Live data from Hacker News

Feedly gets hit by DDoS attack, refuses to give in to blackmail

grahamcluley.com

71–80 of 137 posts

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#71

Earlier quoted context omitted.

If you were a former Google Reader user, you might like Feedbin. I've been with them for the last year or however long and have been fairly happy.

I've been using Digg Reader for a while and I'm actually kind of shocked that most people haven't moved to that. It has its bugs (sometimes showing incorrect numbers, the mobile app locks up sometimes), but it's honestly the best alternative that I've found so far. Maybe it has to do with its free-ness, as people worry about them shutting doors like Google Reader, but if you're looking for a free solution then I'd de…

I was a very happy Digg Reader user for a while, but the bugs just kept getting worse and worse, and I jumped ship.

Now I'm on BazQux, which works very, very well and very, very quickly, but has no mobile version and a design straight out of 1996.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#73
post #11

Earlier quoted context omitted.

From Wiki "For the time being there are no good technical means to counteract misuse of NTP servers" Sigh

Is there a good reason for someone to want a high volume of NTP requests? How do the owners of these servers not share more of the blame for sending so much data at a web server? It should be straight forward to implement a protocol that each NTP server won't send data to the same ip more than once every 10 seconds regardless of the number of requests.

It's already been fixed. Newer version of NTP don't reply with more data than it gets sent, so you can't use the server for amplification. It's servers that have not been updated that are issues.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#74
post #2

Do people really get punished for it? I mean the actual ones behind those bot, not the innocent ones that had their computer hacked without knowing. If yes, how long does it normally take to get them? If At all? Weeks? Months? Years? These days DDoS seems far too easy, far too common.

Why do you think someone is innocent if they let some third party use their computer without permission? For essentially all malware that makes your computer part of a larger botnet, you have to be extremely careless to let it get on your device, not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime (or just misused by playing kids). The latter is illegal[0], why should the fo…

"not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime"

In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime?

Victim blaming is not the answer, it's just silly.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#75
post #66

Earlier quoted context omitted.

Why do you think someone is innocent if they let some third party use their computer without permission? For essentially all malware that makes your computer part of a larger botnet, you have to be extremely careless to let it get on your device, not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime (or just misused by playing kids). The latter is illegal[0], why should the fo…

From our perspective - yes, that's pretty silly. But we are different, we are extremely far from the majority. For many many people, computer is just a box for writing stuff in MS Word and watching porn.

Tell dont not to open .exe file in Email. "What is .exe files?"

Dont use IE "What is IE? Next time they click on it to get to the Internet"

Can You please stoping using XP? "Why should I pay for upgrade when everything i do is working perfectly fine?"

Honestly, there are people who dont know Shxt. And they dont want to know about it either. To them even basic computer usage is extremely complex. That is why Tablet, is getting the traction in Grandma and others who dont want anything but a Internet and Application capable Appliance.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#76
post #44

Earlier quoted context omitted.

Any suggestions on the best RSS reader to self-host?

I like TT-RSS, mostly because it's easy to install, doesn't require a beefy machine, and support themes and plugins. For example, I use it with the feedly theme ( https://github.com/levito/tt-rss-feedly-theme ) and af_feedmod to get a full text feed for various sites ( https://github.com/m42e/ttrss_plugin-af_feedmod ).

Second the recommendation for TT-RSS. For a few bucks it has a good Android app that can hook into your self-hosted server as well. For me it beats a plain old "dumb" mobile app with no sync service since I check so infrequently that I'll sometimes miss stories on feeds that don't maintain a full backlog of posts--it gives me peace of mind knowing that I have a cron job saving everything for me even when I'm not actively doing anything.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#77

Earlier quoted context omitted.

Wow. FYI racket is defined as offering to solve a problem that does not exist, or that would not exist if the offerer wouldn't force it upon you. Unless you're claiming the blackmail group is made up of Cloudflare employees, you should choose your words more wisely.

In the security industry I've seen people watch exploits and DDoS attacks and all sorts of chaos with unfettered glee. It's good for business, it's good for my consulting, and (IMHO the key thing) it's good for increasing the social status of security people. "This is why you listen to me!" Plus we or our friends get to be interviewed by NPR. Hi, Mom! Still, saying they are a racket is a step too far. There were lots…

> [1] Not counting the products themselves as viruses.

Pretty bold assumption IMO

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#78

Earlier quoted context omitted.

Why do you think someone is innocent if they let some third party use their computer without permission? For essentially all malware that makes your computer part of a larger botnet, you have to be extremely careless to let it get on your device, not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime (or just misused by playing kids). The latter is illegal[0], why should the fo…

"not dissimilar to leaving your car unlocked when it is subsequently stolen and used in a crime" In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime? Victim blaming is not the answer, it's just silly.

> In the US at least, this is not a crime. If someone leaves their car unlocked by accident, why should they get punished if someone steals it and uses it for a crime?

Negligence. If you own a powerful tool, you are at least in part responsible for it not to be misused. Similarly to how you are usually required to keep your guns locked away and are held responsible (at least ideally…) if someone steals them from your kitchen table and misuses them, you are held responsible if someone just sits in your car and drives off to kill someone.

> Victim blaming is not the answer, it's just silly.

Except that the victim in a DDoS is the person being ddos’d, not the random user who installed malware. If someone gave you a key and said “Enter this flat over there, take the computer, bring it to me and I’ll give you 10€“, you couldn’t later claim to be a “victim” because they stole your time. If someone sends you a file and goes “double-click this and you’ll get fantastic porn”, I don’t see how you could later claim to be a victim if they stole part of your data cap.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#79
post #75
post #66

Earlier quoted context omitted.

From our perspective - yes, that's pretty silly. But we are different, we are extremely far from the majority. For many many people, computer is just a box for writing stuff in MS Word and watching porn.

Tell dont not to open .exe file in Email. "What is .exe files?" Dont use IE "What is IE? Next time they click on it to get to the Internet" Can You please stoping using XP? "Why should I pay for upgrade when everything i do is working perfectly fine?" Honestly, there are people who dont know Shxt. And they dont want to know about it either. To them even basic computer usage is extremely complex. That is why Tablet, i…

How much do you know about your car's internal combustion engine and components?

Your home electrical?

Your home plumbing? Natural Gas? Lawn care?

The pumps that fuel your car tank?

Not everyone can be an expert in everything. Someone who makes their living perfecting one of those aspects might look at things you do and say "don't do that, you're damaging it" but to you its "who cares? I just need it to work and its been fine up until now!"

Computers/software might be your thing but they're not Grandma's so don't push your agenda on someone just because they might have some ignorance you don't.

Re: Feedly gets hit by DDoS attack, refuses to give in to blackmail

#80

Earlier quoted context omitted.

DDOS-for-hire websites are naturally unstable - if not for the protection CloudFlare provides, they would all knock one another offline and there would be no DDOS-for-hire websites (or only a single, expensive winner). Depending on your point of view, cloudflare providing the protection that makes DDOS-for-hire possible is either (a) them being fair and website-content-neutral, anything else would be censorship or (b…

The DDOS-for-hire company doesn't need a significant or even continuous web presence, does it? Seems ineffective to DDOS them. EDIT Surely many of these DDOS-for-hire companies cross into illegal territory. CF can maintain a content-neutral stance by kicking illegal activity off.

Illegal where?

Their position is a reasonable one: they are not the host, they are not responsible for content, don't ask them to censor.

Post reply on HN