LulzSec Topples EVE Online, Minecraft, League of Legends and other Servers
gamepro.com
gamepro.com
The internet is a shitty place.
If you care about the integrity of your data, you damn well better care about your security.
My credit card number was used from Turkey this week. I have absolutely no idea which website was compromised. And I am pretty sure that whoever was compromised has no idea either.
Our conclusion was that Chase Manhattan had been compromised. That's kind of scary, really. They have to be spending serious money on security.
And yet you know that Chase and Citigroup are spending money on security in copious amounts. My heart breaks to think of all those guys getting paid not to know jack. (Or, just as probably, all those guys getting paid not to be able to shove jack through the corporate process.)
In my case the fact that the purchase was made from Turkey suggests that it was an online compromise.
If my account information or personal details are vulnerable to theft somehow, I want to know about that. But if a server I play games on can be taken down by DDoS, I'd happily go the rest of my life not knowing or caring so long as it doesn't actually happen. It contributes about as much as showing me that that bridge I like to drive over is susceptible to bombing.
Not that I play any of these games, mind.
Yes it's getting annoying, but they're doing it for the lulz. You can't say the same about all the other malicious hackers.
EDIT: I suspect the only reason they didn't succeed getting to Blizzard is because WoW was down for Tuesday maintenance.
edit - # of accounts is 360k vs 12mil.
I agree with you it "helps" to care more about security and robustness. But I don't agree in the way. I have a dream that one day my website with minimum security won't be hacked for lulz and will be treated with respect. =)
I don't agree with their means (it's wrong, IMO, to mess with any machine you don't have permission to mess with) but their end goal aligns with mine: make the world more secure.
> I have a dream that one day my website with minimum security won't be hacked for lulz and will be treated with respect. =)
Would you rather have your site hacked for lulz, or would you rather someone go in and sell your customer's data on the black market?
There's an argument for whiteish-hat intrusions, but DDOSes must be intrinsically black-hat, right?
No. While I agree there's no red-team contribution in a DDOS, quite a few people regarded Anonymous DDOSes on Wikileaks detractors (MasterCard, et al) as the digital equivalent of a sit-in. That seems a bit of a stretch to me also, but certainly there's some application of DDOS that's not purely black-hat.
A more apt analogy might be: opening a poorly locked door to a business, then walking behind the counter and grabbing full print-outs of all their customers' information that was left lying there.
I hope you don't take the same lax approach to security when it's more than your personal documents at stake.
But if nobody except me is a big enough asshole to go round punching people in the face at random...
The disincentives that exist for your example and those that exist for actions similar to those taken by lulzsec are radically different.
The conclusion that people should walk around with full-face helmets is ridiculous because of the existing disincentives for assaulting someone. The conclusion that companies should secure their networks, not such an unreasonable expectation.
Securing networks is indeed a noble goal, but are we prepared to pay for the infrastructure?
The end result does not justify the means, and we all know how the story goes. More legislation to "prevent" hacking, and everyone suffers under the yoke of over-reaction.
What we need are stronger punishments against digital vandalism and profit-oriented digital burglary alike, and more and stronger enforcement.
(not being sarcastic, in case anyone's wondering)
Red teaming is a good thing.
Edit: to be clear, I agree there's no red-team value in DDOS. Though some have ascribed a "sit-in" utility to DDOS in certain circumstances (eg: Anonymous vs MasterCard after Wikileaks broke CableGate).
Sure, life would be grand if no one ever broke into computers. Security is expensive and not remotely fun. But there will always be someone out there motivated to break in. It's good that these guys are doing it publicly. The more common and nasty ones keep their mouths shut and use our machines to do bad things.
EDIT: Made the text a bit clearer.
trying to hit every demographic :/
Because the title on the top of this site will get very unpopular in the next couple weeks.
Discuss secure coding techniques, perform security analysis on software (and closed-source services with bug bounty programs!), make sure your own projects/products are secure, and generally just keep security -- not just attacks -- in the limelight.
Can somebody give me a "worst case" scenario for a government crackdown on the internet?
What's to stop me from running tor? From VPNing out of the country myself? How would this alleged crackdown affect me?
And are you all new to the internet? Hacker groups like this have been around since...ever. I will admit that their publicity seems to have been waning in the last 5-6 years, but we're not really seeing anything new here. The only new thing about it is that this time it's happening on twitter.
This isn't a government cover-up. This isn't a conspiracy. It's one or several nerds doing what most nerds love to do: cause trouble. It's just that this time, it's happening on a much more public forum.
>the government making it illegal to run hacking tools like "tor"
Do you think that there is nothing illegal that happens on the internet now? How long was it illegal to export encryption? How many people actually cared?
>forcing your ISP to record any use of such and block you off the internet
The encryption standards that we all use are the same encryption standards that are recommended by the NSA. Unless my ISP knows something that the rest of the world doesn't, it's functionally impossible for them to see what I'm doing if I'm either using tor, or tunneling out of the country on the back of a VPN.
Tor was invented by the NSA, by the way, for exactly this purpose.
Look at what Iran/Egypt/etc have done to try and crack down on internet usage. Or even China. Look at how successful that has been.
(It has been a failure)
> How long was it illegal to export encryption? How many
> people actually cared?
The people that actually crossed borders to develop crypto software outside of the USA.edit: change to past tense
If the US Government were to bring it in as anti-terrorism laws, while some people wouldn't like it, it wouldn't cause riots on the streets and firefights between the army and the citizens.
Will the US try and do this? I doubt it. If they tried, would political opposition prevent them from getting it done? I think and hope so. But the point is that if it did happen, it wouldn't happen in the same way as Egypt, and so wouldn't face the same reaction. In Egypt, action preceded debate. In the US, if it ever happened, by that time the chance to prevent it would have been lost.
Actually, Paul Syverson, Roger Dingledine, and Nick Mathewson orginated Tor, and Dr Syverson did the original onion routing work at the Naval Research Lab.
https://www.torproject.org/about/corepeople.html.en
I don't recall seeing "NSA" anywhere on any their resumes, in their papers, etc.
Syverson has made it pretty clear Tor is not so good for serious security, eg, trying to evade nation-states. Evading nation-states is what PGP is for. Fundamentally, if you want a pizza, the pizza delivery guy has to know your address, no matter how many intermediate stops he makes. Also, have you used Tor? Speed is a major issue.
The group's agenda isn't entirely clear right now
Yes, it is, they're doing it because they find it funny.Specifically - information gained in the Bethesda http://pastebin.com/i5M0LB58 and whitehat http://pastebin.com/MQG0a130 raids has not been released.
edit to the downvoters: I'm not defending their actions, just putting myself in their frame of mind
The best example I can give is how my brother used to grief Counterstrike on TK-enabled servers - he didn't do this by killing his own teammates, or by cheating against the other team. Rather, he would lure his teammates into killing him often enough that they got auto-banned from the server; his rationale was that everyone was too freaking good at CS anyways, might as well make the game more interesting and difficult for himself, at least. :)
When you decide for yourself which game you're actually playing, sometimes the lulz are just too tasty to resist...
That said, DDoSing a bunch of game servers for games that are completely unrelated and haven't done anything in particular worthy of retaliation is moronic. There's no poetry there, just a bunch of children playing around with the 2011 equivalent of AOHell (and yes, I realize that most of them are probably to young to even know WTF I'm talking about).
They hack company after company in such a short time, are very vocal and cocky about it, but still manage to not make mistakes and get caught. "Too good to be true" rings a bell?
Maybe they're trying to lure people in somehow? I couldn't even guess what the goal is, but it's weird.
Their claim is to have taken on phone-in DRM that pissed off users -- to the point the users wished the servers to crash and burn. Pretty much similar reasoning to Sony hacks, if you ask me...
Beyond that, it's almost impossible to know their motivations.
Is the lulz from laughing with them or at them?
I just hope it wasn't code that I actually wrote that let them in. :) If I was betting, though, I would bet that it was a vulnerability in Adobe LiveCycle Data Services.
I admit, I was at work for the entire downtime so it didn't bother me, but I am pleased with their response to the situation. Hitting the big red button may be a drastic step in response to DDOS, but at least they were willing to take security seriously.
To break is not to build
meaning it is much easier to break something than to build it in the first place. And it holds so very true for virtually any networked app or service.It's no longer funny.
It's like the joke you told at a party that everybody laughed at. Then you told it 5 more times before you left the party.
Unfortunately, I don't see them stopping any time soon. Soo....
It's kinda like a destructive version of people who say "That's what she said".
The most ironic thing about all of this though is they are likely destroying the very feature (anonymity) that they are exploiting.
All this does is give ammo to the record companies that want tight restrictions on the internet. Once that happens, it's game over. They can't win that one.
Being a p.i.t.a is not cool. Throw the book at them.
So LulzSec decided to take down that site and what I assume were a bunch of other easy gaming targets.
It's not easy to back trace when you have to send in someone to do forensics on a computer.
"David Kaczynski had once admired and emulated his elder brother, but had later decided to leave the survivalist lifestyle behind.[74] He had received assurances from the FBI that he would remain anonymous and that his brother would not learn who had turned him in, but his identity was leaked to CBS News in early April 1996."
That, is the opposite of 'teh lulz.' :|
Notice that certain targets are avoided? What I mean by targets is that everything is low hanging fruit only..a sql injection here and sql injection there...nothing really highly skilled. Also targets missing from the list is heavy duty military and gov sites. For example, a low level FBI contractor was attacked not FBI itself, not CIA, non DoD,etc.
The conclusion I come up with is that LulzSec was infiltrated to get anonymous by government agents. After they get anonymous they might figure that they than have info on how to get wikileaks.
If he's talking about USGOV, the demographics of Congress, the Cabinet, and the Supreme Court are pretty clear.
(1) They also may or may not have formerly said "Ni!" Hacker News, like Camelot, can sometimes be a very silly place.