Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

61–70 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#61
post #37

Earlier quoted context omitted.

How many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?

If these systems are owned by private people then the company who designed it/deployed it is liable. If I have root on the device then it's my fault if I screw up, if I don't have root and it's just a plug and play appliance then whoever designed it/sold it can be liable. This solves the issue of "grandma buying an IoT washing machine" mentioned in another comment as the manufacturer of the machines can be sued direc…

You seem familiar with hardware and software hacking, but not the creativity of bad-faith legal hacking ;-)

If you pass that law on Day Zero, I claim that on Day One, manufacturers provide some horribly arcane command-line interface for rooting lightbulbs and washing machines, and add some boilerplate to their shrink-wrap licenses forcing customers to acknowledge that they have admin privileges on their devices.

Problem solved for them, Granny is liable again according to your system.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#63
post #22

I'm not surprised. There are a lot of people banned from Wikipedia by their abusive admins looking for revenge.

It might be, but currently doesn't appear that's the motivation here, not if they're also attacking twitch & WoW.

My guess is they tried google and facebook without any luck so they moved on. The choices made would tell me that they are younger mid-late 20s / probably not from an English speaking country. Motivation.. sense of power.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#64

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

And they're hiring! https://wikimediafoundation.org/about/jobs/#section-8

I worked there for four years and I miss it every day.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#65

Earlier quoted context omitted.

Please be careful of logical tautologies: "It all scales in all directions with a properly thought through architecture" sounds dangerously like, "Programming isn't that hard if you just do it right."

I appreciate what you're saying, but I don't think it quite applied. What I meant was that it's easy to create an architecture for an application that doesn't scale well at all. Eg - poorly sharded data, lots of cross dependencies etc. However, if you properly think through your data model and data flows and use cases, it's generally possible to create a system that is extremely scalable in all directions. This is ce…

I totally agree that you make an excellent point about the relative ease/difficulty of various approaches.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#66

Earlier quoted context omitted.

If these systems are owned by private people then the company who designed it/deployed it is liable. If I have root on the device then it's my fault if I screw up, if I don't have root and it's just a plug and play appliance then whoever designed it/sold it can be liable. This solves the issue of "grandma buying an IoT washing machine" mentioned in another comment as the manufacturer of the machines can be sued direc…

You seem familiar with hardware and software hacking, but not the creativity of bad-faith legal hacking ;-) If you pass that law on Day Zero, I claim that on Day One, manufacturers provide some horribly arcane command-line interface for rooting lightbulbs and washing machines, and add some boilerplate to their shrink-wrap licenses forcing customers to acknowledge that they have admin privileges on their devices. Prob…

Does the license auto-root the device? If yes, then it's an obviously dishonest circumvention of the law and judges will see right through it. If not, then the manufacturer has to prove the device was rooted if they want to pass liability to someone else.

If that still doesn't solve the problem, the media will take care of it. "Buying this smart lightbulb puts you at risk of being sued for thousands of $$$" can't be good for manufacturers and they'd want to avoid the bad press.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#67

Earlier quoted context omitted.

Do these kinds of attacks usually have a motive?

They can be used by blackhats selling e.g. DDoD-netbots to prove the “quality of the merchandise”.

I definitely get the feeling that’s what they’re going for. They mentioned they’re just testing out a new botnet made from IoT devices.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#68

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

Not to diminish Wikipedia engineers talent, of course...

But, I'd consider Wikipedia traffic to skew heavily towards anonymous read-only, with very few logged-in write traffic.

This allows for tons of caching opportunities: Varnish, Memcache, etc. And these techniques are well known.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#69

Earlier quoted context omitted.

Did they say anywhere what their motive was?

Do these kinds of attacks usually have a motive?

I am pretty certain that when China used the Great Firewall to attack github, this was a test of their capabilities.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#70
post #64

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

And they're hiring! https://wikimediafoundation.org/about/jobs/#section-8 I worked there for four years and I miss it every day.

[deleted]
Post reply on HN