Live data from Hacker News

The story around the Linode hack

straylig.ht

51–60 of 175 posts

Re: The story around the Linode hack

#51

Here's an attempt at an explanation/translation: HTP ("Hack The Planet") is a group that likes to break into things. Another (unnamed) group of people impersonated a third group of people ("ac1db1tch3z") and tried to cause trouble for HTP. The impersonators located HTP by examining one of HTP's botnets (a collection of compromised computers that are used to launch things like denial of service attacks). Botnets have…

Why bother reading novels or watch thriller movies when there are comments like this? :)

Re: The story around the Linode hack

#53

Earlier quoted context omitted.

Please give me the password to your regular email account so I can read your emails. I won't delete any of them, but your email server is not a house, and I should have the right to read your emails.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack.

"Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home without my permission, you have trespassed and can be charged with a crime. The only thing I would be "at fault" for is making a lackluster attempt at securing my home. I don't forfeit protection from trespass under the law for that act though.

You see, locks are not what govern access; laws are. HTP is clearly in the wrong here. They forced entry in to Linode's systems, then attempted to extort Linode in an effort to achieve their goals. Swap out Linode's servers for Linode's offices, and there's no question that HTP are operating outside the boundaries of ethical behavior.

Re: The story around the Linode hack

#54

Earlier quoted context omitted.

Please give me the password to your regular email account so I can read your emails. I won't delete any of them, but your email server is not a house, and I should have the right to read your emails.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

Did you honestly just use militarized cyberwarfare as an example of legitimate black hat?

The US/Israel are involved in a proxy war with Iran that involves cyberwarfare, clandestine operations and conventional military strikes (in the case of Israel striking Iranian-sourced Syrian weaponry).

It's an extremely poor example to use open cyberwarfare between nations engaged in everything but overt warfare to attempt to legitimize black hat hacking.

Re: The story around the Linode hack

#55

I am not familiar with the crackers' terms. So does this mean that name.com is not safe? All my domains are there...

The point is, when you're dealing with people of this level of supposed skill, they can just walk into pretty much any network. They're all vulnerable on some level if you're capable of actually breaking them yourself in novel ways. The only real solution is either to not depend on any single network, or to make it clear that you will simply kill anyone who troubles you. Or just remain innocuous enough that nobody wi…

They had skilz, no doubt, but it does not appear the CF hack was the zen apex of hacking. It was a well known exploit you could drive a truck through. Writing Stuxnet, now that was mad skilz.

Re: The story around the Linode hack

#56

Slightly OT, Is it possible to have a web application (using popular tech like RoR, PHP etc.) that cannot be cracked by anyone ?

No. Even if you could write a 'secure' RoR app, at some point the RoR framework becomes the weakest link. ( Or the Linux kernel, or the door of the datacenter.) And more general, security implies always a certain attack scenario, a strong password does not help against stolen hardware and a nuclear bunker does not help against a zero day. On the other hand, you can be quite secure against a plausible attacker, that is a attacker who is not willing to blow zero days against your personal blog. ( Or im general is not willing to spend a lot more than he can gain in the attack.)

Re: The story around the Linode hack

#57

Slightly OT, Is it possible to have a web application (using popular tech like RoR, PHP etc.) that cannot be cracked by anyone ?

Generally you don't need 95% of the stuff that's running. Use the bare minimum. Compile the server you're using, say Nginx, from source with only the bare minimum of options and modules you need. Disable all the services/ports and then selectively enable the ones you need.

Best of all, don't have anything worth stealing. Don't keep the credit cards on your servers, parrot them through a vendor. Don't keep user credentials on your system, us OAuth, Fb or Google auth. If you've got nothing valuable to steal, they'll likely not break in.

But then again, if the Fed's want in, they'll just pull your box from the rack. Don't forget that you can literally freeze a DIMM and dump it and all the encryption keys to another mobo. So, as is the CIA's policy, if you don't want anyone to know something, don't let it touch a computer. ;)

Re: The story around the Linode hack

#58

Earlier quoted context omitted.

Only if the server is switched off and disconnected from the network.

Ha :) I guessed so .. It is impossible to make an un-crackable system .. not sure if that is a good thing or bad ...

Every lock has a key. ~Hacker's motto

Re: The story around the Linode hack

#59
I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement.

It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If there were well respected hackers who spoke publicly against this kind of behavior it might make some people think twice. (Unfortunately, most well respected hackers used to be these kids before they got real jobs)

HN is full of individuals who try to take the high road, versus the kind of anonymous internet idiocy that exists in nearly every forum and chatroom. I love this about HN. I wish more of the internet took it as an example.

Re: The story around the Linode hack

#60

Earlier quoted context omitted.

Please give me the password to your regular email account so I can read your emails. I won't delete any of them, but your email server is not a house, and I should have the right to read your emails.

A right? I didn't say they have a right. They hacked into. Did the US/Israel have a _right_ to use Stuxnet against Iran? No. They hacked into. When did you accuse the US secret service or hope that they will be punished? Double standards? I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

> I won't give my email or its password to you, but if you can find it, hack it and decrypt my emails, then it would be only my fault, and you will have my respect.

Ah yes, the "might makes right" philosophy that we all know and admire from primary school.

Post reply on HN