Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

21–30 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#21
post #3

I was just wondering why I couldn't hop on Feedly. I feel sort of bad that this is what makes me finally self host my RSS reader, since it's totally out of their control, but I've been planning on jumping ship for a while, it's just been low priority for me. Goread has been tempting me though, so I guess I'll check it out.

If you were a former Google Reader user, you might like Feedbin. I've been with them for the last year or however long and have been fairly happy.

I'll second support for Feedbin. The interface is clean and uncomplicated, it's so cheap that it really isn't worth my time to self-host, and it works with my RSS apps of choice.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#22
post #2

Do people really get punished for it? I mean the actual ones behind those bot, not the innocent ones that had their computer hacked without knowing. If yes, how long does it normally take to get them? If At all? Weeks? Months? Years? These days DDoS seems far too easy, far too common.

Yes, people get jailed for DDoS attacks, at least in the UK. For example, two attackers were jailed for 5 years in 2013 for an extortion attempt and DDoS attack against an online casino: http://www.cnmeonline.com/news/ddos-playground-bully-blackma...

Jailtime for extorting a casino sounds like a good deal.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#23

I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?

Is that really a correlation? Have we seen a decrease in zombie counts as XP machines attrition out?

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#24

I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?

Considering a lot of intrusions happen via the web browser / plugins installed in the web browser (flash/java come to mind right off the bat), I don't think XP being retired has anything to do with future botnet sizes.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#25
post #15

I wonder why they're not using Cloudflare.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

That's like saying bodyguards are a protection racket because muggers and assassins exist. Yes, it sucks to have to pay for defense, but that doesn't mean the problem is your defense vendor's fault, or that said vendor has done anything wrong at all.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#26
post #15

I wonder why they're not using Cloudflare.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

CloudFlare offers a free tier as well that provides protection.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#27
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

Wow. FYI racket is defined as offering to solve a problem that does not exist, or that would not exist if the offerer wouldn't force it upon you. Unless you're claiming the blackmail group is made up of Cloudflare employees, you should choose your words more wisely.

In the security industry I've seen people watch exploits and DDoS attacks and all sorts of chaos with unfettered glee. It's good for business, it's good for my consulting, and (IMHO the key thing) it's good for increasing the social status of security people. "This is why you listen to me!" Plus we or our friends get to be interviewed by NPR. Hi, Mom!

Still, saying they are a racket is a step too far. There were lots of accusations of the antivirus vendors purposefully releasing viruses in the 80s and 90s[1], which would certainly be a racket if it were true.

[1] Not counting the products themselves as viruses.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#28

I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?

Considering a lot of intrusions happen via the web browser / plugins installed in the web browser (flash/java come to mind right off the bat), I don't think XP being retired has anything to do with future botnet sizes.

it's a coktail,you cant only blame flash or java,the browser and the os running these stuff shares some responsibility.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#29

I guess the demise of XP is still a long ways off. If there were no XP users remaining, could there still be enough hackable computers to create a large enough botnet?

Considering a lot of intrusions happen via the web browser / plugins installed in the web browser (flash/java come to mind right off the bat), I don't think XP being retired has anything to do with future botnet sizes.

Even if everything was up to date, you still can't make sure that you don't get infected. The common hobby for kids these days: finding and writing exploits

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#30
post #18
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

It is a protection racket ONLY if they are aiding or doing the attacks. I don't see how protecting a company from DDoS attacks is a protection racket by itself, care to elaborate?

Isn't that an extortion racket when they force you to either buy their service or attack you?
Post reply on HN