Let's put aside what is "legal" and focus on what is "socially desirable" business behavior from the perspective of Anon. MasterCard, as a private entity, has wide leeway in how it chooses to deal with other private entities such as Wikileaks. Is this socially desirable? While I have no special insight into what Anon is thinking, I would surmise that they are not pleased that private entities are restricting free-flow of information and acting as a state's agents even when not compelled to do so by the force of law.
We've heard from many business (Amazon, PayPal, etc) that blocking WikiLeaks (and consequently inhibiting free distribution of classified US documents and secret corporate information) is, at its core, a profitable business decision. I would guess that Anon is trying to send a message that such an "anti-freedom" decision (scare quotes intentional) can instead become very expensive.
It's Mastercard's choice whom they do business with, and by launching this attack Anon is only further solidifying the misguided popular belief that Wikileaks is akin to a terrorist organization. It may seem like a victory in the short term, but in terms of Wikileak's PR I think it's a huge setback.
No it's not.
Can you explain how it isn't their choice? Mastercard, VISA and American Express turn down applicants ALL the time, so doesn't this go against what you are saying here?
I'm not saying it isn't their choice, but there is no real advantage to them angering politicians who could screw them on votes or funding at some point in the future.
Why would anyone do business with someone if there was even a tiny chance that they would get screwed over the next day to the tune of MILLIONS and MILLIONS of dollars. The fact that mastercard.com is down and their SecureCode service is offline has already cost thousands of small businesses millions of dollars. Do you think these companies are going to support something like Wikileaks after this event?
Anon has reduced Wikileaks' available resources by making people less likely to facilitate donations to them.
Visa and MasterCard can block payment providers if they believe those generate a lot of fraudulent activity, not because they disagree with those organisations activities.
I fully support unions and strikers, however I'm not sure how I feel about this kind of action. The similarity ends with differences such as strikers have names, faces, spokespeople, they decide together if they are for or against striking, it isn't one or more people with nothing to do with the company who makes the decision.
This kind of action is asymmetric and unbounded: Anon can hurt MasterCard without cost to himself (presumably) and he can theoretically carry it out for as long as he wants. This can only lead to some kind of escalation if MasterCard (and similar entities) want to survive.
Also, is it better to let those populations suffer in "jail" for generations? (If I was Eastern European, I'd be pretty pissed to have been left to rot until 1989.)
If nothing else, the dictators spread their problems (support of terrorists, atom weapon programs etc).
Look at WW II for what will happen when democracies are pressed. At the start of the war, British military argued against bombing private property (German factories). Compare that to a few years later.
(I guess the place where this is closest to happen next, is Israel and the humongous Hezbollah (/Hamas?) arsenals of rockets optimized for attacks against civilians.)
Point is, those juntas are arguably a blight on humanity that needs to be solved, the longer it takes the worse it might be.
Ah well, this is both after the discussion and irrelevant to Wikileaks.
Edit: Made a bit clearer.
Presumably getting caught and jailed/fined is a potential cost? So it's not an action without risk/cost.
"Legal" just means the government agrees with it. The state claimed a monopoly on "law" along the way.
The tension we see today is that the "legal" does not represent the "socially desirable" / "law" anymore.
Granted, a binary offline/online result using DDOS attacks is a very rude reputation system, but the reputation feedback processes can be improved upon by competition (semantic web startups anyone?).
Exactly. In the US we have a system of checks in balances to pit competing mobs against each other in a way such that it is sufficiently difficult for a mob to rule over a large population. But if the mob gets sufficiently large, they can rule. And likewise, for small geographic regions we often do have mob rule.
I don't see why civil disobedience should cease to be civil disobedience just because it's on a computer.
A boycott is only effective if the disgruntled group has enough population to affect the business of the target. There in lies the problem with a DDoS attack. It is not a symmetrical response. A small group of people could execute such an attack, while the majority of actual customers may not have an issue with their actions.
When it comes to oligopolies, the usual rule of corporations as private, independent entities that can do whatever they please, goes out the window.
Must they also offer service to companies with bad credit or a history of fraud?
That said, Paypal is not making nearly enough on transaction fees to cover wasting a single minute of a lawyer's time. If there's even a chance of there being legal issues with an account holder, it's almost certainly in their business interest to end that account.
There doesn't even need to be explicit conversation between government officials and Visa/MasterCard for there to be a conspiracy; it's more of a matter of a gentleman's agreement to cover each other's backs.
I don't like that they've denied them service, but I believe it is and should be perfectly legal for them to do so. Can you explain why you think it should be illegal?
A market that's guarded by a couple of monolithic entities with similar interests is not open, and without credit card transactions a lot of international business is essentially impossible. I believe that's too critical an issue to be left to the whims of corporations.
The situation would be very different if we had dozens of easily available credit card providers who would take our money with no hassles. Whether you consider that a failure of the states or the corporations is no the issue at hand. The problem is one of assigning too much power to aisngle entity.
http://en.wikipedia.org/wiki/Montgomery_Bus_Boycott
> Under a 1921 ordinance, 156 protesters were arrested for "hindering" a bus, including King. He was ordered to pay a $500 fine or serve 386 days in jail.
It's all in how you spin it.
I think a better analogy might be a sit in. If you occupy all the seats in a restaurant, I think it kind of qualifies as a meatspace DOS. I guess the difference is that in civil rights sit ins of the 60s, the people sitting in actually wanted service.
I guess the digital analogue would be a bunch of people requesting permission to donate to Wikileaks, rather than permission to load the page. It seems the subtle difference is that civil rights groups actually wanted the service that they deny to others, while anon wants a service different from the one they are denying to others.
I guess its up to individuals whether they think the difference is significant.
LOIC is really, really basic, and anon has never really gathered any respectable amount of bandwidth. Most small botnets put them to shame.
What I suspect, however, is that actual botherders are using these raids as cover. They can still DDoS the target, but 4chan takes the blame. The recent addition of "hivemind" functionality to LOIC, which slaves the user's computer to an irc feed that controls targeting and firing, seems like the perfect opportunity for a botherder to set their botnet to take orders from same.
And attacking a website is never justified. It is wrong regardless of how much effort the owner puts into securing it. Likewise, it's exactly the same crime to steal a car that has an alarm as one that doesn't.
As to your specific point, leaving my car unlocked with the windows down overnight on a dark street in Detroit doesn't make the inevitable thieves justified, but it does make me retarded, and completely undeserving of sympathy.
edit: The only difference is in how fast you manage to recover.
The only reason these things work today is because of a lack of urgency. I mean, when this starts happening every week, people will call for regulation, it may take a few years to get it sorted out politically, then another few before the policy catches up, and things like this won't be possible any more.
In the mean time, the damage done is relatively small. Yes it sucks for some online merchants, but let's not blow this out of proportion.
I remember 10 years ago there was a 'digital sit in' (the term 'ddos' didn't exist yet) on my at that time employer's website. There were camera crews coming in, interviewing our CEO's, it was big news. In reality, the effect was minor; averaged over the few days around it, the loss of sales was not even statistically significant.
Imagine 100 years ago, when building and driving cars was practiced by enthusiasts only, how they must have lamented the prospect of not being able to drive as fast as they would like to on all roads! I'm not saying I'm looking forward to more control over the internet, but the Wild West days are over, and as the internet and computers become more fundamental in societal functioning, some form of oversight to safeguard a good functioning are inevitable.
Seriously, if you thought enforcing traffic laws was a futile affair, just wait until the other 4 billion people on this planet get online, and the Internet becomes the medium of transmission for literally every bit of shared information on the planet. Think about it: every TV show, every film shown in theaters, every phone call, every book, magazine, and newspaper; things I'm not even thinking of because they haven't been invented yet. (While we're on the subject, every speeding ticket too.)
That day will come, sooner than you think. You seriously believe we will have the capacity to police that? I am dubious.
You can hardly expect these things to arise overnight. I'm not sure what your point is on all the data that will be generated, transmitted and consumed. There is (in the context of this discussion) no need to track all of that, only to find out what the source is of traffic deliberately causing problems. Of course we will be able to pinpoint the origin of disturbances; when we can't any more, we'll be in Singularity territory, and then all of this is moot anyway.
This 'this is the Internet, your norms don't apply to us' nonsense needs to die already. With the internet becoming institutionalized, the same order that has arisen in meatspace will arise online. Of course there will always be the fringes where subgroups hang out in to a greater or lesser degree separate order (like the downtown biker bar in meatspace), but that doesn't prevent order from existing elsewhere.
Take your own phase, "pinpoint the origin of disturbances." What exactly is meant by that? There are literally thousands of people all over the world who loaded up LOIC and are participating in this attack. I myself contributed simply by surfing to Mastercard.com to see what all the fuss was about, as I'm sure millions of others did as well. Who is culpable? Assuming it were technically possible, how would you go about solving this problem? I hope you'll agree that the word "pinpoint" is hopelessly inadequate here.
Anyways, the entire analogy is flawed. Policing that internet is absolutely nothing like patrolling the highways. How do you account for encryption? The fact that physical presence has no bearing on your online activities? This is unlike anything we've experienced before, and I have a hard time seeing free and democratic societies putting the genie back in the bottle. China is another story.
The question is not how to control, within hours, an attack like the one that happened on MasterCard. The matter is that when it happens again, and there is enough momentum for it, everybody participating will be logged (I mean it's generally not that hard to distinguish between a regular visitor and someone running LOIC) and prosecuted. After a while it will become known that doing things like this has consequences, and the amount of people willing to participate will fall rapidly, until there is only a core left (this core is usually hard to control, but small enough to not matter much).
Take another analogy: rioters. What is the strategy when you have a group of rioting protesters? You contains the damage (police squads to keep the mob from strategic points) and you arrest a few of the core people and prosecute them. That doesn't stop rioters, but it does impose a barrier on participation; so the size of the group of people willing to riot is small enough to be restricted to some extremists (which, despite popular opinion, is quite small).
* Your role is an employee is to help accomplish a corporation's objectives.
* (In this case) the corporation's objectives are unethical.
* You're contributing to something unethical.
That being said, nobody is perfectly ethical. But if I worked for Amazon or PayPal, I'd have quit by now, and I'd never have taken a job with MasterCard in the first place.
I also don't mean "held responsible" in a legal sense, either. They've done nothing wrong legally. Legality != morality, though.
But they are responsible for those they know about.
Most people don't have the option of just up and quitting their jobs.
Even if finding a new job is easy, it's still difficult. I just went through this process, it's still rough...
As I said, everyone makes choices. Everyone commits minor works of evil. If doing wrong is worth your mortgage... it's your life.