Live data from Hacker News

How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

blog.phpfog.com

71–80 of 202 posts

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#71

Earlier quoted context omitted.

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

I know, they acted as if they could get away with it by apologising. However, whatever you think of PHPFog, a lot of people have invested everything they have in that project, and it could have (and still could have) done irreperable damage to their reputation and investment. Big companies can tank this crap but attacking a new startup is like punching a child.

Therefore you want to sue a child?

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#72
post #37

I mentioned this last time, but I don't think anyone was interested, but the "John" guy is compwhizii (same handle on Twitter) who runs the forums (facepunch.com) for garrysmod, a very popular game. I will be curious to see how garry (owner person) responds to this, or if he already has. Elliot is apparently VERY scared and blames John (compwhizii) (edit: not john, he blames someone else called supersnail1): http://w…

And here's Elliot's "official statement": http://elliotspeck.com/phpfog.html And for anyone who missed it, here's what Elliot posted in the previous HN discussion about the phpFog breach: http://news.ycombinator.com/item?id=2346161

Hi, I'm ! My site says what city I'm from. I've written publicly to admit that I committed multiple crimes, definitely without consulting legal counsel first! I even put them in a nice bulleted list that can be copied and pasted right into a complaint. They're pressing charges, but that's bullshit. I'm 16!

Not too bright, are we? Instant message the company you just hacked and bust out from behind your handle, then provide evidence for the prosecution in the form of a Web page? What is with kids these days?

It only takes one episode of Law & Order to figure out how to proceed here. Clue: Attorney.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#73
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

I would encourage them to pursue legal action. I think it's right, justified and also strategically important—you can't have other kids thinking they will get away with it in the future.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#74
post #4

I feel really bad for the phpfog guys. But given the situation, I think they handled it admirably well - kudos to them. No software is secure and this could have happened to anyone. Especially startups who have to take shortcuts at the very beginning. I know the attackers were just kids but I have to admit pursuing legal action sounds very tempting - even to just act as a deterrent to others. If they had just put up…

What I find most disturbing about this whole situation is the way in which these teenagers are handling themselves, especially after the fact. The continued denial of responsibility and half-hearted mea culpa, coupled with the monetary damage to those businesses who had been running on PHPFog, leads me to sincerely desire that these teenagers face a penalty of some magnitude, not just a slap on the wrist. Maybe then…

[deleted]

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#75
post #68

I am bothered by some of the language in this post: - we were aware of the potential security threat behind post-deploy hooks and were about to disable them [...] but... - we were days away from replacing this server - They were a short-term stopgap measure we had been planning to replace To me, it sounds like the real problem could have been stated as "We were lax on security," but almost worse than that is the lack…

I read him being very apologetic for their security shortcomings in all of the appropriate places, and only blaming delayed fixes on timing issues. He was very contrite and forthcoming about their security issues. Accountability was all over the article.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#76
post #71

Earlier quoted context omitted.

I know, they acted as if they could get away with it by apologising. However, whatever you think of PHPFog, a lot of people have invested everything they have in that project, and it could have (and still could have) done irreperable damage to their reputation and investment. Big companies can tank this crap but attacking a new startup is like punching a child.

Therefore you want to sue a child?

bring him to criminal courts. close enough.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#77

Goes to show you why the DRY principle (I might be stretching that analogy here, but bear with me) is important here - if you have old stuff lying around in production that was cloned a long time ago, you might forget about it and open yourself up to unfortunate incidents like this. PHP Fog is doing great work to make the PHP ecosystem easier to work with, and I hope they didn't suffer too much from this mistake.

I don't think DRY applies here unless you really stretch it. The "fix it if you see it, don't put it off" principle fits a lot better.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#78
post #34

Earlier quoted context omitted.

Amazon is happy to. The limits you cite are merely the point at which you need to have a conversation with Amazon staff. They are quite happy to accomodate _much_ heavier usage from customers.

When I asked for a raise to my limit they denied me, on the basis that my usage was insufficient. Of course, my usage was low because I hadn't launched my product fully because I didn't have enough instances to serve a lot of customers ... catch 22. So I had to build out a rather convoluted architecture that used the loophole of deploying to multiple regions and failing over to whichever region would give me an insta…

"Can I please speak to your supervisor" works sooo often in these situations.

Re: How We Got Owned by a Few Teenagers (and Why It Will Never Happen Again)

#79
post #38

The blog post is riddled with the words "luck" and "timing" which brings doubt into my mind that the team can actually take full responsibility for their actions. "aware of the potential security threat " but they left it for the next week, who honestly here would do that? I have also seen comments around the web of migrating to Php Fog because of how they handled the situation. If you are one of these people please…

I couldn't agree more. The phpFog team cut corners to deliver quickly. We (devs) all do it. The important part is to clean up after yourself.

The whole blog post seems a bit melodramatic. I mean seriously, who here hasn't spent 3 all nighters in a row fixing a mistake? sack up and do what you should've done before deploying other people's data.

...and who would seriously sue these kids? they handled it poorly but they're smart (definitely smarter than i was at 16) you're lucky it was curious kids, rather than malicious (and experienced) hackers that would've been harder to catch. Do you really want to burden them with a criminal record for life?

Post reply on HN