Paypal.com appears to be unavailable
paypal.com
paypal.com
Isn't that exactly what the US government have done? "It's for the greater good". The people involved in these attacks are just as bad.
Try to keep things in perspective. We're facing a substantial progression towards a hybridization of the scenarios outlined in 1984 and Brave New World, and you're worried about the disruption of commerce?
Are your priorities really that warped?
There's always collateral damage, whether it's merchants or your civil rights.
I should've guessed that there would be hand-wringing about commerce on here, but I never knew it would be so ridiculous considering what's being hashed out here.
Give it a week and nobody will remember any of this, besides the businesses that lost money.
I'm completely opposed to these actions, but I've got to say that causing financial losses is a fairly effective protest.
That's the tragedy not
>besides the businesses that lost money.
Nobody cares about citizenship or rights anymore. Just money.
The majority of Paypal Visa and Mastercard customers rely to some extent on a stable international environment. Suggesting that these companies need to change their moral stance to accommodate anarchists is silly. Wikileaks actions suggest they want to take down the establishment that in a large part enables such companies to operate.
Indeed the fact that these companies have now been attacked by the associates of those they chose not to support means that they made the right decision. Why would they want to bolster groups that will turn and attack them?
If Paypal, for example, hadn't accepted Wikileaks as a customer in the first place then they wouldn't be having to deal with the current situation and could serve the majority of their customers better.
Taking a capitalist view basically Wikileaks supports believe that the rest of us should be screwed over so they can make their point. It's not civilised it's brutish anarchism.
> Wikileaks actions suggest they want to take down the establishment that
> in a large part enables such companies to operate.
How so? If my government is doing illegal things, or just things that I don't agree with behind closed doors, should I just accept that there's nothing that I can do to change that? Should these things be ignored because to bring these things to light would 'de-stabilize the international environment' and cause hardships to businesses?I'm also curious as to how the release of these cables is going to 'take down the establishment.' Do you fear that the US government will crumble, sending America into a period of anarchy all due to WikiLeaks? If not, then do you think that any reasonably intelligent person would believe that that would happen? Do you classify Wikileaks as 'not reasonably intelligent?' If not, then why?
> Indeed the fact that these companies have now been attacked by the associates of
> those they chose not to support means that they made the right decision.
For starters, Anonymous could be best described as a 'Stand Alone Complex' as has been pointed out here and on Reddit a couple of times. It's a loosely coupled group of people that is ever changing as people join/depart from it based on whether they 'believe in the cause' or 'get bored' or whatever. Censorship on the web by 'the establishment' really gets Anonymous riled up (see Scientology trying to get the Tom Cruise video pulled from the web). To say that Anonymous is an 'associate' of Wikileaks is about as close to the truth as saying that Osama Bin Laden is an 'associate' of the American public just because they share the believe that the US Army should not be in Iraq.That point aside, these companies chose to drop support for Wikileaks because they associated 'dropping Wikileaks' with 'zero risk' and 'keeping Wikileaks' with 'high risk.' That risk-assessment is no longer valid due to these attacks. Whether 'dropping Wikileaks' is still lower risk than keeping them is debatable, but it is no longer 'zero risk.' There are companies that only understand financial incentives. If you want them to pay attention to you, you need to affect their bottom line. What I gather from you post is that when a company becomes a pillar of commerce like these credit card processors have, then we can no longer morally affect their bottom line due to the effects that will have on other businesses. The problem with these belief is that you are effectively stating that these companies are 'untouchable' and a stone's throw away from 'too big to fail.'
> Why would they want to bolster groups that will turn and attack them?
Not that DDoS is necessarily the way to go, but I doubt that there would be any other way to get credit card companies to even give you the time of day once they have deemed that you are 'useless' to them. Do you have an alternate method of making the credit card companies stand up and listen to you once they've decided that you are to be ignored? > Taking a capitalist view basically Wikileaks supports believe that the rest
> of us should be screwed over so they can make their point. It's not civilised
> it's brutish anarchism.
No offense, but human civilization/society is a huge object that has a large amount of momentum and doesn't turn on a dime. This is why most large changes come with a lot of violence and disruption.Using your logic, Rosa Parks was a brutish anarchist because she believed that 'white people' should be 'screwed over' and prevented from having a seat at the front of the bus in order for her to make her point. The best course of action would be to disrupt no one. Maybe if Rosa Parks had just lodged a written complaint with the local board of commerce, white racists would have non-violently accepted that black people are their equals?
1. Financial services will re-evaluate the risks of this kind of attack vs. the cost of assigning more resources to guard against it.
2. Governments will finally start taking IT security seriously.
The latter is the more interesting, because while banks are generally reasonably clued up about balancing risks and will simply adjust their current practices, elected representatives who aren't technically inclined will probably be discolouring their underwear over the fall-out if the bad guys really tried to do some damage, given that it is this easy for a few upset people to cripple the world's payment systems.
I suspect that as a reuslt, we can look forward to increasingly draconian penalties being introduced for this sort of action in most jurisdictions, the end of on-line anonymity as it has been known, and ruthless throttling/disconnection of entire ISPs/countries that don't play ball with either of the above. If you thought government reactions to copyright infringement were heavy-handed, I imagine they will look like a nun comforting a child compared to what is coming next.
The sad thing is that better security, robustness, user authentication, etc. should have been built into the Internet by default for years, but the same "Wild West" evolution that was so successful in the early days has also been a poor driver of consolidation now that the Internet isn't just a toy for the military types and the universities any more. Maybe the Powers That Be will finally start taking serious advice about IT from people who know what they're talking about and collectively give the issues the attention they deserve. (I won't hold my breath, though; this could all end in tears, with a mess of ill-informed and poorly-implemented measures that cause all kinds of additional dangers to innocent people without actually fixing the real problem.)
The problem is that you just can't secure a whole infrastructure overnight and that security is very hard.
1. Declaratively the governments are indeed taking IT security seriously. Thus many guidelines, laws and other formal documents regarding IT security have been accepted. Unfortunately many of these are internally inconsistent or in conflict with others. The net result is that in the name of "security" the governmental IT systems are unnecessarily complicated and expensive.
2. In practice - prescribed security measures are mostly not enforced due to many reasons (eg.: The measures are so strict and rigid that enforcing them would prohibit various legitimate users from actually doing their work; The people in charge of implementation and administration of these systems are plain incompetent and/or disinterested).
3. Securing everything that is currently deemed necessary to the extent prescribed by relevant law will turn out to be prohibitively expensive due to various logistic problems (who will implement necessary auditing systems for legacy systems that nobody udnerstands and there are no funds to replace, where will you store all the auditing information, where will you get competent engineers that actually understand the infrastructure and are willing to work proactively to secure them - for a laughable wage?,...).
So - as a matter of fact - I have to state that governments don't really take IT security seriously. They don't understand the issues and they don't even care. They care for scapegoats and thats it.
Disclaimer: Most of my work is on government related IT projects/systems.
Yes the government wants to cover its ass first and foremost.
But that doesn't mean they don't take IT seriously, they just don't understand it to the point they cannot select people to work with that understand it correctly.
disclaimer: I've designed COMSEC systems
Actually, you can never completely defend against every possible attack. Any finite limit can be exceeded. As long as an attacker can use up some sort of finite resource on your box or network, you're toast.
SYN floods don't happen anymore because SYN cookies make the size of your TCP half-open connection table infinitely large. So no DoS anymore. But other things are not that easy to fix; you can prevent 1 IP from opening a million slow connections to your server and filling up your state table and running your web server out of fds. But you can't prevent a million people from all opening up one connection without blocking legitimate users.
DoS is very hard to defend against. I think in this case, there is probably something easy to fix (get rid of those Windows 95-based routers and app servers), but in the general case, there is nothing that can be done.
I work for a major DDoS mitigation equipment company and we see SYN floods all the time.
And you CAN block one million users from all opening up one connection. Our software/hardware makes this happen. There are MANY MANY ways that DDoS can be dealt with; the biggest hurdle in many cases is convincing a customer that they might be next. Until then, they often don't see the need to spend the money on sufficient capacity or properly test their system against the range of "probable" attack vectors.
That's likely what you're seeing here.
It /is/ true that attacks are becoming more sophisticated and targeting applications rather than just pure network resources (e.g. b/w). A big part of our efforts are trying to abstract away the potential attack vectors common to several application stacks rather than developing solutions for each one at a time.
P.S. Paypal seems to work fine for me right now.
During the Olympics in Korea, which Arbor ran DDoS protection for, attackers set up web pages that simply directed hundreds of thousands of computers at URLs on the MSNBC sites. How are you going to filter against that? If you have a botnet, you can saturate a target with totally legitimate traffic.
You can talk all you want about anomaly detection and attack characterization, but if your attacker has a botnet that generates totally legitimate traffic patterns, you have a very hard problem to solve. It isn't intractable, but probably will require code changes to your application to address.
A lot of anti-DDoS gear that gets sold to enterprises is snake oil. Most companies aren't in a position to filter their own traffic.
The problem of distinguishing between legitimate traffic and attack traffic gets harder when the attack starts to look more like legitimate traffic. It doesn't get impossible.
You can have a more effective attack if you have a LOT of machines you can use to generate legitimate requests. Of course, after a short while, it's going to be possible to determine which of those hosts are part of the botnet because you can build a history of their requests over time.
So it's not an impossible problem to solve; just a hard one. Most enterprises don't really want to pay the money necessary to protect the bulk of their enterprises.
I don't think I missed jrockway's point, but I do think you're missing mine: namely, that effective DDoS protection is expensive and time-consuming from a training standpoint relative to any individual company's exposure. That's why we don't see more anti-DDoS features in high-profile websites, not because it's ineffective.
Even so...we STILL see lots of packet-y type attacks. It's often overlooked but crafting effective attacks requires really good programming skills. Such skills are often unevenly distributed in script-kiddie kommunities.
My point is, any finite limit can be exceeded. In days of old, it was state tables and file descriptors. Now it's bandwidth. Filtering doesn't matter once the packet has traveled down your finite link to your packet filter. That bandwidth has been used, and denied service to a legitimate user that wanted his packet to go to your server.
Mostly, you're right, it comes down to luck. Attackers don't get the chance to do a daily dev / qa / release cycle. They write something, push it to a bunch of users who hate Amazon and Paypal today, and that's the end of it. If they wrote good code, the attack will be good. If they need to tweak something, they missed the opportunity.
That's what's saving everyone here -- luck.
Current best practice has been to use technologies like FLOWSPEC to get the traffic off the network much closer to the origin.
So about the SYN floods you see in real life, how do those work? Do routers not do SYN proxying for the servers behind them? Do SYN cookies not work? Are sequence numbers being forged? Is the link saturated? Something else?
FIREWALLs on the other hand, might use a SYN to make an entry in a table that's used to track connection state. That table might be overloaded by a SYN flood. Same thing applies to load balancers.
SYN cookies work just fine at the ENDPOINTs.
The very fact that this whole cablegate debacle even exists clearly demonstrates that parts of the US government do not.
PS: To put this into perspective, one of the guys I work with was there for 9/11. He sustained significant injury while several people in the room with him died. Yet, he is also willing to work in the building and most people in the building where not harmed.
So, if you are going to equate a single low impact release with “sucking” the go for it. But, I would point out unlike banks which often lose large numbers of SSN’s the government keeps the hole list for everyone and that has not gotten out. And (as my original post pointed out) sometimes when dealing with hard problems mitigation really is the best you can hope for.
And he's right the stuff that will come out of it probably will not be very encouraging.
So yes, it's already happening, and in the coming years the internet is bound to change profoundly.
On a meta level, and for improving my own communication skills, I'm a bit surprised that you are being upvoted while I got downvoted yesterday in the MasterCard thread for saying essentially the same. Anyone who answered me yesterday and disagreed with me care to tell me why? Did I not make my point clearly enough, or was it the form of the message?
Edit: link to previous post: http://news.ycombinator.com/item?id=1983858
If I were a betting man, I'd say we'll see many years of ill-informed and badly implemented draconian policy. I'd go further to say that it won't improve significantly until at least a couple more generations have walked the halls of power and true digital natives finally cast their votes in parliament.
If that generation has enough of these views hard-wired into their understanding, _now_ could be the high-water mark for understanding of the dangers and appropriate reactions.
A lot of issues are caused because the young don't get out and vote. They* are already under-represented because the old simply outnumber them. The fact that they don't vote as well makes it especially hard.
Rich.
* = not counting myself amongst the "young" any more ...
Edit: downvote me all you like, but you should read the post about what happens when you're busted by the feds (from the hacker crackdown): http://web.textfiles.com/hacking/agentsteal.txt
Many people -- WikiLeaks, in fact -- are protesting US action in Iraq. They are particularly upset about the "collateral damage" of civilians being caught up in the violence.
Yet here, those cheering for the DDoS attacks in support of WikiLeaks are just shrugging off the collateral damage that this attack is causing.
Addendum: the quick, reflex downvotes are really annoying. If you think I'm not contributing to the discussion, please at least take the time to explain why. It seems to me that there's a patter for these. I lose a few points immediately, but then as more thoughtful people actually take the time to think about it, the score climbs back up into positive territory. That suggests to me that the down-votes are just readers being petulant because I disagree with them.
I don't know if Assange goes around saying "anarchy for everyone!" and I don't care. I don't like the idea of vast swaths of government operating in secret. From the CIA, to the closed door congressional meetings.
Second, it's only money. In the scheme of things it's probably a net positive for the economy as alternatives are explored, supporting perhaps financial startups, security firms are employed, etc.
You (and lot's of others) are comparing that to leaks detailing loss of life. I don't get it. The moral compass on HN is weird.
So Wikileaks and Anon are not bullying people?
When it comes to infrastructure, the small guys can't always have backups. Do you have two power companies simultaneously supply your office? Two broadband connections? Yet I believe that someone maliciously cutting off my water or broadband to make a political point is as much in the wrong as someone cutting off my payment provider.
After this, the banks will be afraid of Anonymous, and they will do whatever it takes to stay off their radar... including turning down a lot of legitimate business. "Politically unconventional" organizations around the world are about to get the same arms-length treatment that adult sites have always gotten.
I'm frankly appalled at how many people here are actually defending MasterCard, Visa and PayPal. As if money and shareholder interests are all that matters.
There are also examples of companies that don't hand over their clients' information without court orders or give in to political pressure (for example XS4ALL here in the Netherlands) and you know: they are actually appreciated for it and very successful!
There are millions of jobs and people who depend on these companies everyday. It's not just about money and shareholder interests.
You can't reason backwards and say "well if they just hadn't done X everything would be fine" The parent's point is if they start reasoning like that, they'll just toss out anybody vaguely smelling suspicious (which I also think is the logical result, along with increased black lists of IP addresses)
Expect more like this. Eventually we'll get around to some issue that you can't feel so self-righteous about pursuing. Then the shoe will be on the other foot.
That's impossible as it is: too much work, AND, too much lose of income.
Bullying was pathetic in high school and is so much worse in the 'grown-up' world, especially when it affects so many normal people.
Closing people's accounts (not just Wikileaks) when they see fit, having no real recourse to try and get your money once that's happened etc.
Paypal have a reputation for being a bunch of thieves. I can't say I feel bad for them.
I've never been burned by them, I'm just going from the amount of people here that post a regular "Paypal froze my account" story.
Wikileaks has not been charged with any crime anywhere in the world, let alone been found guilty.
So why is it the US government is after them like the villain in a bad James Bond movie?
This isn't about wikileaks or what they have published - it's not about the content of cablegate, which is 250k documents which would have been made public in 5 - 10 years, none of them "top secret", all of them freely available to 3M+ army and government personnel.
This is about a free press, and in turn, it's about democracy. It's about who rules this world. Is it us, the people. Or is it big business which has bought our government with good money?
Let's be very clear about this - leaking classified information is a crime. Publishing leaked classified information, however, is protected by the 3rd Amendment. The US government therefore can't charge Wikileaks with a crime. So the US government has decided to go rogue and fight outside the legal framework - without laws, courts, or trials. THAT is the problem. Nothing else.
>Publishing leaked classified information, however, is protected by the 3rd Amendment.
First. The Third is "No Soldier shall, in time of peace be quartered in any house, without the consent of the Owner, nor in time of war, but in a manner to be prescribed by law.".
At a very minimum wikileaks is distributing copyrighted information without authorization. Technically they can be taken completely down via the DMCA.
Ultimately of course PayPal, Amazon, Mastercard and others don't want to do business with Wikileaks, or anon, or any similar "fuzzy" business. The business doesn't have to be illegal, they can just be a liability business and that's what they are -- only a lot of people spouting a lot of hot air are going to patronize your service because you cater to them, yet a lot of people will leave you because of it.
Nonetheless, the kids will get bored. GUARANTEED the governments of the world are going to introduce anti-DOS legislation that mandates an immediate cutoff of nodes that participate in DOS (and further a cutoff of networks that don't manage DOS attacks originating in their network). That is absolutely inevitable, and honestly is a very good thing.
anyone with authority who rallies against the Anon community would likely make themselves a target also.
What amount, if any, preparation can guard against a cyber mob-rule attack? It seems that unless a machine is unplugged from the network, you're up shit creek without a paddle.
I think we may have sacrificed a lot - eg. the ability of the net to process pre-Christmas payments, for the "gain" of providing the ability of some dick at DoD to tell us what Hillary's people think of various national dictators, or that Iraq was not 100% superbly executed. Yeah, big deal.
I don't believe Assange's arrest is a conspiracy. 4chan launching all this shit may just force the net to change in some very bad ways.
Now they're threatening to take down twitter (who don't need any help in doing that!) because they are percieved to be preventing 'wikileaks' from trending. Looks increasingly like a load of kids with a ddos hammer seeing enticing nails everywhere.
Being immoral in order to expose the immorality of others does nothing but muddy the waters. There are better ways of challenging these things while retaining your decency.
They have unlimited resources, they have expertise, and they've seen it coming. If Anonymous can take PayPal down, then they can take anyone down.
They don't, if they did you would not be reading this post.
sites will be up AND down simultaneously for different people. That's what happens when they're overloaded.
Just type https://www.paypal.com to go straight to the web page.