Live data from Hacker News

The story around the Linode hack

straylig.ht

71–80 of 175 posts

Re: The story around the Linode hack

#72

I can't think of a better classification for a terrorist than people who sit around all day working to destroy credibility of corporations and expose personal and financial information for the sake of their own fucked up moral code and amusement. It would be nice if we had internet role models. IRC is full of low-life degenerates who perpetuate the vitriol that reinforces this way of life as an acceptable pastime. If…

>I can't think of a better classification for a terrorist than

Really? You can't think of a terrorist definition that uses, you know terror to coerce people into doing things? While you may not like these guys, labeling it "terrorism" is counterproductive. If you stretch terrorism to include anything that involves the potential for someone to feel fear about anything, you can classify nearly everything as terrorism.

Re: The story around the Linode hack

#73

Earlier quoted context omitted.

IRC is a communication medium. Could we please not vilify it? It's like saying people who use burner phones are bad people.

It's also a machine that generates dumbed-down conversation. The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. There's nothing inherently wrong with this. But it does foster negativity much of the time. I know hundreds of people who dedicate their lives to the drama and bullshit that is spawned solely by being in an IRC channel. If it went…

Yeah... I think you're hanging out with stupid people a bit overmuch.

You can say the same thing about SMS, Facebook, Twitter, IM in general, email in general, MUDs and MMOs, telephones, telegraphs...

Should all those go away, too?

Re: The story around the Linode hack

#74

Earlier quoted context omitted.

I didn't say it would be technically impossible, I said it would be noticed. If you make it a theoretical problem, and it most certainly isn't (there are a lot more practicalities involved), you're adding at least another string compare to every query. That's enough of a latency shift for me to notice in my graphs -- I notice when the Internet reroutes itself and my DNS latency goes up by 5 milliseconds. This isn't a…

I wasn't speaking theoretically. I don't understand how a pipe read + string compare + pipe write would add 5ms per query. As for detection, that was the reason I brought up CPU power. Modern CPUs are so fast that that it seems like this redirector would hardly generate a blip in any chart (such as top). I don't care about proving anybody wrong. I care about filling my knowledge gaps. I.e. it's interesting to try to…

You'd be using network sockets, not pipes (pipes are slow as fuck btw). And it would add the latency of the network transmission in both directions, plus the processing time, which would add up to much more than 5ms unless you're on the same network segment as your target. And higher CPU load increases latency.

Who is going to notice increased latency in DNS queries? Most likely web developers. Nobody else I can think of would do (non-cached) bulk DNS queries to random domains and actually be looking for millisecond changes in lookup time. And those developers would have no insight to the DNS infrastructure serving requests, so they'd have no idea to contact the DNS admins to investigate. Even the DNS admins could be fooled before they contact network admins to do further research.

The bottom line is not "has DNS latency changed?", it's "has DNS latency become unacceptably high enough to force me investigate?" Unless it's becoming a problem, I think anyone would ignore increased latency because they have ten other work tasks to deal with.

Re: The story around the Linode hack

#76

Some hopefully-helpful clarifications of the inside baseball talk from just the overview (I haven't read the full zine), enhanced with inside and general knowledge I've gained in my travels on this mortal coil: - HTP claims to have{, had} access to name.com, which Linode currently uses. This access enables an unauthorized party to update authoritative nameservers for your domain; i.e., if you host at Amazon, very lik…

> - Linode got railroaded here and the general reaction by folks is a little overdone. You know that's true when even the hackers' overview of the hack specifically calls out people bitching about Linode security on Twitter. All it takes is one zero-day, and you will all be hit by one in your career, so cut Linode a little slack. Unfortunately, there's not much slack left to cut. Linode pulled that line taught with t…

Agreed. The one thing I think Linode could do better is communicate. The secrecy model is ... odd.

Re: The story around the Linode hack

#77

Earlier quoted context omitted.

IRC is a communication medium. Could we please not vilify it? It's like saying people who use burner phones are bad people.

It's also a machine that generates dumbed-down conversation. The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. There's nothing inherently wrong with this. But it does foster negativity much of the time. I know hundreds of people who dedicate their lives to the drama and bullshit that is spawned solely by being in an IRC channel. If it went…

I think contributors to the many open software projects that both you and I depend on, that use IRC as a first class collaboration tool would strongly disagree with this point of view. I certainly do.

Re: The story around the Linode hack

#78

Earlier quoted context omitted.

You're not getting it. No one is saying that Stuxnet was "right". That conversation is set in an entirely different context than the Linode hack. Iran is seeking to produce a nuclear weapon with the openly stated goal of launching it against another country. There is no segue from Stuxnet to this Linode hack. "Fault" is not in question here either. Let's say I leave my front door unlocked. If you enter my home withou…

I admit Stuxnet was a bad analogy to black hat hacking. But either is the analogy of hacking into a server and physically trespassing into a private property. The main goal of my comments is to object to the opinion that hacking is somewhat comparable to physical break and enter actions. This is an age where one can find himself in prison for tens of years for hacking and getting access to information (the prospects…

> Being in an underground hackers crew is much fun and possibilities to learn things for young men who are smart and different than their friends. Those guys and gals are the future top-class engineers at Google and other IT giants and I want them to continue hacking and growing personally and professionally, not rotting in the prison.

Or the next members of the many criminal syndicates on the internet who steal/harass/blackmail with little regard of the consequences.

Re: The story around the Linode hack

#79

Earlier quoted context omitted.

IRC is a communication medium. Could we please not vilify it? It's like saying people who use burner phones are bad people.

It's also a machine that generates dumbed-down conversation. The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends. There's nothing inherently wrong with this. But it does foster negativity much of the time. I know hundreds of people who dedicate their lives to the drama and bullshit that is spawned solely by being in an IRC channel. If it went…

The natural slant on IRC is away from intelligent discourse and toward a cross between texting and one-line jokes with friends.

What? I could name 20 channels of the top of my head this is not true for.

Post reply on HN