Live data from Hacker News

Malicious attack on Wikipedia – what we know and what we’re doing

wikimediafoundation.org

71–80 of 320 posts

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#71
post #3

Just like trying to set your local public library on fire. There are always crazies in the world.

> Just like trying to set your local public library on fire.

No, more like superglueing the doors shut for a few hours.

Don't really see the damage, especially since they moved onto Twitch and WOW servers, I'd say more work and a few early nights sleep has got done in the end.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#72
post #64

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

And they're hiring! https://wikimediafoundation.org/about/jobs/#section-8 I worked there for four years and I miss it every day.

> I worked there for four years and I miss it every day.

Sorry but now I'm curious, why did you leave?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#73

Earlier quoted context omitted.

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

Can't wait to tell Gran she's legally liable for a DDoS because her unsecured IOT washing machine best buy sold her caused the internet to cave in ;)

Skip Gran and sue Best Buy and the IoT washing machine manufacturer.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#74
post #20

Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas

Part of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many…

That's exactly how over-regulation starts.

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#75

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

Wasn't Instagram famous for having a very small team of engineers responsible for the availability of the entire platform before Facebook acquired them?

Not sure how big ig was on acquisition, but I always remember that story being about WhatsApp with only 35 engineers

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#76

Earlier quoted context omitted.

They can be used by blackhats selling e.g. DDoD-netbots to prove the “quality of the merchandise”.

I definitely get the feeling that’s what they’re going for. They mentioned they’re just testing out a new botnet made from IoT devices.

And so the IoT wars begin...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#77

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

I used to work at FB and now work at Reddit. The engineering staff count at Reddit is within the same order of magnitude as the number you cite above. :)

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#78

Someone claimed the attack on twitter with some details (DDoS) - and proved it later by stopping the attack for x minutes then restarting it at a specific time. https://twitter.com/fs0c131y/status/1170093562878472194?s=20 - the attacker also went on to DDoS the twitch ingest servers (not twitch.tv itself) knocking some big streamers offline.

Who are they?

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#79

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

If you consider the amount of money they are burning in comparison to 5 years ago, are the results really that impressing? See https://en.wikipedia.org/wiki/Wikipedia:Wikipedia_Signpost/2...

Re: Malicious attack on Wikipedia – what we know and what we’re doing

#80
post #68

Just want to mention, WMF has a very small but elite team of engineers. Amazed they maintain an Alexa top 5 site with many orders of magnitude less engineering staff than Facebook or Reddit. I think they must count ~100 engineers? I can't imagine what such a small team must be going through with a major DDOS - wish them well in their efforts!

Not to diminish Wikipedia engineers talent, of course... But, I'd consider Wikipedia traffic to skew heavily towards anonymous read-only, with very few logged-in write traffic. This allows for tons of caching opportunities: Varnish, Memcache, etc. And these techniques are well known.

The proportion of read/write may skew towards reads, but Wikipedia still is an application where any user can create state visible to all other users. It's not as simple as this comment makes it out to be.
Post reply on HN