Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

41–50 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#41
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

You can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example.

People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's not like you can monitor what kind of traffic your phone apps send out.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#42

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Did they say anywhere what their motive was?

Power tripping most likely.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#43
post #37

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

How many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?

You'll also have to prove the IOT device DDoSing from my IP isn't a rogue device. I swear it's not mine.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#44

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Did they say anywhere what their motive was?

Do these kinds of attacks usually have a motive?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#45
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

There was a string of arson attacks on little free libraries in Metro Vancouver; eventually a pair of teenage boys were arrested.

I suspect that the sharing of knowledge and encouragement of developing wisdom is, to some, a threatening prospect. Perhaps they have experienced learning difficulties and are struggling with shame and frustration, or perhaps they disagree strongly with the concept of an intellectually liberated population. Libraries are, after all, a pillar of liberalism.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#46
post #28
post #15

Earlier quoted context omitted.

> I think they must count ~100 engineers? https://wikimediafoundation.org/role/staff-contractors/ has the names of 379 employees. I believe (perhaps astonishingly) that is all - engineers and non-engineers combined. Their engineers spread across departments, but judging by the 141 instances of the string 'engineer' in that page, I'd be surprised if the number exceeds 200.

That’s what happens I guess when you’re running a charity, you can recruit top talent (I assume many 10x folks wouldn’t mind working for wikimedia!) and every dollar counts. Pretty incredible.

They seem to be at the leading edge of hiring remotely and they don't pay anywhere near facebook salaries. The culture must be attracting some strong developers.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#47

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

It's because they're just serving a big site, not running the world's most sophisticated surveillance and ad serving machine. Serving giant websites isn't all that hard if you're just spewing out SQL queries into html templates. It all scales in all directions with a properly thought through architecture.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#48

Earlier quoted context omitted.

Some people just like to break things. It's that simple.

That doesn't appear to be the case here. This was done for the attention, not just for the thrill of breaking things.

Probably proving their skills to potential clients.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#49

Remember: there are BitTorrent links that the Wikimedia Foundation gives out of SQL dumps of Wikipedia and the other projects. You can have a copy in case this happens in your country: https://en.wikipedia.org/wiki/Wikipedia:Database_download#Wh... Also, the Kiwix project has a hotspot project that allows you to host ZIM files (dumps of Wikipedia and other CC licensed content, like TED talks and StackOverflow) on a R…

Caveat: the last full Kiwix English Wikipedia archive was made in 2018. They could use some help with automating their build process if anyone here has the time.

From a cursory glance at the site and source code, it's really hard to see who/what is involved with building an archive. There's automated builds set up for the Pi image itself.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#50

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

It's because they're just serving a big site, not running the world's most sophisticated surveillance and ad serving machine. Serving giant websites isn't all that hard if you're just spewing out SQL queries into html templates. It all scales in all directions with a properly thought through architecture.

Please be careful of logical tautologies:

"It all scales in all directions with a properly thought through architecture" sounds dangerously like, "Programming isn't that hard if you just do it right."

Post reply on HN