Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

121–130 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#121
post #104

Earlier quoted context omitted.

I'm sorry, but in between your Straw Man argument and your indirect Ad Hominem attack, I fail to see you address the point that these kids caused harm to a business. Nowhere did I say that PHPFog bears no responsibility for the security of their service, but that doesn't excuse what these kids did one bit. I'm just much more impressed with the way that PHPFog is handling their business after the fact than these kids…

>I fail to see you address the point that these kids caused harm to a business Very well. These kids caused harm to a business. So what's that change? The business screwed up, badly. The agent of destruction is quite irrelevant. Had it been a power failure, backup failure, permissions failure, data leak, or data corruption would PHPFog deserve any less blame? This need to shift some responsibility to a bunch of kids…

> This need to shift some responsibility to a bunch of kids is nauseating.

They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it.

Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to security (not criminally irresponsibly, but if harm did come to their customers due to this, there could be possible civil liability). The fact that PHPFog bears some blame for their security practices doesn't take responsibility off the kids who broke in and vandalized their systems.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#122
post #86

Earlier quoted context omitted.

Just, do be aware that there are a lot of people that fit the description he gave; they are particularly numerous among the people who use the words "white hat" or "hacker" (with any modifier) in their services.

Downvotes because of phrasing? Here. So called 'white hat hackers' tend to be fraudulent script kiddies who couldn't hack their way out of a gibs0n. They often attend classes like this http://www.infosecinstitute.com/blog/ethical_hacking_compute... and read a book or two like this http://www.google.com/products/catalog?q=hacking+exposed&#38... . Some times they'll even have a sweet certification like this https://www…

Can you explain your "1% are sellouts" comment? Are you saying that top-tier crackers that accept money for their services are sellouts?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#123

Earlier quoted context omitted.

You're right, we're not using the same definition. That doesn't mean I don't have a point.

Of course. I guess I'm not clear what your point is though.

My point is that you must treat intrusions as an inevitability when trying to counteract intrusion. And anyone who builds a sandcastle should be aware of the ocean. The kid's breaking into this account is embarrassing.

Just because we can hold individual humans accountable (and should) doesn't mean we shouldn't have the perspective of "CONSTANT VIGILANCE."

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#124
post #121
post #104

Earlier quoted context omitted.

>I fail to see you address the point that these kids caused harm to a business Very well. These kids caused harm to a business. So what's that change? The business screwed up, badly. The agent of destruction is quite irrelevant. Had it been a power failure, backup failure, permissions failure, data leak, or data corruption would PHPFog deserve any less blame? This need to shift some responsibility to a bunch of kids…

> This need to shift some responsibility to a bunch of kids is nauseating. They aren't shifting responsibility. The kids are responsible for their own actions. They did something illegal. They are responsible for it. Now, PHPFog is also responsible for protecting their customers; they are supposed to provide a secure hosting environment. PHPFog is a victim here, but has also acted irresponsibly with regards to securi…

>They aren't shifting responsibility

Yes PHPFog is. The only reason these kids are even mentioned in the blog post is to shift blame. Their part in the post serves no other purpose.

The entire event could have been recounted without a single personification of the hackers in the blog post.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#125
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

The article starts out in that tone, but it changes to be pretty remorseful after that. For example the "why it won't happen again" part.

I agree with parfe's comment below.

They sound incredibly laxed on security and the "we were days away from fixing it" could be complete bull. To Lucas, it probably sounds better to say they were close to fixing it instead of admitting they were unaware of these exploits.

I find the disclosure in the blog post great, but the conditions they had leading up to the hack very disappointing.

If they were aware of the exploits, they should have taken quicker action. They'll probably be focusing on security big time now... they have no other choice.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#126
post #65
post #18

Earlier quoted context omitted.

Lucas and his team are amazing. Everyone makes mistakes, and no system will be perfectly secure. So in my mind the best parts of the entire post were these: "We have hired professional white hat hackers with government level security experience to attempt regular pen tests on our system, both as regular users as well as giving them special access and seeing if they can get through." and "If you find a security flaw a…

Hiring white hat hackers is a joke. They are the ultimate in hacks. Step 1. Open up Metasploit Step 2. Button Mash. ???? Step 3. Profit

Nessus?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#127
post #119

Earlier quoted context omitted.

You know what we call kids who loot bank vaults? Bank robbers.

No, we call them juvenile delinquents and treat them like children. And we certainly don't call the bank the victim.

1. We don't treat them like adult criminals (necessarily), but we certainly treat them like criminals. Here are some examples (some harsher than others):

Bank robber, 13, could get 21 years in US jail (http://www.breitbart.com/article.php?id=CNG.cb17379375828ffc...)

Teen bank robber to be held for two years (http://www.morningjournal.com/articles/2011/02/18/news/doc4d...)

Boy, 15, Charged in Armed Bank Robbery in Lancaster (http://articles.latimes.com/2002/aug/09/local/me-bankrob9)

2. Why do you think banks aren't considered victims in cases of robbery? Because they could have done more to prevent the robbery from happening?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#128
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

The problem with pressing charges as a detterrent is that it is fundamentally unjust, because the punishment is set up as a detterrent and is disproportionate to the crime. Example: imagine the country of Dictatoria where if you jaywalk you are publicly tortured for a couple of weeks and then put to death. "As a detterrent" A little extreme? Well, consider the 10-20 (or more) year sentences for cyber-terrorism these…

Why do you think these kids would get 10-20 year sentences? Have you ever heard of a computer crime getting that high of a sentence? No one on http://en.wikipedia.org/wiki/List_of_convicted_computer_crim... has gotten more than 5 years, and they include people who have sold access to botnets of hundreds of thousands of machines. A quick Google search reveals someone sentenced to 20 years, but for stealing millions of credit and debit card numbers, which is actually a sizable crime with significant damage to many victims. http://www.scmagazineus.com/hacker-albert-gonzalez-receives-...

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#129
Leaving the doors to your house wide open does not grant every passerby the right to enter.

So, yeah, PHPFog screwed up and did that. Then these kids went in, threw paint on the walls, smashed some windows, etc.

PHPFog was stupid - they admitted that.

The kids were criminal.

The first is not illegal - the second is.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#130

Earlier quoted context omitted.

Of course. I guess I'm not clear what your point is though.

My point is that you must treat intrusions as an inevitability when trying to counteract intrusion. And anyone who builds a sandcastle should be aware of the ocean. The kid's breaking into this account is embarrassing. Just because we can hold individual humans accountable (and should) doesn't mean we shouldn't have the perspective of "CONSTANT VIGILANCE."

Still, does that really hold up?

Certainly should have to treat intrusions as inevitable in designing the system, but there still is responsibility on the part of the intruder.

I lock my door because I consider it inevitable that someone will eventually try and break in. However, if someone does break into and vandalize my apartment, I sure as hell would consider them responsible and not consider in an act of God.

Post reply on HN