Live data from Hacker News

Techcrunch hacked again

news.ycombinator.com

41–50 of 54 posts

Re: Techcrunch hacked again

#41

  GARY COLEMAN: I didn't say it was nice! But everybody does it! And ain't it fun to 
   watch figure skaters falling on their asses?

  NICKY: Sure!

  GARY COLEMAN: And don'tcha feel all warm and cozy, Watching people out in the rain!

  NICKY: You bet!

  GARY COLEMAN: That's...

  GARY AND NICKY: Schadenfreude!
-- Avenue Q

Re: Techcrunch hacked again

#43
post #28

At televised sporting events, a prankster, usually drunk, will sometimes run onto the field to make a spectacle. Yet, the broadcast always cuts away, so as not to encourage the behavior even more in the future. Perhaps we could consider a similar policy on submissions and upvotes about site-defacements? The hack will already get plenty of attention from the normal visitors of the affected site, and coverage in other…

so just to make sure this is clear... on a site titled "Hacker news" you don't want hacking to be in the news?

Re: Techcrunch hacked again

#44
post #39
post #28

At televised sporting events, a prankster, usually drunk, will sometimes run onto the field to make a spectacle. Yet, the broadcast always cuts away, so as not to encourage the behavior even more in the future. Perhaps we could consider a similar policy on submissions and upvotes about site-defacements? The hack will already get plenty of attention from the normal visitors of the affected site, and coverage in other…

Idealistic. But not practical. Sporting events have just one broadcaster. One person who controls what you see. Online, everyone is a broadcaster. That changes the game. Not everyone will agree to such a policy. And you just need one player to disagree to make it impractical. Case in point: 9/11 attacks were shown on TV repeatedly - because there was more than 1 player who could do the broadcasting.

I don't think incidents could (or should) be completely hidden, as in the sporting example. But they could be less promoted.

We don't all have to magnify the events. Each news site (and voter) can decide where they want to play on the information continuum. Should News.YC be more gotcha-tabloid-if-it-bleeds-it-leads, or less?

Re: Techcrunch hacked again

#45
post #5

Bad guys only need to know one way in. Good guys need to know all the ways in.

  Good guys only need to build one layer of security.
  Bad guys need to break every layer of security.
(Problem is, most systems are more about Weakness in Width than Defence in Depth.)

Re: Techcrunch hacked again

#46
My two cents: I guess they were using xmlrpc to post to the blog. The incutio xmlrpc library (or rather the metaweblog api which wordpress uses) requires that you send the username and password in the clear, so a man in the middle could easily gain access to their wordpress install.

Re: Techcrunch hacked again

#48
post #5

Bad guys only need to know one way in. Good guys need to know all the ways in.

Good guys only need to build one layer of security. Bad guys need to break every layer of security. (Problem is, most systems are more about Weakness in Width than Defence in Depth.)

Good guy need to block all possible hacks

Bad boy need to find the only missing one !!

Re: Techcrunch hacked again

#49
post #22

Earlier quoted context omitted.

They get hacked twice in a row, day after day has become the new routine. Someone there is totally doing their job you think?

Getting hacked twice in short time doesn't automatically mean incompetence. There could be literal dozens ways of entry - including all the third party javascript services they run. Also we don't even know if the attack was done using a 0day exploit. A sign of incompetence would be if they had their whole database wiped out and they did'nt have any backup (ala codinghorror.com) or they got hacked exactly the same way…

> Getting hacked 2 days in a row only means they couldn't find the weakness yet.

Because, you know, restoring from a backup is the same as securing a site, right? And there's no way that a hacker could do worse things? Because infecting some visitors or something similar wouldn't hurt their reputation?

Sorry for the outburst, but this happens way too often.

Re: Techcrunch hacked again

#50
post #28

At televised sporting events, a prankster, usually drunk, will sometimes run onto the field to make a spectacle. Yet, the broadcast always cuts away, so as not to encourage the behavior even more in the future. Perhaps we could consider a similar policy on submissions and upvotes about site-defacements? The hack will already get plenty of attention from the normal visitors of the affected site, and coverage in other…

But the viewers want them to cut to the streaker
Post reply on HN