MasterCard under DDOS, can't process SecureCode online payments
blog.securetrading.com
blog.securetrading.com
First, let's stipulate that 4chan's Anonymous raids are mostly juvenile and often ineffective at doing anything meaningful to their targets.
At the same time: The ability of a community to completely self-organize, without central direction, and instantly execute a publicly-visible plan like this is without precedent in human history.
It stands to reason that as time goes on, larger groups of people will become involved in communities that exhibit 4chan-like cohesion. A larger pool means a higher likelihood of these groups including people with the knowledge and ability to do ever-increasing damage.
The long-term implications are interesting. Into the future, are we talking about the instant formation and dissolution of "terrorist" or "dissident" groups, bound together by transient common interest and gone again within days or hours? If you're a government or corporation, this is terrifying. You can keep tabs on other governments, and even traditional terrorist cells, which each move at the speed of the usual group dynamics, proportional to their size.
But what the hell do you do about groups you can't predict that are gone before you even figure out what's wrong? Groups that aren't bound together by national identity or other easily quantified affiliations – just ideas, ideals and transient events?
There's something meaningful here that points to how we all get along in the future, in the same vein as the "post-secrecy world" presaged by Wikileaks-style activism enabled by network technologies.
Or maybe I just need a nap.
I don't see any reason to believe it went down that way.
It's probable it was a group who already had much of the ability in-place to execute an attack like this, and who decided to target mastercard.com because it was found to be vulnerable, or because paypal and amazon were out of thier reach.
Economist / Babbage: http://www.economist.com/blogs/babbage/2010/12/more_wikileak... (I think he gets the definition of OP wrong, but everything else seems to jive with my non-firsthand understanding.)
The internet has no filter. Information flows at a steady constant pace; in fact most communication now a days can take place immediately. This has its pros and cons. Pros, well its awesome. Cons, without a filter many people will jump on a bandwagon without knowing the full details of a situation.
Sometimes people do not think as logically as they think they are. Acting on hearsay and emotions alone will lead people to act reckless, and once that stone starts rolling it's hard to stop; zerg.
This should not be taken as a generalization of online networks as there are outliers in most situations. This is just a reminder that not everyone on the internet has other people best interest in mind. Some people are just mean.
The best relationships are somewhere in the middle.
What about a government doing as it sees fit? That should be more frightening to you because it's existing for a long time and it's cost countless lives. And it's still doing so.
Of course, a government has the ability to influence a situation more than the Internet; they can pretty much do what ever they want. I don't see them throwing that weight around to much though. In fact, if the Wikileaks documents has taught anyone anything, it is that the government is on its grind 24-7 365.
Dont get me wrong. DDoSing Paypal, Master Card, et al is pretty entertaining, but I wonder what that cost other people? They screwed with an individual organization, well they have millions of clients. Instead of giving the situation time to develop, the Internet took the easy path to instant gratification, destruction.
If you mess with ourIdol(X) we(Y) will not hesitate to take you(Z) down, and not care about them(ABCDEFGHIJKLMNOPQRSTUVW)
A better solution would have been: Get the news. Allow the news to sink in. What is the gravity of the situation? Are there any opposing arguments? Let those arguments sink in. Rationally, which view is better? Has the news changed yet? Form opinion. Talk to opposition. Plan. Attack.
All of that should take at least a 1 or 2 days. Internet, their on it in like 5 minutes.
I suspect you don't know much about anarchy if you think it's without order. It's just (according to the literature) without inequality.
>but I wonder what that cost other people?
At this point, there is pretty much no action you could take that would have any effect on the people you wish to motivate without affecting innocent people as well. Deciding to not use a monopoly business only has negative affect on you, not the monopoly. They wont even notice.
The writer used the various strikes and protests in Europe as an example. His point was that as the nation-states became less relevant, people would begin to more closely associate in virtual groups than geographic ones.
I _also_ read the recent leaks about China, which leads me to believe that the Chinese think they can keep a lid on the internet.
This could be the beginning of a long, drawn-out period of chaos and overreaction by all sides. Sure would suck to have to choose between that and totalitarianism (even if, in the end, totalitarianism wouldn't work) Perhaps this is some author's overactive imagination though. I sure hope so.
The anarchist groups active today are a little less troubling than groups like the Red Army Faction, Red Brigades and the Irish Republican Army that were a feature of the 1970's and 1980's.
The real danger of mob rule might come from unscrupulous politicians making capital from social tensions. The recent series of expulsions of Romany from France and Italy were certainly a very troubling reminder of Europe's recent history.
http://en.wikipedia.org/wiki/Nicolae_Ceau%C5%9Fescu
And I do not doubt that if some European politician got it in to their heads to try something really stupid that such 'reminder' demonstrations would turn violent pretty quickly.
In France it wasn't 5 years ago that 100's of cars were burned every night and in the Netherlands squatters do battle with the riot police with some regularity.
Mob violence is never far away.
If you can do better than that be my guest, but I definitely see them as motivated by politics, even if not directly attacking a specific policy or having a concrete goal. It's more an act of frustration with life set off by the friction between police and these youths, specifically one incidence was the spark that set off the powder.
I've lived 'east' of Berlin for a while and still spend quite a bit of time there and in Romania and this particular sentiment strikes me every time I'm there. In the big cities the differences are large but outside not nearly as much if at all. Poverty is still quite present and the fat cats have found ways of getting fatter.
At least it's gotten easier for people to get around, provided they have the means of doing so.
A successful mob revolution requires a huge mob that can spill over government opposition. Such a huge mob can be prevented in 2 main ways - $ and Fear:
1. The Chinese and Singaporean approach: The fascist state with a booming economy. Fear of punishment and desire to make money keeps the mob small.
2. The North Korean approach: Have such a huge military that the rest of the country can not overrun it ever. The downside is no state can support that kind of military and you get starvation.
Iran etc. are a mix of 1 & 2 with less prosperity then Singapore but more sate violence and spying then China.
I have absolutely no faith that a violent revolution can happen anywhere in today's Europe. We're too old and too rich.
Such a huge mob can be prevented in 2 main ways - $ and Fear
Fear, Doubt and Censorship is what defined the Stalinist regime before Dec '89 in Romania. The North Korean approach: Have such a huge military that
the rest of the country can not overrun it ever.
The military is formed out of ordinary people that can switch sides at any time. Also wars are won in the hearts first: you can make the military switch sides if you give the impression that this isn't a war they can win.In Romania I still think it was a coup d'état, as the army switched sides quite early; but the mob was there, it was furious ... and it emerged out of nowhere. And it was interesting because romanians really aren't violent people.
Governments should learn to not piss off citizens: people can take a lot of pain before acting, but there's always a tipping point and from there onward it turns into a civil war between millions of people and a couple of thousand with guns (but that's a short-lived tactical advantage).
In Plato's Republic, he set up a cyclical theory of the progression from one form of government to the next. From aristocracy to timocracy to oligarchy to democracy to tyranny and back again to aristocracy.
The transition between democracy and tyranny was ochlocracy, a.k.a. mob rule, out of which emerges a demagogue.
Maybe some of them fall into this category, but many of the others are the ones pulling most of the strings.
They are responsible for millions of dollars in campaign contributions, whereby they essentially buy seats in the House and Senate and dictate much of the legislation. They influence voters through mass advertising and propaganda, they influence the representatives through lobbyists and the threat of withdrawing their financial support.
The "government" then becomes a battlefield between the ignorant, the manipulated, the enlightened, and the powerful manipulators sitting at the top.
This seems to be a chicken-and-egg question to me. I'm not sure how you can determine whose strings are being pulled, and who are the pullers.
Is it really the corps that are coercing the politicians into misbehavior? Or is it the politicians that create an environment in which corporations can gain an advantage by doing so?
In all countries today, the power of the government, or an individual politician, exceeds that of a corporation. That's obviously true, or why else would the corporations be contributing to political election campaigns? Corporations are (despite popular complaints) at the mercy of their customers; look at the OP for an example of how corporations are held instantly responsible for any perceived action, contrasted to politicians who "launch an investigation" and then the problem is forgotten long before the next election, or who use demagoguery to convince voters that they are the lesser evil; if the opponent wins the country will fall apart.
Similarly, in all cases the government controls far more money than any corporation. What portion of the GDP does the government's budget make up? Compare that to the revenue of any corporation.
EDIT: OK, guys. I'll take a down-vote, but please give me the courtesy of an explanation as to why I'm wrong.
US multinationals do depend on security provided by US Government, but they can exist without it too. The US Government on the other hand is absolutely and wholly dependent on large multinationals, at least in it's current form.
In China or Russia it's the other way around. Government does work with both domestic and multinational big co's, but shall the need arise they will be reduced to Nil in no time as has been demonstrated time and time again.
P.S. power of any individual politician exceeds that of largest corporations? Seriously?
Yes, in the sense that they don't need to rely on the government. On the other hand, they are at the mercy of the government. One quick flourish of the pen, and a company can be destroyed. Obviously this is true at the startup scale, where a niche can simply be erased. But even at the larger scale, a national decision to back one approach can be devastating (as in FCC decisions). Or antitrust actions can decimate a company (ATT, IBM, narrowly avoided by Microsoft). The bottom line is that the government has the guns, literally.
The US Government on the other hand is absolutely and wholly dependent on large multinationals
I simply can't see how this is the case. Can you explain further? I mean, I don't see how the government needs Google or GM in any way.
power of any individual politician exceeds that of largest corporations?
I probably made that sound grander than I should have. In once sense, if every other politician is against you, then in general, winning one to your side won't help. However, in more realistic circumstances, winning a single person to your side (especially with America's committee system) can make all the difference. A single congressman influencing the language of a bill can mean hundreds of $millions in income, or the complete obsolescence of your business plan.
This is just absolutely not true. When US president has the guts to suggest that company(ies) responsible for largest ecological disaster in US history should pay for it, it equalled to "shake-down" to people currently running US legislative branch, then what are we even arguing about? ATT, IBM and MSFT were decimated? Seriously? They were broken-up, as they were approaching monopoly (that's a good thing you know), but all three examples and their spin-offs are thriving since then.
One thing you got right though - start-up world is risky.
Even if you're right, it's beside the point. My argument was that government holds ultimate power even against the biggest corporations.
It is true that they're not always able to wield their power, as in your BP example. That's a good thing, because it demonstrates that the government is at least constrained to operate predictable (i.e., the rule of law). If the government were able to spin anything as a righteous stand, and do whatever they thought they could get away with, then business (and indeed any freedom) would be stymied, because people could not be certain that they'd be able to go about their business -- the fear from uncertainty would inhibit all sorts of activities.
And the fact that ATT and IBM are doing well now really doesn't enter into it. The simple fact is that these were giant, powerful corporations. Yet the government still had the power to tear them apart. That simple fact demonstrates my argument; the "goodness" of the action is besides the point.
Nonsense and demonstrably false. If Al Gore had won his election that would have been the first time in 20 years that a candidate who didn't spend the most money won a presidential election. In Michigan the only Senator to vote against the Patriot act got ousted by a clueless hack who, once again, happened to spend a lot more money.
Spending more money doesn't always win, but it has enough effect that politicians live or die based on campaign contributions. Snap their fingers and wipe away a corporation? Yea right, so no other corp would ever give them money again?
I'm afraid you're living in a dream world. The US government is completely owned by big business. The only difference between republican and democrat is which companies they are owned by.
Let's put aside what is "legal" and focus on what is "socially desirable" business behavior from the perspective of Anon. MasterCard, as a private entity, has wide leeway in how it chooses to deal with other private entities such as Wikileaks. Is this socially desirable? While I have no special insight into what Anon is thinking, I would surmise that they are not pleased that private entities are restricting free-flow of information and acting as a state's agents even when not compelled to do so by the force of law.
We've heard from many business (Amazon, PayPal, etc) that blocking WikiLeaks (and consequently inhibiting free distribution of classified US documents and secret corporate information) is, at its core, a profitable business decision. I would guess that Anon is trying to send a message that such an "anti-freedom" decision (scare quotes intentional) can instead become very expensive.
It's Mastercard's choice whom they do business with, and by launching this attack Anon is only further solidifying the misguided popular belief that Wikileaks is akin to a terrorist organization. It may seem like a victory in the short term, but in terms of Wikileak's PR I think it's a huge setback.
No it's not.
Can you explain how it isn't their choice? Mastercard, VISA and American Express turn down applicants ALL the time, so doesn't this go against what you are saying here?
I'm not saying it isn't their choice, but there is no real advantage to them angering politicians who could screw them on votes or funding at some point in the future.
Why would anyone do business with someone if there was even a tiny chance that they would get screwed over the next day to the tune of MILLIONS and MILLIONS of dollars. The fact that mastercard.com is down and their SecureCode service is offline has already cost thousands of small businesses millions of dollars. Do you think these companies are going to support something like Wikileaks after this event?
Anon has reduced Wikileaks' available resources by making people less likely to facilitate donations to them.
Visa and MasterCard can block payment providers if they believe those generate a lot of fraudulent activity, not because they disagree with those organisations activities.
I fully support unions and strikers, however I'm not sure how I feel about this kind of action. The similarity ends with differences such as strikers have names, faces, spokespeople, they decide together if they are for or against striking, it isn't one or more people with nothing to do with the company who makes the decision.
This kind of action is asymmetric and unbounded: Anon can hurt MasterCard without cost to himself (presumably) and he can theoretically carry it out for as long as he wants. This can only lead to some kind of escalation if MasterCard (and similar entities) want to survive.
Also, is it better to let those populations suffer in "jail" for generations? (If I was Eastern European, I'd be pretty pissed to have been left to rot until 1989.)
If nothing else, the dictators spread their problems (support of terrorists, atom weapon programs etc).
Look at WW II for what will happen when democracies are pressed. At the start of the war, British military argued against bombing private property (German factories). Compare that to a few years later.
(I guess the place where this is closest to happen next, is Israel and the humongous Hezbollah (/Hamas?) arsenals of rockets optimized for attacks against civilians.)
Point is, those juntas are arguably a blight on humanity that needs to be solved, the longer it takes the worse it might be.
Ah well, this is both after the discussion and irrelevant to Wikileaks.
Edit: Made a bit clearer.
Presumably getting caught and jailed/fined is a potential cost? So it's not an action without risk/cost.
"Legal" just means the government agrees with it. The state claimed a monopoly on "law" along the way.
The tension we see today is that the "legal" does not represent the "socially desirable" / "law" anymore.
Granted, a binary offline/online result using DDOS attacks is a very rude reputation system, but the reputation feedback processes can be improved upon by competition (semantic web startups anyone?).
Exactly. In the US we have a system of checks in balances to pit competing mobs against each other in a way such that it is sufficiently difficult for a mob to rule over a large population. But if the mob gets sufficiently large, they can rule. And likewise, for small geographic regions we often do have mob rule.
LOIC is really, really basic, and anon has never really gathered any respectable amount of bandwidth. Most small botnets put them to shame.
What I suspect, however, is that actual botherders are using these raids as cover. They can still DDoS the target, but 4chan takes the blame. The recent addition of "hivemind" functionality to LOIC, which slaves the user's computer to an irc feed that controls targeting and firing, seems like the perfect opportunity for a botherder to set their botnet to take orders from same.
And attacking a website is never justified. It is wrong regardless of how much effort the owner puts into securing it. Likewise, it's exactly the same crime to steal a car that has an alarm as one that doesn't.
As to your specific point, leaving my car unlocked with the windows down overnight on a dark street in Detroit doesn't make the inevitable thieves justified, but it does make me retarded, and completely undeserving of sympathy.
edit: The only difference is in how fast you manage to recover.
I don't see why civil disobedience should cease to be civil disobedience just because it's on a computer.
A boycott is only effective if the disgruntled group has enough population to affect the business of the target. There in lies the problem with a DDoS attack. It is not a symmetrical response. A small group of people could execute such an attack, while the majority of actual customers may not have an issue with their actions.
When it comes to oligopolies, the usual rule of corporations as private, independent entities that can do whatever they please, goes out the window.
Must they also offer service to companies with bad credit or a history of fraud?
That said, Paypal is not making nearly enough on transaction fees to cover wasting a single minute of a lawyer's time. If there's even a chance of there being legal issues with an account holder, it's almost certainly in their business interest to end that account.
There doesn't even need to be explicit conversation between government officials and Visa/MasterCard for there to be a conspiracy; it's more of a matter of a gentleman's agreement to cover each other's backs.
I don't like that they've denied them service, but I believe it is and should be perfectly legal for them to do so. Can you explain why you think it should be illegal?
A market that's guarded by a couple of monolithic entities with similar interests is not open, and without credit card transactions a lot of international business is essentially impossible. I believe that's too critical an issue to be left to the whims of corporations.
The situation would be very different if we had dozens of easily available credit card providers who would take our money with no hassles. Whether you consider that a failure of the states or the corporations is no the issue at hand. The problem is one of assigning too much power to aisngle entity.
http://en.wikipedia.org/wiki/Montgomery_Bus_Boycott
> Under a 1921 ordinance, 156 protesters were arrested for "hindering" a bus, including King. He was ordered to pay a $500 fine or serve 386 days in jail.
It's all in how you spin it.
I think a better analogy might be a sit in. If you occupy all the seats in a restaurant, I think it kind of qualifies as a meatspace DOS. I guess the difference is that in civil rights sit ins of the 60s, the people sitting in actually wanted service.
I guess the digital analogue would be a bunch of people requesting permission to donate to Wikileaks, rather than permission to load the page. It seems the subtle difference is that civil rights groups actually wanted the service that they deny to others, while anon wants a service different from the one they are denying to others.
I guess its up to individuals whether they think the difference is significant.
* Your role is an employee is to help accomplish a corporation's objectives.
* (In this case) the corporation's objectives are unethical.
* You're contributing to something unethical.
That being said, nobody is perfectly ethical. But if I worked for Amazon or PayPal, I'd have quit by now, and I'd never have taken a job with MasterCard in the first place.
I also don't mean "held responsible" in a legal sense, either. They've done nothing wrong legally. Legality != morality, though.
But they are responsible for those they know about.
Most people don't have the option of just up and quitting their jobs.
Even if finding a new job is easy, it's still difficult. I just went through this process, it's still rough...
As I said, everyone makes choices. Everyone commits minor works of evil. If doing wrong is worth your mortgage... it's your life.
The only reason these things work today is because of a lack of urgency. I mean, when this starts happening every week, people will call for regulation, it may take a few years to get it sorted out politically, then another few before the policy catches up, and things like this won't be possible any more.
In the mean time, the damage done is relatively small. Yes it sucks for some online merchants, but let's not blow this out of proportion.
I remember 10 years ago there was a 'digital sit in' (the term 'ddos' didn't exist yet) on my at that time employer's website. There were camera crews coming in, interviewing our CEO's, it was big news. In reality, the effect was minor; averaged over the few days around it, the loss of sales was not even statistically significant.
Imagine 100 years ago, when building and driving cars was practiced by enthusiasts only, how they must have lamented the prospect of not being able to drive as fast as they would like to on all roads! I'm not saying I'm looking forward to more control over the internet, but the Wild West days are over, and as the internet and computers become more fundamental in societal functioning, some form of oversight to safeguard a good functioning are inevitable.
Seriously, if you thought enforcing traffic laws was a futile affair, just wait until the other 4 billion people on this planet get online, and the Internet becomes the medium of transmission for literally every bit of shared information on the planet. Think about it: every TV show, every film shown in theaters, every phone call, every book, magazine, and newspaper; things I'm not even thinking of because they haven't been invented yet. (While we're on the subject, every speeding ticket too.)
That day will come, sooner than you think. You seriously believe we will have the capacity to police that? I am dubious.
You can hardly expect these things to arise overnight. I'm not sure what your point is on all the data that will be generated, transmitted and consumed. There is (in the context of this discussion) no need to track all of that, only to find out what the source is of traffic deliberately causing problems. Of course we will be able to pinpoint the origin of disturbances; when we can't any more, we'll be in Singularity territory, and then all of this is moot anyway.
This 'this is the Internet, your norms don't apply to us' nonsense needs to die already. With the internet becoming institutionalized, the same order that has arisen in meatspace will arise online. Of course there will always be the fringes where subgroups hang out in to a greater or lesser degree separate order (like the downtown biker bar in meatspace), but that doesn't prevent order from existing elsewhere.
Take your own phase, "pinpoint the origin of disturbances." What exactly is meant by that? There are literally thousands of people all over the world who loaded up LOIC and are participating in this attack. I myself contributed simply by surfing to Mastercard.com to see what all the fuss was about, as I'm sure millions of others did as well. Who is culpable? Assuming it were technically possible, how would you go about solving this problem? I hope you'll agree that the word "pinpoint" is hopelessly inadequate here.
Anyways, the entire analogy is flawed. Policing that internet is absolutely nothing like patrolling the highways. How do you account for encryption? The fact that physical presence has no bearing on your online activities? This is unlike anything we've experienced before, and I have a hard time seeing free and democratic societies putting the genie back in the bottle. China is another story.
The question is not how to control, within hours, an attack like the one that happened on MasterCard. The matter is that when it happens again, and there is enough momentum for it, everybody participating will be logged (I mean it's generally not that hard to distinguish between a regular visitor and someone running LOIC) and prosecuted. After a while it will become known that doing things like this has consequences, and the amount of people willing to participate will fall rapidly, until there is only a core left (this core is usually hard to control, but small enough to not matter much).
Take another analogy: rioters. What is the strategy when you have a group of rioting protesters? You contains the damage (police squads to keep the mob from strategic points) and you arrest a few of the core people and prosecute them. That doesn't stop rioters, but it does impose a barrier on participation; so the size of the group of people willing to riot is small enough to be restricted to some extremists (which, despite popular opinion, is quite small).
MC thought that preventing money from going to some people who move information around was a smart business decision. Anonymous replied with, <<No, trying to prevent the free flow of information is a bad business decision.>>
They do this, presumably, with the idea that next time MC will think twice before doing their part in silencing the flow of information.
This is all irrelevant to WikiLeaks. They have nothing to do with this at all, except that their particular case provides Anon with a clear example to set for MC.
If they continue to choose to ban payments through their system to Wikileaks, I assume they'll continue losing money from DDoSs. shrug I don't have any idea what'll happen, but I think you have to accept that Anon has a point, even if you don't agree with them.
MC slows the flow of information. Anon slows the flow of cash to MC. If MC doesn't respond, it seems like they'll keep losing money.
And I think the answer is no, although it's arguable. There is surely a point at which MC will try to do the "right" thing instead of the profitable thing, and it's easy to see how that point is between cutting off Wikileaks (which arguably is harming US national interests) and changing business strategy to appease hackers.
Given that its unclear to me that what Wikileaks even did is illegal (http://www.nytimes.com/2010/12/02/world/02legal.html?_r=1) I have little sympathy for MC. It just feels like they're a bully in this situation. It does suck for their customers though. Maybe more customers will drop MC due to their inefficiency? Who knows.
If I worked for any sort of internet payment gateway, I'd certainly make sure to never take on Wikileaks as a client.
Notice that if there is no response at all from, let's call it "the internet crowd", then there will be no free speech on the internet. Any attempt to say anything which corporations aren't comfortable with (this includes anything that the governments aren't comfortable with) will be quickly silenced.
So, while I am not a fan of 4chan's DDOS attacks, I see them as a reaction — similar to crowds in the streets.
I think not. It is of course if it is only one private company, because the individual has a choice, but if all private companies deny it, then the individual has no choice, thus it is no different than the government itself having denied it.
This that we are seeing, I believe, is the connection between corporations and government in action, the business-government complex if you like. Private companies should not have the right to discriminate based on other's beliefs or opinions.
Boycott list:
* Amazon (Amazon stops hosting WikiLeaks website [Reuters, 20101202])
* Tableau Software (Another Falls: Tableau Software Drops Wikileaks Data Visualizations [20101202])
* Everydns.net (WikiLeaks fights to stay online after US company withdraws domain name [guardian.co.uk, 20101203])
* Paypal (WikiLeaks loses PayPal revenue service [cnn.com, 20101205])
* PostFinance (Swiss bank freezes WikiLeaks founder's legal defense fund [rawstory.com, 20101206])
* MasterCard (MasterCard pulls plug on WikiLeaks payments [cnet.com, 20101206]
* Visa (WikiLeaks loses PayPal revenue service [ibnlive.in.com, 20101207])
* Twitter??? (it was or it wasn't censorship?)Unless the Boycott is huge.
Now, if you just reduce your usage of their services, then you're right, it'll be hard to attribute.
Boycotts and demonstration raise awareness, but unless it reaches a critical mass, they don't work. Boycotts and demonstrations that disrupt (like marches through the street or strikes) are other forms of economic attacks that cause real monetary loss.
Voting with your wallet only works so far. Usually you're in the minority. Not because you're wrong. Even elections understand this: the results are based on those who voted, not those who could vote.
Review history, and time and time again you'll see economic attacks as parts of non-violent means.
And what about the guy who was buying safety equipment and now he has to do the first day without it?
Edit: I should also remind you that even if you want to accept your arguments, they aren't impacting actual transactions. Merely SecureCode transactions done online. So I highly doubt a diabetic in need of medicine now is going to order online.
Edit 2: And seriously, a guy get's a bit more hungry because he has to wait a tad longer because he can't order Fat Man's Pizza online because SC is down, and that's violent? Heck, then I guess Gandhi wasn't so peaceful after all, what with his salt march causing less money for people, and therefore, less money to buy food with, and therefore, less food to eat.
But I didn't know it was online only. In that case it's hard to think of plausible ways it would do physical harm.
I didn't say "violent" so don't complain about me calling stuff "violent". All I said is that economic harm can cause physical harm, it's not harmless (contrary to the person who said it is harmless. not low on harm but literally harmless).
You should not be upset with people who make corrections without expressing any opinion. Factual, literal-minded minor corrections are no threat to your side unless your side is mistaken.
No. I can't think of a way having my CC being denied online is going to physically hurt me. Maybe you can give an example.
Seriously though, your logic is flawed.
> I didn't say "violent" so don't complain about me calling stuff "violent".
Sorry, but what would you call an attack that causes physical harm? Peaceful?
You don't have to say the word violent, but you can still describe it.
> All I said is that economic harm can cause physical harm
And a butterflies wing could flap because of it can cause a hurricane causing the deaths of millions. Yes, everything is connected. I can create all sorts of crazy scenarios. Let's stick to reality.
Anon is doing a DDoS. Twisting that round and saying "Anon is attacking people causing physical harm" is dumb.
> Factual, literal-minded minor corrections are no threat to your side unless your side is mistaken.
I'm fine with factual, logical minded corrections. Your comment was void of that. You should remember context.
Until you can show anon attacking people causing physical harm, your actually not saying anything.
Yes, economic harm has real life consequences. Everything relates. Heck, you could make arguments that NOT DDoS could save someones life because someone couldn't pay for a gun they were going to use to kill someone with. You can go crazy with all sorts of stupid thought experiments. I mean, hell, let's go all out. Your posting of comments is killing living things, what with all the electricity needed to power the servers that connect your computer to this server. Your purchase of your computer keeps low-wage works in low-conditions.
But all that is stupid.
And that's not what I meant. And you know it. That's what makes you dishonest.
Is it because you think I posted something wrong on the internet?
If boycotts and demonstrations don't reach critical mass, then they were not accepted by your peers. Be glad for this, many groups that are not generally accepted do marches that don't generate popular support.
Same logic can be applied to Rosa Parks, who held up a bus full of people and delayed them from getting to wherever they were going, and also forced a police officer to deal with her rather than stay on patrol watching for real crime.
Of course, even in this case, it's dealing with the MC servers, which affects SecureCode. People aren't buying gas or food out and about with SecureCoded MCs.
So, either you agree with me... or you disagree with me. Which is it? Are you suggesting Parks attacked people, or do you agree with me?
Could anyone explain what it would take to minimise vulnerability to such attacks? I would have expected the standard load on SecureCode to be pretty high anyway, so I'm surprised that an attack brought it down. I welcome anyone to fix my reasoning :)
Basically, if your site is open to the public then it's open to bots. And there are far more bots than people. So if someone directs their bots to your site, you'll go down.
End of story.
It seems mission-critical to get their site back up, but they haven't. I assumed that was because they couldn't. But if you say they can....why haven't they?
Everything is hard the first time.
Easiest form of DoS to carry out and easiest to defend.
Prevention:
a) Upstream forwarding proxy that will block all requests from an IP that hammers the server
b) Low timeouts (5-10 seconds)
c) Intelligent upstream router than can drop the routes
d) They are hitting mastercard.com, which should be distributed on a CDN
e) Separate the public website from the application, don't even but them in the same IP address block
At Techcrunch we survived a 4chan DoS attempt. Surprised Mastercard didn't (I think the scale of this attack is larger, but still)
I wouldn't mention it; just my friendly advice. Anon is a fickle beast.
That's a pretty large but, when a DoS is, by nature, all about scale.
http://en.wikipedia.org/wiki/LOIC
They even gave it a cute name.
I find the 'relinquish control' part really interesting. Someone could totally f anon over if a hivemind version with access to the OS was released. Yeah, you could only ever use it once, but once is enough. 4chan would reverb about it for months.
Also because I just kept imagining the program playing a clip of the Harbinger going "assuming direct control" whenever you relinquish.
Going with the latest web server attack (the long open connections with POST) there is not a whole lot of protection that could be afforded other than throwing more resources and more servers at the mix such that each of them can handle the open connections that are SLOWLY sending data to them. There could be time-outs, but those are easy to figure out with some experimentation and it doesn't require much to keep endless connections going forever and sending the bare minimum required to keep the connection alive.
Other attacks like ICMP ping floods just flood the network to the point that the routers are unable to physically carry the traffic from point A to point B. They start dropping packets. If at this point you attempt a TCP/IP connection it most likely will not get through in the large flood. ICMP traffic can be dropped at the door, letting legitimate traffic through again, and generally can easily be taken care of at the edge routers.
Then there are the various TCP/IP flood attacks which are mostly designed so that on the target a connection stays in an open queue whereby the host runs out of backlog so that it can't accept new connections, also known as half-open connections. SYN cookies help with this.
Or still the best method is to have a VERY large botnet of computers that attack the target so that the amount of traffic is simply overwhelming no matter the method used. If your server is on a 100 Mbit connection, you can NEVER accept 1 Gbit worth of data. Now multiply that and start looking at where in the infrastructure there is a bottleneck. If inside your network you can accept 10 Gb's a second, but your gateway router is only rated at 1 Gb's a second you can just choke the router and it doesn't matter what is behind it.
With massive DDoS attacks it becomes very costly, as you have to divert the traffic elsewhere first where it can efficiently be filtered for legitimate and non-legitimate and then have it be sent on to the actual backend servers that then respond.
The only solution is to have nothing to do with them. Not exactly an optimum solution - I'd much rather be cut off and constantly find new hosts than have people afraid to have anything at all to do with me.
These attacks are not helping wikileaks.