Live data from Hacker News

New ‘Meow’ attack has deleted almost 4k unsecured databases

bleepingcomputer.com

131–140 of 544 posts

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#131
post #96

Earlier quoted context omitted.

Sometimes the best path forward does harm, sure. It's just hard for me to agree that deleting these databases is the harm-minimizing path. One example of a less harmful path that comes to mind immediately is installing a random password on the unsecured database and emailing the domain owner the password. That would cause downtime but it would limit the irreversible damage. You could even say that you will delete the…

What you propose is illegal in most 1st/2nd world countries. In mine, the company could thank you and then put you straight to jail for 30 years. Unfortunately very few small businesses run sade reporting programs and often react with attack.

I certainly think the most legal approach is to do nothing except notify, or maybe nothing at all. But if you must modify the database, locking it reversibly is more defensible morally.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#132
post #103

Earlier quoted context omitted.

I don't think the parent suggests it exonerates the hackers. Just that the clients are better off.

Better off? The idea that victims deserve to be victimized because they didn't take enough care is trotted out every time a security issue comes up on HN.

[deleted]

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#133
post #92

Earlier quoted context omitted.

Like, how does the local mom and pop correctly evaluate a person's IT chops? Usually by price and unfortunately both mom and pop like a bargain - I've seen this play out more times than I would like. Also how do you evaluate, say, a landscaper's chops? Or any other kind of contractor's for that matter? By doing research beforehand, checking what kind of reputation that person has etc. Low-effort or lack of research g…

In construction and landscaping work those companies are usually licensed, bonded and insured. If they fuck up the work there's obvious financial recourse. Also, the measure of them fucking up is generally a lot clearer for physical labor and for mom and pop businesses, getting construction work inspected by a 3rd party is usually more straightforward and cheaper. In software, financial recourse generally means you h…

I don't how it is in the US, but in my country an audit that would reveal such an obvious lack of security costs no more than the equivalent of a single minimum salary - usually much less. On top of that several companies that offer such services are widely known because their media presence is mostly articles about vulnerabilities in routers, phones, operating systems etc.

I hail from a post-communist country so I assumed the culture in the US is more developed in this regard.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#134
post #109

Earlier quoted context omitted.

Except that I didn’t leave the doors open. Someone I trusted with the keys, left them in their safe. Unlocked. So I rather have their whole place burned down and MY keys melted at the same time.

You are suggesting that it was just "keys" but that isn't the case here. You don't know what type of data is being destroyed. A better example might be a storage unit service that left the front gate unlocked. If someone torches the place to illustrate that they need better security would you be comfortable with that? Isn't there a better approach that we should encourage or is OK to encourage people to destroy thing…

Maybe. However, if this was my diary or photoalbum, bank statements, medical reports or anything of that sort I’d rather have them destroyed than knowing that they may have been copied... The lesson is not for the people, it’s for the companies that take shortcuts to save money. It for the MBA’s that think things don’t have to be properly engineered.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#137
post #5

Somehow I feel good about this. The article claims nothing good can come of deleting exposed databases, but I strongly disagree - I'd by far rather my data be deleted than stolen and shared. If the owner doesn't have proper backups AND can't secure a database, they have no business hosting such data, period. IMHO.

Who says it's consumer data? It can be a personal project, a blog, etc.

Just because it's not secure doesn't mean you should delete the data, because where does such reasoning end?

Reminds me of the super meat boy web version with database creds in client. Dev knew, but just did a quick implementation. Hacker wanted to prove his point and ruined it for everybody. Making a secure version was not worth the effort, so now because of this prick nobody could enjoy it.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#138
post #110
post #96

Earlier quoted context omitted.

What you propose is illegal in most 1st/2nd world countries. In mine, the company could thank you and then put you straight to jail for 30 years. Unfortunately very few small businesses run sade reporting programs and often react with attack.

So is deleting a database. Putting a password and emailing the admin would solve the password problem. But I agree doing anything is probably illegal. I would leave it... not worth hassle of wearing the superman cape.

The problem is with the e-mailing part. A mom&pop is unlikely to track you down if you lock out their DB, but they'll likely report you to police if you contact them about it.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#139
post #5

Somehow I feel good about this. The article claims nothing good can come of deleting exposed databases, but I strongly disagree - I'd by far rather my data be deleted than stolen and shared. If the owner doesn't have proper backups AND can't secure a database, they have no business hosting such data, period. IMHO.

I think this is a little simplistic. Depending on what data is being deleted, it may have real life economic consequences for individual people. What if one of the databases has a record of credits you've purchased at your local spin studio? Hopefully they have a back up, but if they don't, you and/or the owners stand to make significant losses. Are there databases that could be lost without consequence except to the…

But what about the companies making millions in profit each year that are carelessly exposing sensitive data because they don't want to spend a little more on quality IT work?

No one wants to see their local pizza shop lose their pizza-credit database, but if that's the price to pay for data security then so be it.

Re: New ‘Meow’ attack has deleted almost 4k unsecured databases

#140

Earlier quoted context omitted.

What part of the example do you dispute? Spin studios have databases, like almost all small businesses these days.

If I knew we were frying fish this small Id a brought a different pan

4000 small fish is a lot of biomass.
Post reply on HN