The internet is a shitty place.
The internet is a shitty place.
But if nobody except me is a big enough asshole to go round punching people in the face at random...
The disincentives that exist for your example and those that exist for actions similar to those taken by lulzsec are radically different.
The conclusion that people should walk around with full-face helmets is ridiculous because of the existing disincentives for assaulting someone. The conclusion that companies should secure their networks, not such an unreasonable expectation.
What we need are stronger punishments against digital vandalism and profit-oriented digital burglary alike, and more and stronger enforcement.
(not being sarcastic, in case anyone's wondering)
Securing networks is indeed a noble goal, but are we prepared to pay for the infrastructure?
The end result does not justify the means, and we all know how the story goes. More legislation to "prevent" hacking, and everyone suffers under the yoke of over-reaction.
Red teaming is a good thing.
Edit: to be clear, I agree there's no red-team value in DDOS. Though some have ascribed a "sit-in" utility to DDOS in certain circumstances (eg: Anonymous vs MasterCard after Wikileaks broke CableGate).
Sure, life would be grand if no one ever broke into computers. Security is expensive and not remotely fun. But there will always be someone out there motivated to break in. It's good that these guys are doing it publicly. The more common and nasty ones keep their mouths shut and use our machines to do bad things.
EDIT: Made the text a bit clearer.
EDIT: I suspect the only reason they didn't succeed getting to Blizzard is because WoW was down for Tuesday maintenance.
edit - # of accounts is 360k vs 12mil.
If you care about the integrity of your data, you damn well better care about your security.
If my account information or personal details are vulnerable to theft somehow, I want to know about that. But if a server I play games on can be taken down by DDoS, I'd happily go the rest of my life not knowing or caring so long as it doesn't actually happen. It contributes about as much as showing me that that bridge I like to drive over is susceptible to bombing.
Not that I play any of these games, mind.
My credit card number was used from Turkey this week. I have absolutely no idea which website was compromised. And I am pretty sure that whoever was compromised has no idea either.
Our conclusion was that Chase Manhattan had been compromised. That's kind of scary, really. They have to be spending serious money on security.
And yet you know that Chase and Citigroup are spending money on security in copious amounts. My heart breaks to think of all those guys getting paid not to know jack. (Or, just as probably, all those guys getting paid not to be able to shove jack through the corporate process.)
In my case the fact that the purchase was made from Turkey suggests that it was an online compromise.
Yes it's getting annoying, but they're doing it for the lulz. You can't say the same about all the other malicious hackers.
I agree with you it "helps" to care more about security and robustness. But I don't agree in the way. I have a dream that one day my website with minimum security won't be hacked for lulz and will be treated with respect. =)
I don't agree with their means (it's wrong, IMO, to mess with any machine you don't have permission to mess with) but their end goal aligns with mine: make the world more secure.
> I have a dream that one day my website with minimum security won't be hacked for lulz and will be treated with respect. =)
Would you rather have your site hacked for lulz, or would you rather someone go in and sell your customer's data on the black market?
There's an argument for whiteish-hat intrusions, but DDOSes must be intrinsically black-hat, right?
No. While I agree there's no red-team contribution in a DDOS, quite a few people regarded Anonymous DDOSes on Wikileaks detractors (MasterCard, et al) as the digital equivalent of a sit-in. That seems a bit of a stretch to me also, but certainly there's some application of DDOS that's not purely black-hat.
A more apt analogy might be: opening a poorly locked door to a business, then walking behind the counter and grabbing full print-outs of all their customers' information that was left lying there.
I hope you don't take the same lax approach to security when it's more than your personal documents at stake.