high-status white-collar cunning-and-intelligence, of the kind you'd expect of a person in the tech industry. An evil person, surely, but the respectable, movie-villain-you-love-to-hate kind of evil. Calling someone "a criminal", meanwhile, degrad…

Calling someone a criminal degrades their status from someone who doesn't commit crime to someone who does. It degrades them from someone who adds value to someone who takes value.

There is moral judgement involved with calling someone a criminal, and rightfully so. Taking what other people have created by force or extortion degrades society.

Re: Basecamp was under network attack

#174

I take it at one point people will start to believe that I work for OVH (I really don't) but... OVH has a mandatory DDoS protection on all its dedicated servers: fees have been slightly raised to take that mandatory protection into account. There are a few gotchas, including if I understand it correctly the need to "retry twice" when you try to SSH in your server when a DDoS is going on but... OVH doesn't even feel a…

Yes, I also have an OVH server, and I've gotten the email "You're getting DDOSed, we're handling it" (paraphrasing) about a half dozen times. Each time, it's a seamless transition.

I'm a big fan of OVH.

Re: Basecamp was under network attack

#175
post #167

Earlier quoted context omitted.

While I know this is a little pedantic, I'm pretty sure the analogy falls down a bit -- denial of service attacks are often illegal (for instance, in the US it's possible for them to be prosecuted under the Computer Fraud and Abuse Act or even under trespassing or contract laws). Even without the blackmail attempt this could still be considered a criminal act.

So are open carry in most countries. You don’t come off as pedantic, just US-centric.

The US is far from the only country to make DDoS a crime or tort in various situations.

Re: Basecamp was under network attack

#176
post #175
post #167

Earlier quoted context omitted.

So are open carry in most countries. You don’t come off as pedantic, just US-centric.

The US is far from the only country to make DDoS a crime or tort in various situations.

Of course not, and that was not my point.

The original comment said that because DDoS could be illegal, is was different from openly carrying a fire-arm; that assumes that openly carrying a firearm isn’t illegal. It often is, outside of the US -- hence my response.

I would have appreciated you didn’t downvote me before you understood that.

Re: Basecamp was under network attack

#177
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

I always liked how the Japanese apologised. There is no excuse as its irrelevant, all you get is an apology, compensation and how/why it wont occur again. Not sure if that was an industry specific thing but it sure was effective.

Re: Basecamp was under network attack

#178
post #176
post #175

Earlier quoted context omitted.

The US is far from the only country to make DDoS a crime or tort in various situations.

Of course not, and that was not my point. The original comment said that because DDoS could be illegal, is was different from openly carrying a fire-arm; that assumes that openly carrying a firearm isn’t illegal. It often is, outside of the US -- hence my response. I would have appreciated you didn’t downvote me before you understood that.

Fair enough, but the comment you had replied to had assumed quite reasonably that DDoS is a criminal act, and I can only assume your response quibbling about that was $SOMETHING-centric. Apologies for the downvote but that impression changed my interpretation of your later comment.

Re: Basecamp was under network attack

#180
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I agree that DHH is such a great writer. He used the metaphor of a people blocking down your house so that non-technical users can easily understand what he's saying.
Post reply on HN