Live data from Hacker News

AOL Moloch: open-source, large scale, packet-capturing, indexing database system

molo.ch

121–130 of 156 posts

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#121

The Filesystem Hierarchy Standard [0] has been around for ~25 years but it still took quite a long time before most Linux distros decided to adhere to it (for the most part; some still do "non-standard" things at times). Now that we're to that point, please stop screwing it up and coming up wih your own locations for application binaries, data, etc. To be clear, the "/data" directory -- under which Moloch's pre-built…

This is probably intended to be run in a container, but as that's not specified, it's certainly extremely weird.

Even inside a container, you want stuff in the standard places, for minimal surprises.

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#122

Not the greatest choice of name: Moloch[a] (also Molech, Mollok, Milcom, or Malcam) is the biblical name of a Canaanite god associated with child sacrifice, through fire or war. From: https://en.wikipedia.org/wiki/Moloch

Sheesh, I hope no-one looks up my user name on wikipedia..

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#123
post #20

Fun fact, Moloch was initially created with funding from DARPA's famous Cyber Fast Track program! It's great to see that Moloch is still going strong since ~2013. There is some previous discussion of Moloch when it was released in this older thread: https://news.ycombinator.com/item?id=20586005

What can you do with a packet capture on a modern high security network besides go, "yup, that's TLS"? May DoD turns off the forward secrecy stuff and escrows keys?

In large part you're not looking at TLS application-data with this stuff; you're monitoring internal networks and all the protocols they run, in part so you can retroactively see if exploits, once revealed, have been run. For that kind of stuff you often care a lot more about, say, SMB dissection than you do about what stupid websites people are looking at.

The longstanding existence of tools like these --- and there are "better" ones that aren't open source, and have been for decades --- is one reason that "vulnerability equities processes" don't make sense; if the DoD uses an exploit against a foreign target, it can't just reveal it a few months later without compromising sources and methods.

(That doesn't mean you should care about that problem; I'm just reporting).

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#124
post #4

This is cool, thanks for sharing! I'll be honest, I didn't think AOL did anything...interesting...but this is interesting to me! What are some open-source alternatives / analogues to this product?

> I'll be honest, I didn't think AOL did anything...interesting...

Well, there is also https://github.com/aol/ExtJS4-Fart

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#125

The amount of professional-grade hand-wringing virtue-signaling in this comment section makes me feel ill. Why get bent out of shape over the name of a software project? It's virtually a meaningless factor in day-to-day life. What about hearing phrases "Sacrificing a Chicken to Moloch," the "spirit cooking" culture and related symbolism rampant in elite political circles? Shouldn't we be more interested in that? Lots…

If you have a strong, negative emotional response to the name of a project, I think letting the project author know can be helpful. I’m a rational guy to the best of my ability, but FWIW I would avoid using this project solely because of its name (just the thought of that name evokes a sick feeling to me - that’s how strong the negative association is... I won’t explain why as this isn’t an appropriate venue for that…

If they named it something like “Pinochet” or PIZZAGATE, I’m sure we’d be getting completely different responses from the same people who think naming a project after a child sacrifice idol is “funny” or “cool“.

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#126

Seriously "Moloch", was Lucifer or Satan taken already? Edit: And the logo is an owl lmao hard pass - what can they gain from this?

Well, there's already a database called Voldemort...

We had a client that forbade us from using their real name even in internal communication. Formaly they where called "client 123" but informaly we called them "Voldemort". They where (really!) absolutely delighted when they found out

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#127

Earlier quoted context omitted.

If you have a strong, negative emotional response to the name of a project, I think letting the project author know can be helpful. I’m a rational guy to the best of my ability, but FWIW I would avoid using this project solely because of its name (just the thought of that name evokes a sick feeling to me - that’s how strong the negative association is... I won’t explain why as this isn’t an appropriate venue for that…

If they named it something like “ Pinochet ” or PIZZAGATE , I’m sure we’d be getting completely different responses from the same people who think naming a project after a child sacrifice idol is “funny” or “cool“.

Do you have a list of forbidden words ? Asking for a friend.

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#128

The Filesystem Hierarchy Standard [0] has been around for ~25 years but it still took quite a long time before most Linux distros decided to adhere to it (for the most part; some still do "non-standard" things at times). Now that we're to that point, please stop screwing it up and coming up wih your own locations for application binaries, data, etc. To be clear, the "/data" directory -- under which Moloch's pre-built…

If you look at the source code of most open source software, the devs typically install by default to arbitrary directories. They either don't know about, or care about, operating system standards. When Linux distributions package that software, they choose to change how that software works to align with standards. Usually their own standards, but those can often align with distro-independent standards too. But as a packager, you expect that you'll be modifying paths and making patches.

So really it doesn't matter where a random dev decides to install their software to by default, since either A) it's proprietary and it's non-standard anyway, or B) it's up to us to package it the way we want it.

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#129
post #4

This is cool, thanks for sharing! I'll be honest, I didn't think AOL did anything...interesting...but this is interesting to me! What are some open-source alternatives / analogues to this product?

AOL bought one of the first web server start-ups in 1995 and open-sourced the tech in 1999. It was pretty advanced for the time. http://philip.greenspun.com/wtr/aolserver/introduction-1.htm...

Re: AOL Moloch: open-source, large scale, packet-capturing, indexing database system

#130
post #12
post #6

Earlier quoted context omitted.

Perhaps they were going for an association with Allen Ginsburg's Howl ( https://www.poetryfoundation.org/poems/49303/howl ) instead?

Reminds me of when someone saw that the NSA's public key ( http://www.cypherspace.org/adam/hacks/lotus-nsa-key.html ) to be included in Lotus Notes had an organizational name of "MiniTruth", and a common name of "Big Brother". Moloch isn't the good guy in Howl. Moloch! Solitude! Filth! Ugliness! Ashcans and unobtainable dollars! Children screaming under the stairways! Boys sobbing in armies! Old men weeping in the pa…

Moloch the dude in the cubicle across from mine that always eats his lunch at his desk and chews with his mouth open!

Moloch the meddling micromanager from Maine!

Moloch the Junior Architect!

Moloch the 3-space indenter!

Post reply on HN