Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

231–240 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#231
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

That's such a terrible idea but it would make a fantastic satire Sci fi short story premise.

Technology that cannot be used by anyone but the snobbish tech elite because anyone else just gets sued to oblivion.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#232
post #192
post #15

Earlier quoted context omitted.

> I think they must count ~100 engineers? https://wikimediafoundation.org/role/staff-contractors/ has the names of 379 employees. I believe (perhaps astonishingly) that is all - engineers and non-engineers combined. Their engineers spread across departments, but judging by the 141 instances of the string 'engineer' in that page, I'd be surprised if the number exceeds 200.

Speaking as someone listed on that page, and having attended all-hands meetings, yeah, we're not huge. Though it is worth bearing in mind that everything's open source, and there's a hefty community component. So there's a more vaguely specified number of people who might provide patches, and individual wikis are mainly run by volunteers.

Just drop by and say thanks you. Not many worldwide charity for human knowledge. Add oil.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#234
post #207

Earlier quoted context omitted.

There's always something "undesirable" for someone in a big crowdsourced website.

The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings. Moreover, as they took the decision they went to great pains to explain this was an exceptional case. Going from that to 'undesired political speech will be censored' requires more of a slippery cliff than a slippery slope.

>The cloudfare 8chan action was based on a direct link with multiple actual mass-shootings

What is this "direct link" you speak of? Did the shooters plan/recruit/organize their attacks on 8chan?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#235
post #56

Earlier quoted context omitted.

- Advertising for potential DDoS service buyers - Bragging rights - Experimentation Edit: Also potentially political or personal. Eg Posting something that offends 8chan||nation states etc. There's quite often blackmail involved (Pay us $x BTC and we go away). Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins.

> Cloudfront or similar should offer DDoS protection for free as a gesture of goodwill, it's good bragging rights for CF so everyone wins. Well, it is still a lot of wasted resources (bandwidth, energy, compute) for everyone involved (ISP, CF, attacker, defender, compromised machines), so I wouldn't be so quick to say that "everyone wins".

Consider it a 'cost of doing business'. Everyone gets DDoSed, I'm pretty sure that's one of CloudFronts primary service-based solutions

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#236

Earlier quoted context omitted.

I think it’s somewhat misleading to refer to those who support genocide and child abuse as simply “political undesirables.”

It's not just supporting. Taking a neutral stance on censoring these things, or not being adequately proactive on hate speech, is now seen as condoning. You either censor your user base, or upstream will censor you. Gone are the days of "The net interprets censorship as damage and routes around it." The new policy is "The net interprets wrongthink as noise and filters it out."

It’s not censorship: they are not suppressing information, they just aren’t allowing their resources to be used to spread it.

It would be “censorship” if they actively antagonized any attempt to spread the information, such as by lawsuit or DMCA notice. They are just refusing to participate.

And given that the “information” is definitively known to be child pornography and violent white supremacy propaganda presented as news, I would personally say refusing to participate is the only responsible action.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#237

Earlier quoted context omitted.

I think it’s somewhat misleading to refer to those who support genocide and child abuse as simply “political undesirables.”

Genocide has been and still is a political tool. It is extreme, but ultimately something that people consider and carry out as part of political processes, not a special category of its own. And realpolitik is to continue dealing with countries that practice genocide. Consider Burma or China. Cloudflare simply has the luxury of choosing which politically disagreeable parties they do not want to associate with because…

I didn’t say it wasn’t political, but it’s not just undesirable for immediate political reasons — it’s undesirable for nearly universally-agreed moral and ethical reasons. So implying it’s only inconvenient for politics is, in my opinion, misleading.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#238

Earlier quoted context omitted.

After working with a few large corporations and their DDoS protection solutions, I did not have a good experience with Verisign, and they were not able to handle attacks or get things working. However, I have great experiences with Akamai and Cloudflare. I trust the people at Wikimedia will choose wisely. I would I have learned that Verisign has one of the worst BGP mitigation/scraping solutions out there. There are…

Any serious mitigation solution must be BGP based, not proxy. Besides its technical merits and convenience, it also minimizes the risk of a benevolent controller (e.g. Matthew Prince of Cloudflare) ruining your company, because it becomes your upstream provider only during the attacks. Otherwise the GRE tunnels are not in use. The IP addresses are still yours always. We used Verisign for mitigation of a 44Gbps volume…

Akamai has a BGP based DDoS mitigation service via their prolexic acquisition.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#239

Earlier quoted context omitted.

They can be used by blackhats selling e.g. DDoD-netbots to prove the “quality of the merchandise”.

I definitely get the feeling that’s what they’re going for. They mentioned they’re just testing out a new botnet made from IoT devices.

Ah, Mirai Mark N. So what, light bulbs? Cameras?
Post reply on HN