Live data from Hacker News

The story around the Linode hack

straylig.ht

101–110 of 175 posts

Re: The story around the Linode hack

#101
post #24

Earlier quoted context omitted.

DNS is very compact (a few hundred bytes a query), you're talking about maybe 10mbit of traffic tops: not a hard problem these days

It's not about size, it's about rate and introducing latency. Just the hijack itself is going to add DNS latency, which is monitored by any competent operations team. Expert operations teams, and I know of one, also monitor the BGP path to their public addresses (including nameservers) to detect things like the Youtube kerfluffle. Adding a conditional ("do I answer or do I proxy?") on every DNS query -- and there are…

>Adding a conditional ("do I answer or do I proxy?") on every DNS query -- and there are many -- is going to introduce enough latency to be noticed unless you throw a lot of gear at it. And you're still going to introduce latency by inserting another hop. That's my point, though I do agree with you.

Welcome to the world of recursive name servers, there is a lot of software out there that does exactly what you just mentioned, I fail to see what would be hard about making this change.

Re: The story around the Linode hack

#102

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

You have to decide whether to take HTP at their word that they deleted credit cards.

Don't we also have to take them at their word that they even had decrypted CC's? I haven't seen any proof yet that they obtained the decrypted private key, just their statement saying they grabbed in-memory keys.

Re: The story around the Linode hack

#103
post #100

Earlier quoted context omitted.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack. "Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home withou…

Offtopic, but have you got a source for "Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country." I had a quick look on the Wikipedia page but couldn't see anything there. http://en.wikipedia.org/wiki/Nuclear_program_of_Iran

That statement is untrue. Among journalists I know of, the one who has studied this the most and reported on it in the most detail is Gareth Porter.

Re: The story around the Linode hack

#104

I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement. It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If…

The more I think about it, the more similar these sorts of groups seem to inner-city gangs. Otherwise good kids get caught up in the wrong environment, find acceptance within a peer group, and then become seduced by the intoxicating taste of power over others. As someone who engaged in my fair share of computerized mischief as a teenager, I can understand how a kid could fall into that trap. As someone who's pulled all-nighters to re-install/recover servers from attacks -- because you can never really trust your systems again, otherwise -- I don't think even the "non-profit" attackers realize the harm they cause.

If someone has a beef with society, there are plenty of honest and constructive ways of "sticking it to the man" without resorting to violating people's property.

Re: The story around the Linode hack

#105

Some of their claims seem a bit far-fetched. Hacking name.com, Xinnet, MelbourneIT, and Moniker? That would be huge. Why haven't we heard more from them? > We identified which users on HTP were involved with the FBI, and promptly gained access to one of their cams. Not sure what they mean here. FBI camera? User's laptop camera? Either way this also seems far-fetched. If everything they said was actually true it's ver…

Not so far fetched. They've posted hack logs of MelbourneIT, name.com, and Moniker in the same zine.

Re: The story around the Linode hack

#106

Earlier quoted context omitted.

> - Linode got railroaded here and the general reaction by folks is a little overdone. You know that's true when even the hackers' overview of the hack specifically calls out people bitching about Linode security on Twitter. All it takes is one zero-day, and you will all be hit by one in your career, so cut Linode a little slack. Unfortunately, there's not much slack left to cut. Linode pulled that line taught with t…

Agreed. The one thing I think Linode could do better is communicate. The secrecy model is ... odd.

I didn't pull my hosting from Linode because they got hacked, I pulled it because they were hiding this from me. I even went as far as replacing the card I used to pay them and dealing with the massive headache of updating payment info with a new card number because I didn't know if I could trust their assertion that CC numbers didn't get released.

If I can't trust you at your word, you no longer have the privilege of holding my data or my CC info. Two breeches with a lack of communication really does spoil overnight the trust that has been built up over years of wonderful and reliable service.

Re: The story around the Linode hack

#107
post #100

Earlier quoted context omitted.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack. "Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home withou…

Offtopic, but have you got a source for "Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country." I had a quick look on the Wikipedia page but couldn't see anything there. http://en.wikipedia.org/wiki/Nuclear_program_of_Iran

This is the world stage, so objectivity is hard to find, but there is a substantial amount of posturing from Mahmoud Ahmadinejad that shows a pretty aggressive stance toward Israel, if not open contempt [1].

That's really besides the point though. Anyone who seeks to boil "right and wrong" down to a simple principle that applies in all cases is holding simplicity above practicality. "Simple principles" are no more sustainable than utopian ideologies. The reality is that right and wrong are subtle and contextual. Bringing Stuxnet in to the Linode discussion is just an effort to sidetrack the topic.

Any way you slice it, HTP has dragged "innocents" in to the fight. It's not right when governments do it on the world stage. It's not right when thugs and gangsters do it by terrorizing neighborhoods with gang violence. It's not right when crackers do it during their internet turf battles.

1: http://en.wikipedia.org/wiki/Mahmoud_Ahmadinejad_and_Israel

Re: The story around the Linode hack

#108

Earlier quoted context omitted.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack. "Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home withou…

I admit Stuxnet was a bad analogy to black hat hacking. But either is the analogy of hacking into a server and physically trespassing into a private property. The main goal of my comments is to object to the opinion that hacking is somewhat comparable to physical break and enter actions. This is an age where one can find himself in prison for tens of years for hacking and getting access to information (the prospects…

You keep getting buried because you've hitched your wagon to the wrong horse. Your core argument seems to be that punishment for hacking is often disproportionate to the crime committed.

For example, poorly written laws make even simple port scanning a risky activity. I agree that this is ridiculous, but you needn't defend HTP here in order to take that position. If anything, HTP are to blame for the overreaction from policy makers. They are having a very difficult time distinguishing between mischief and mayhem.

The law should take context in to account. If you were caught exploring an old, abandoned warehouse, you might end up with a misdemeanor trespass charge (hopefully), but if you're caught probing a corporate server, the current climate seems to dictate that you'll land a felony in short order. You've got groups like HTP to thank for that because of their extortion activities and willingness to leverage the well being of innocent people in their trivial games.

Re: The story around the Linode hack

#110
post #15

Here's an attempt at an explanation/translation: HTP ("Hack The Planet") is a group that likes to break into things. Another (unnamed) group of people impersonated a third group of people ("ac1db1tch3z") and tried to cause trouble for HTP. The impersonators located HTP by examining one of HTP's botnets (a collection of compromised computers that are used to launch things like denial of service attacks). Botnets have…

> tried to cause trouble for HTP. Here's hoping the FBI "causes trouble" for the lot of them. Breaking into other people's stuff is not cool. If I leave my door open by mistake, yes, that makes me a bit absent minded, or foolish, but it does not give anyone the right to wander into my house.

Everyone bitching about HTP or AnonOps or any other hacking group that likes bragging should at least be thankful that they talk about their hacks. I would bet that the crime syndicates have better hacks and keep their mouths shut about them. Those vulnerabilities don't get patched, those customers never get notified. I am not defending HTP or the like, just saying, at least they boast.
Post reply on HN