Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

31–40 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#31
post #11
post #4

Earlier quoted context omitted.

I quite liked this article about the issue. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... > The shocking thing about these DDoS-for-hire services is that — as I’ve reported in several previous stories — a majority of them are run by young kids who apparently can think of no better way to prove how cool and “leet” they are than by wantonly knocking Web sites offline and by launching hugely disruptive…

From Wiki "For the time being there are no good technical means to counteract misuse of NTP servers" Sigh

Drop all port 123 packets that are heading to the DDOS'd server from anything but the authorized NTP server is a pretty good start.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#32
post #28

Earlier quoted context omitted.

Considering a lot of intrusions happen via the web browser / plugins installed in the web browser (flash/java come to mind right off the bat), I don't think XP being retired has anything to do with future botnet sizes.

it's a coktail,you cant only blame flash or java,the browser and the os running these stuff shares some responsibility.

Exactly how is the OS supposed to stop an exploited browser from doing anything malicious? Even if you have strict access controls like SELinux, that won't stop a browser from participating in a DDOS attack and changing settings like cache or homepage to get reinfected next session. And if you don't have strict access controls, like 99% of desktops, the exploited browser can freely install all the user-mode malware it wants. So XP vs. not-XP is completely meaningless at this stage.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#33
post #18
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

It is a protection racket ONLY if they are aiding or doing the attacks. I don't see how protecting a company from DDoS attacks is a protection racket by itself, care to elaborate?

From what I have read, Cloudflare takes considerable flack because they willingly provide services to the websites that let you buy and sell ddos-for-hire services.

Also, I believe their defense is "we are a proxy, not the host, go elsewhere to complain". So, yes- They appear to allow these booters to exist and thrive in a world where they were unable to (at this level) before.

* http://www.webhostingtalk.com/showthread.php?t=1235995 * http://www.organicweb.com.au/17240/internet/cloudflare-secur... * http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#34
post #3

I was just wondering why I couldn't hop on Feedly. I feel sort of bad that this is what makes me finally self host my RSS reader, since it's totally out of their control, but I've been planning on jumping ship for a while, it's just been low priority for me. Goread has been tempting me though, so I guess I'll check it out.

If you were a former Google Reader user, you might like Feedbin. I've been with them for the last year or however long and have been fairly happy.

How does this solve the problem of another DDoS against some other RSS reader? Are you going to suggest that if Feedbin gets attacked next, to hop to the next product?

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#35
post #18
post #15

Earlier quoted context omitted.

Cloud flare is a protection racket. Some people don't use them on principle. They are the vendor selling chastity belts to stop rape. It is in their best economic interest that these attacks continue. It's sad that to run a service now the expectation is to shovel money to another service to absorb UDP packets.

It is a protection racket ONLY if they are aiding or doing the attacks. I don't see how protecting a company from DDoS attacks is a protection racket by itself, care to elaborate?

[deleted]

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#36
post #6

Earlier quoted context omitted.

There will always be people who want to get some easy money and have the brains for that. Instead of playing the cat and mouse game we better take care that our networks are protected from, at least, small to mid-range DDoS attacks. The alternative is potential oppression from the governments - "you fear the bad guys, OK, then we will take some more freedoms from you and improve our surveillance to catch them".

There's no reason you can't punish criminals like this and still have a free, democratic, and open society.

Criminals work hard to re-invest their money in the upper world. Once they successfully do that punishing them can become very hard. Free, democratic and open societies are far more vulnerable to this than dictatorships, there you are either part of the 'in-group' or you're going to be hunted.

An open society makes the assumption that people play by the rules and that those that do not will be caught and can be punished. But in reality that assumption does not hold true. Witness the extent to which the Mafia has been able to ruin your country. They've managed to infiltrate the highest echelons of politics, live like kings and in general are so far above the law that it's farcical.

Punishment is for small time criminals. So yes, hackers, burglars, extortionists and so on stand some chance of being caught. But the big fish (in this case, the bosses of the hackers) will likely get away with it while some patsy does time.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#37
post #11
post #4

Earlier quoted context omitted.

I quite liked this article about the issue. http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... > The shocking thing about these DDoS-for-hire services is that — as I’ve reported in several previous stories — a majority of them are run by young kids who apparently can think of no better way to prove how cool and “leet” they are than by wantonly knocking Web sites offline and by launching hugely disruptive…

From Wiki "For the time being there are no good technical means to counteract misuse of NTP servers" Sigh

Is there a good reason for someone to want a high volume of NTP requests? How do the owners of these servers not share more of the blame for sending so much data at a web server?

It should be straight forward to implement a protocol that each NTP server won't send data to the same ip more than once every 10 seconds regardless of the number of requests.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#38
post #11

Earlier quoted context omitted.

From Wiki "For the time being there are no good technical means to counteract misuse of NTP servers" Sigh

Drop all port 123 packets that are heading to the DDOS'd server from anything but the authorized NTP server is a pretty good start.

Where do you drop the packets? If your filter is inside your own network, and your bottleneck is your network connection to the outside world, then you're out of luck.

If you can arrange with your upstream internet access provider for them to filter out junk before it hits the bottleneck, then great - but that involves cooperating with people, which may take some time.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#39
post #6

Earlier quoted context omitted.

There's no reason you can't punish criminals like this and still have a free, democratic, and open society.

Criminals work hard to re-invest their money in the upper world. Once they successfully do that punishing them can become very hard. Free, democratic and open societies are far more vulnerable to this than dictatorships, there you are either part of the 'in-group' or you're going to be hunted. An open society makes the assumption that people play by the rules and that those that do not will be caught and can be punis…

Italy is the country where I live, but I'm not sure I'd call it "mine". If it were mine, I'd run it differently :-) I am not a citizen in any event.

I think you're wrong in any event: the more open and well run a society is, the harder it is for mafias to really take root. That's why they are stronger in places like Italy than in, say, Sweden: http://en.wikipedia.org/wiki/The_Moral_Basis_of_a_Backward_S...

And truth be told, there has been progress in the fight against the Mafia, just that it's a long slog, not something that's going to be fixed from one day to the next.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#40
post #18

Earlier quoted context omitted.

It is a protection racket ONLY if they are aiding or doing the attacks. I don't see how protecting a company from DDoS attacks is a protection racket by itself, care to elaborate?

From what I have read, Cloudflare takes considerable flack because they willingly provide services to the websites that let you buy and sell ddos-for-hire services. Also, I believe their defense is "we are a proxy, not the host, go elsewhere to complain". So, yes- They appear to allow these booters to exist and thrive in a world where they were unable to (at this level) before. * http://www.webhostingtalk.com/showthr…

Allow them to exist, yes.

Help them thrive, how? I don't understand. Because they prevent DDOS-for-hire services from attacking each other? Surely "other DDOS-for-hire operators" are not the people charged with stopping DDOS-for-hire services.

Post reply on HN