Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

241–250 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#241
post #182

Earlier quoted context omitted.

A proxy is a perfectly acceptable “serious” solution for this type of problem, as well as nearly all of the rest. Wikipedia is not the kind of website that would warrant being removed from Cloudflare. What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack?

> What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack? The problem is that you are basically mitm:ed all the time.

That’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#242
post #214

Earlier quoted context omitted.

How did 8chan "encourage" large gun massacres exactly? By allowing users to post content?

By not moderating content largely, it was no secret what the site was letting go.

By your statement then reddit was complicit with the Russian trolls during election season because the bitcoin trolls who evolved into trump trolls were not punished in the slightest (I have a list of 300+ usernames that are still active today)

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#243
post #155
post #63

Earlier quoted context omitted.

My guess is they tried google and facebook without any luck so they moved on. The choices made would tell me that they are younger mid-late 20s / probably not from an English speaking country. Motivation.. sense of power.

Why do you think they are not from an English speaking country? They are likely advertising their botnet (and seems to be working rather well).

I think they might think they're not English speaking because it wasn't the English wikipedia sites that went down. Then again, they may easily have tried that too but it's larger, built to handle more traffic.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#244
post #241

Earlier quoted context omitted.

> What’s wrong with having an upstream provider for caching close to the user and other features when you’re not under attack? The problem is that you are basically mitm:ed all the time.

That’s not what MITM means. I get that you don’t like Cloudflare but voluntary use of a CDN isn’t a MITM any more than, say, Amazon is a MITM because you host on EC2.

A better comparison would be Cloudfront and Application Load Balancers since you can expose your own ec2 server or load balancer and be e2e encrypted (unless AWS wanted to run commands on your instance, which they could do, but that's a different threat vector entirely).

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#245

Earlier quoted context omitted.

You appear to be extremely mad Cloudflare stopped proxying a website that encouraged large gun massacres.

Alternately: The fact that Prince was super okay with hosting those websites until the moment it made him look bad

That's a valid stance but they didn't host the website; they only provided DDOS protection for the actual host (which proceeded to drop 8ch once CF stopped providing the protection).

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#246
post #242
post #214

Earlier quoted context omitted.

By not moderating content largely, it was no secret what the site was letting go.

By your statement then reddit was complicit with the Russian trolls during election season because the bitcoin trolls who evolved into trump trolls were not punished in the slightest (I have a list of 300+ usernames that are still active today)

The point is that Reddit tries to moderate, which is good enough for their providers (AWS/Fastly).

The 8ch takedown wasn't actually due to issues with moderation, since (at least based on the owner's video) 8ch removed the post, actively responds to real law enforcement requests, and the original post was actually posted to IG. The issue was that CF was getting enough bad press, and more importantly enough calls/concerns from real Enterprise clients (this is speculation on my part), to take down the website.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#247

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

I'd actually love to see a fully working IPFS fallback for wikipedia when regular hosting doesn't work. Would it even be possible with ipfs?

From a comment above: https://ipfs.io/ipfs/QmXoypizjW3WknFiJnKLwHCnL72vedxjQkDDP1m...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#248

Earlier quoted context omitted.

I don't see why you'd come up with something that so misaligns the interests of everyone except lawyers. Instead, imagine the DDoS landscape if we had to pay a small price for bandwidth. There would be a natural disincentive to having a toaster saturating your bandwidth as part of a botnet because it would quickly show up on your bill. And something as simple as shipping an IoT product or Rasberry Pi with bad default…

I don't see why you'd come up with something that so misaligns the interests of everyone except Comcast :) We don't need to be priced by the bandwidth, we just need better accessibility to metering. Something my mother could look at and say "huh, the toaster's sent 8gb of data today..."

If you’re not charged for it and it’s not enough for you to feel reduced performance on your other devices, why would you even both looking?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#249

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

The attacker also attack Blizzard's game servers. Is actively taking down WoW classic and Overwatch.

https://www.reddit.com/r/classicwow/comments/d10x4f/servers_...

The attacker was posting updates to Twitter, but their account has since been suspended.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#250
post #146

Earlier quoted context omitted.

> Serving giant websites isn't all that hard if you're just spewing out SQL queries into html templates. It all scales in all directions with a properly thought through architecture. No. 1. Your comment makes it sound like Wikipedia is just, or mostly, serving read-only content, which is far from true. Yes, static read-only content is significantly easier to serve than dynamic, editable one, but Wikipedia is the latt…

I've never heard anyone in my life say they could rebuild MS office in a weekend. What, in your opinion, would be the work needed to go from a 100k monthly active user site to a wikipedia scale site - that would be comparable to rebuilding MS office?

I've never heard anyone in my life say they could rebuild MS office in a weekend.

The saying usually uses Facebook or Twitter.

Post reply on HN