Live data from Hacker News

LulzSec: Why we do what we do

pastebin.com

131–140 of 195 posts

Re: LulzSec: Why we do what we do

#131
post #119
post #109

Earlier quoted context omitted.

The gunshot analogy fails hard. LulzSec pre-empted at least half of it, by stressing how harm occurs quietly all the time. Data gets stolen or destroyed and we just don't know it. Unlike gunshot wound, where a person lands in a hospital, or morgue, or goes missing, data can be, and indeed is, copied quietly. Of gunshots, people are informed most of the time; of security breaches, barely ever. Cops investigate most gu…

Corporations most definitely shoot people... http://en.wikipedia.org/wiki/Military

This is what I mean when I say that bad conversation drives out good.

Re: LulzSec: Why we do what we do

#132
post #67
post #4

They seem somewhat clueless.. If the NSA can partner with ISPs to scan internet traffic for phishing, viruses, etc ...the obvious next step is Lulzsec mentions or member mentions...in IRC, email, etc.. There is no such thing as hiding when attacking the internet, sooner or later you become the bitch

It's good for the NSA that there's no way to securely communicate over an insecure medium. It's also convenient that all Internet infrastructure exists inside the USA.

You are being ironic. It actually is possible to communicate securely over an insecure medium, and not all the internet's infrastructure is in the USA. Am I right?

Re: LulzSec: Why we do what we do

#133
post #73
post #4

They seem somewhat clueless.. If the NSA can partner with ISPs to scan internet traffic for phishing, viruses, etc ...the obvious next step is Lulzsec mentions or member mentions...in IRC, email, etc.. There is no such thing as hiding when attacking the internet, sooner or later you become the bitch

Call me crazy, but I'd rather have LulzSec stealing passwords on crappy secured services than a NSA agent scanning my whole life. That would be the single worst outcome.

Really? Because the NSA could be doing it right now and you wouldn't have a clue. If someone steals your password though, chances are you'll notice.

Re: LulzSec: Why we do what we do

#134

OK, so for the remaining 3 people out there who were pathologically not paying attention, computer hacking is easy. The state of computer security is poor. Lulzsec deserves a medal and a chest to pin it on for breaking this news to all of the people who don't have a facebook account, have never been on irc, didn't see the movie wargames, don't know anyone who plays world of warcraft, has never read the new york times…

I don't see that analogy working very well. It's not about shooting single people. It's about banks building their vaults using cardboard and paper, instead of concrete and steel. It's just not that smart.

Re: LulzSec: Why we do what we do

#135
post #44

Earlier quoted context omitted.

So let's think about how traffic gets onto the network and what steps might make sense to limit that. I have some "crazy" ideas about this including per device reputation enforced as close to the device as possible. Yes, if we say that anyone with any sort of device can send data to anyone then this will be a problem. There are other options including different sorts of "darknet" type things. Are there no "outside th…

It'd need the help of browsers or OS's (depending on where in the stack you put the logic), but one idea might be to require requests/packets to be signed by something that proves a sufficient amount of CPU work has been done (ala bitcoin). If the site comes under attack, they could turn this on (presumably with a middle-man service that can take high bandwidth) and up the amount of work required to reach the destina…

Of course, botnets or LOIC would completely bypass this defense...

Re: LulzSec: Why we do what we do

#136

Earlier quoted context omitted.

I think everything else said in the post proves they are sociopaths. They don't seem to place value in "peons", "lulz lizards", or really any kind of human beings.

Having no moral doesn't make you a sociopath.

That's almost the textbook definition:

a person, as a psychopathic personality, whose behavior is antisocial and who lacks a sense of moral responsibility or social conscience.

Re: LulzSec: Why we do what we do

#137
post #67
post #4

They seem somewhat clueless.. If the NSA can partner with ISPs to scan internet traffic for phishing, viruses, etc ...the obvious next step is Lulzsec mentions or member mentions...in IRC, email, etc.. There is no such thing as hiding when attacking the internet, sooner or later you become the bitch

It's good for the NSA that there's no way to securely communicate over an insecure medium. It's also convenient that all Internet infrastructure exists inside the USA.

Given the NSA's charter, I wouldn't be surprised if most of their data interception mechanism are focused on non-US internet traffic.

Re: LulzSec: Why we do what we do

#138
post #128
post #106

Earlier quoted context omitted.

Being a victim of a random person with a gun with no particular affinity for shooting you isn't easily avoidable; being a victim of a random person with Burp Proxy and a couple hours of work is . That's the key difference here. Security is hard, but we have great processes to make things secure and keep them secure against all but the most dedicated attackers. Mind you, these processes aren't perfect. Things fall thr…

I've been kept out of Sony and all this by never consuming from them. this is the epitome of capitalism. your comment was spot on until the edit. last sony thing I paid was a cassette walkman. then after betamax, minidisc, memory stick, etc, etc, etc... you have to be a sucker to support them. sad but true. anyway, by not consuming from a company with low market ethic, I also avoided a company with bad network securi…

> this is the epitome of capitalism

Sure in your case, of an informed technology enthusiast. The average customer, however, is not aware of shoddy security practices endangering his data. Which novadays means his personal finances, too. Also, the average decision maker at the companies in question is not aware of your protest, either; it takes press attention to make him aware.

This is heavy information disparity; the market self-regulation cannot happen in such case. The customers simply cannot make informed (!) choices, nor put pressure on the website operators. Curiously enough, many of the decisionmakers at the companies may also be unaware of seriousness of the risks just as well.

LulzSec steps in. By grabbing headlines they aim to inform the widest audience of what goes on, and force press to take on the hard subject. Let's hope the press does the job well, so capitalism can do its at last.

Re: LulzSec: Why we do what we do

#139
post #122

Earlier quoted context omitted.

The difference is that LulzSec managed to get their word on every tech blog in the world. They also managed to get their basic message - nothing is safe, and here's proof - onto nearly every single major news site in existence, and they made their message immediately and personally important to millions of people. That's why I'm praising them. They don't need to propose a solution; that's already been done. They don'…

What they bring to the party is visibility. Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans. As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based…

An article on Wired gets read and forgotten. An article about passwords in the NYT gets dismissed as "newfangled kids". Ten million credit cards stolen - one of which is yours - gets remembered. Having your FB account manually and maliciously defaced changes your life. That's visibility that no article or book can sell.

Consumers are supposed to start using tools like KeePass or LastPass. Adding symbols to a simple 6-character password doesn't help. Adding symbols to a high-entropy 20-character password and never using a password twice makes you basically immune to this kind of thing.

Re: LulzSec: Why we do what we do

#140
post #16

Raise your hand if you're hesitant to write what's on your mind for fear of receiving some special attention from Anonymous, LulzSec, and friends.

I wouldn't be to worried about it, and here's why:

For Anonymous, they're driven by strong moral convictions in their attacks these days (e.g. look at this puppy killer, let's fuck him up). The wayward person on the internet is of no interest to them. I've had my info posted on 4chan in full - address, phone number, email, facebook, screen names for other things, etc, with no lasting effects. Got spammed a bit, had some strange things arrive in the mail, but nothing malicious. They'll only be mean if they think you deserve it.

LulzSec is out there with a different purpose - they want publicity. The ddos attack they just ran wasn't to strategically take out services, it was to gain publicity by temporarily taking out unimportant but socially obvious targets. The CIA website was the public facing one, the only purpose it served was to be a PR job for the CIA. Smearing their PR site gets people looking. Smearing some random guy on the internet does not.

Basically, you're not important enough to warrant attention, nor am I, and nor are most people.

Post reply on HN