Live data from Hacker News

Wikileaks moves to Amazon's cloud to evade massive DDoS

arstechnica.com

31–40 of 70 posts

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#31
post #30

Unfortunately, once the big guns of the media and those opportunists in government find out, Amazon will be forced to make a statement one way or another. Do they support this kind of thing or not? I can even imagine calls for a boycott from some sectors - not a great thing for Amazon at this time of year.

[deleted]

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#32
post #11
post #3

I'm not familiar with Amazon's content policies, but I couldn't see Amazon wanting this stuff hosted on their servers.

Amazon is fine with it, according to the WSJ. http://blogs.wsj.com/digits/2010/11/29/wikileaks-using-amazo...

"Amazon and WikiLeaks did not return requests for comment."

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#33
post #4

This is very interesting. If Wikileaks does in fact become designated a terrorist organization by the US, then it seems Amazon will have to shut them down or run the risk of providing them "material aid". The same would be true of any other cloud provider... are there any sizable cloud providers outside the US?

If Wikileaks is a terrorist, then so too is the New York Times, and any other media outlet that has conveyed the same information Wikileaks released.

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#34
post #7

Earlier quoted context omitted.

It would depend on how Wikileaks designed their AWS infrastructure. Amazon's policies are specific to the territory in which they operate. They obey the local laws for the data they will store on their hardware and will only comply with local laws. For example, if you provision your services in the EU-Ireland region, it is governed by the laws of the EU, not by the United States. That being said, I don't know the spe…

> the laws of the EU We are, sadly, not quite that far along yet.

The EU issues Regulations, which have immediate effect in member states, and Directives, which member states are required to implement in national law, so it's not too far wrong to talk about EU law. http://en.wikipedia.org/wiki/European_Union_law

Caveat: IANAL (but my wife is).

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#36
post #3

I'm not familiar with Amazon's content policies, but I couldn't see Amazon wanting this stuff hosted on their servers.

Why not? The New York Times and many other newspapers published the same data, and surely there's no problem hosting the NYT, so why is Wikileaks special in this regard?

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#37

I am curious who wants to attack Wikileaks and for what purpose. I think it's unlikely this is the USG because of the sheer pointlessness of it, plus the fallout that would occur if it were discovered. The likeliest major player I can think of is China, but I'm not sure I have a reason for that belief other than that they are the bogeyman du jour. An alternate possibility is that this is just some cracker flexing his…

Wired said some random guy did it, not a government: http://www.wired.com/threatlevel/2010/11/wikileaks-attack/

Note to other members: It's not OK to downmod someone for an opinion, especially not below zero.

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#38
Doesn't hosting with Amazon create a money trail? If the US were to prosecute them, they could subpoena Amazon, and find more members of the organization.

Assange is knowingly putting himself in the line of fire, but isn't there a goal to make sure other members of wikileaks stay anonymous?

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#39
post #15

It looks like it's hosted in the US (ec2-184-72-37-90.us-west-1.compute.amazonaws.com). Also, the front end proxy is doing some heavy filtering to weed out the cheap hit-and-run nodes participating in the DDoS but still accepts legitimate browser-based requests (persistent). Notice how a Reset (R) is sent right away on the first try: 08:57:41.211436 IP managed.unixy.net.49467 > ec2-184-72-37-90.us-west-1.compute.amaz…

Surviving DoS attacks is not a new problem; I'm sure that Amazon has quite a bit of experience in that area. But thanks for the trace, quite interesting!

I wonder how well their Cloudfront CDN holds up for delivering static content in the face of a DDoS vs just using heavy static cachine with ngnix or apache on EC2.

Re: Wikileaks moves to Amazon's cloud to evade massive DDoS

#40
post #30

Unfortunately, once the big guns of the media and those opportunists in government find out, Amazon will be forced to make a statement one way or another. Do they support this kind of thing or not? I can even imagine calls for a boycott from some sectors - not a great thing for Amazon at this time of year.

Everything that embiggens this story is good news for Wikileaks. And Amazon taking a stance would be something big.
Post reply on HN