Live data from Hacker News

Please Stop Attacking MIT's Network

blog.achernya.com

191–200 of 220 posts

Re: Please Stop Attacking MIT's Network

#191
post #23

I suppose the one silver lining is that this could be useful data for MIT admins to locate weaknesses in their network.

So maybe we should punch random strangers in the face in hopes of locating their weaknesses at stopping punches?

Not strangers. Just women and children.

Re: Please Stop Attacking MIT's Network

#193
post #143

Earlier quoted context omitted.

Do you have a link to the evidence? My current understanding is that MIT didn't want Aaron to avoid jail. Is that correct ?

The evidence is comments by Aaron's lawyer as quoted in the Boston Globe. See http://www.bostonglobe.com/metro/2013/01/15/humanity-deficit... for the article.

The "evidence" is bullshit. Look at exactly what is said.

AS, for all of whatever it was good that he brought the world, was mentally ill. For whatever reason, he did not receive the help that is freely available in our society. (There was a lot more available before Reagan cut it to shreds, so he could pass on big bucks to his rich cronies, but I digress...)

THAT is the true tragedy here. Depression is a totally, totally fucked up brain function anomaly. People who have not experienced it are simply clueless and should STFU. The REST of you: get help. Get Help - Now!

Re: Please Stop Attacking MIT's Network

#194

I feel like this guy could not miss the point by much more distance. How much of a shell do you have to live in to think "well sure, someone died after fighting for the rights of millions of people, but jesus, you people are going to inconvenience us for a few hours? this is just ridiculous!"

So after someone important to me dies, I can come over to your place and annoy you for a few hours? What exactly does that accomplish?

Lumping everything connected to 'MIT' together as the same evil thing is shortsighted and counterproductive.

Re: Please Stop Attacking MIT's Network

#195
post #180
post #105

Earlier quoted context omitted.

And how did that work out for him by the way? I head they've dropped their lawsuit? Also, if DDoS is "destructive" then copying a file is stealing.

> Also, if DDoS is "destructive" then copying a file is stealing. How does that follow?

"destruction" and "stealing" are both words with a physical connotation, that is misleading when used in a computational/digital context.

Re: Please Stop Attacking MIT's Network

#196
post #45

As I'd mentioned on an earlier submission about W3C's site being inaccessible: A cool thing about Aaron's activism was that it involved building things, circumventing censorship, and spreading information, rather than sabotage and denial-of-service.

Yeah, well, people who aren't Aaron are kind of mad at MIT right now. That said, MIT has some smart people, surely they can put their noggins together to figure out a way to stem the attack. Maybe once and for all, and for the good of the internet, they can contribute this tool for unilaterally turning off DDOSes to the public.

Distributed denial of service attacks are very difficult to deal with (I have dealt with—read: suffered through—several each year for the past ten years on and off.) Often there is little to nothing you can do within your network to improve the situation.

It's an issue of raw volume, once the attacker(s) exceed your capacity you're saturated and dead in the water. At this point, the techniques that will help must be applied at a point where the pipe has greater capacity than the attack, and depend on the exact nature of the attack and so vary in effectiveness.

That isn't to say the situation couldn't be improved, but I think widespread infrastructural changes would be needed and isn't the kind of thing MIT folks could just work out and apply to their current situation.

Re: Please Stop Attacking MIT's Network

#197
post #59

Earlier quoted context omitted.

There have been hundreds (thousands?) of javascript exploits. Javascript is also a major component in user tracking. Go to a news site and you'll see a dozen trackers most likely against your wishes, reducing privacy and performance. It's a hostile internet out there. Hostile images may exist but they are an order of mag. or two less common of a threat. Of course, where to draw the line is subjective, but the idea th…

Can you link to a recent (for any reasonable value of the word) remote code execution vulnerability with JavaScript? Because my observation has been that RCE through codecs has been a much bigger vector for compromised systems.

http://www.metasploit.com/modules/exploit/windows/browser/ie... was a cool one, but really, almost EVERY vulnerability requires JavaScript for the heap spray, even if the bug is somewhere else. Of course, running plug-ins in web pages is even more retarded than running JavaScript. By the way, images can spray the heap too, but, for some reason, they are not commonly used.

Re: Please Stop Attacking MIT's Network

#198

Earlier quoted context omitted.

Who do you think should fix it if not the MIT students? Why don't they go and physically remove administration from the MIT and never let it back? It seems impossibly unlawful when I write this but you know, there were times when students had a political agendas and they used to run over campuses, barricade them and battle the police. And now it's like "we're gonna hate them for life and not do a thing". I understand…

By what right to they have to "take over" MIT and "never let administration back"? It's not their property, and no amount of "cause celebre" or "protest du jour" should make it such.

It's not "the administration" property either.

And when you come to think about it, how can an university be someone's property? Surely you can own buildings, but how do you own education and knowledge?

Re: Please Stop Attacking MIT's Network

#199

Earlier quoted context omitted.

Yeah, well, people who aren't Aaron are kind of mad at MIT right now. That said, MIT has some smart people, surely they can put their noggins together to figure out a way to stem the attack. Maybe once and for all, and for the good of the internet, they can contribute this tool for unilaterally turning off DDOSes to the public.

Distributed denial of service attacks are very difficult to deal with (I have dealt with—read: suffered through—several each year for the past ten years on and off.) Often there is little to nothing you can do within your network to improve the situation. It's an issue of raw volume, once the attacker(s) exceed your capacity you're saturated and dead in the water. At this point, the techniques that will help must be…

I know the mechanics of DDOS. I was around when some of the first distributed attacks were being directed at best.com (et al: http://www.pentics.net/), my ISP at the time.

I was using understatement to mock both MIT's reputation for innovation and intelligence and their role in the events that appear to have spurred the attack, so maybe they could put their vaunted brainpower to work solving that problem instead of killing downloaders, so to speak.

Re: Please Stop Attacking MIT's Network

#200
post #70
post #14

I do not condone the attacks that may be occurring. However, if you are trying to get someone's attention- it makes more sense to get the attention of the students rather than the administration. Today's MIT students are tomorrow's death-ray designers, robot-maintainers, and policy makers. They are tomorrow's administration- and they may not have made up their minds yet about ethical issues of intellectual property o…

If you're trying to simply "get the attention" of the student body, congratulations you have it. If you're trying to get the student body on your side, you're doing the exact opposite. If I pay $X/year to attend an institution, and someone wants to fuck with my ability to learn to further their own political goals (no matter how noble) you're not winning me over.

Let me get this straight- "no matter how noble" a political goal is- to you, that message being spread to others is less important than uninterrupted access to download your class syllabus or read your friends' blogs?

If your parents or government have not already paid for your tuition I urge you to think of something else to do with that money.

Post reply on HN