LulzSec: Why we do what we do
pastebin.com
pastebin.com
For the rest of us, it's pretty tedious.
There's another situation that fits the general parameters of what they describe. Almost no one is protected against it. Being a gunshot victim.
At least in the US, pretty much anyone can get their hands on a handgun either legally or illegally. Almost anyone can use one with a bare minimum of instruction. And almost no one is protected - if you pick a name out of a hat of all america, pretty much any possible outcome will be dead easy to track down, stalk, find the right opportunity and shoot dead. And a vanishingly small numbers of shooters make an announcement about the whole incident on the Internet.
But, all that said, if you go around shooting people for no real reason and bragging about it you're assuredly a psycopathic asshole.
Mind you, these processes aren't perfect. Things fall through the cracks, and effectively nothing will keep out a significantly determined attacker, but that doesn't mean you shouldn't follow well-established security methodologies. In the vast majority of cases, they hold up well.
Edit: I want to note that, in all likelihood, no amount of secure development and review would've kept people out of Sony -- there were just too many people that wanted to attack them, and too large an attack surface. It could've diminished the number of successful attacks, and it could have reduced the amount of data stolen, but in all likelihood attackers would've still made it in to some extent. However, things like the Brink attack might have been stopped entirely, since they didn't seem to be terribly determined to get in.
Lulzsec isn't even calling their shots. They're casting around for security issues widely without rhyme or reason. You're supposed to lock your front door, but if you go through a neighborhood and try everyone's front doors you'll always find one that's left open. Now imagine your neighborhood is the world. It's literally impossible that you'll ever run out of victims.
The truth is that computer security isn't shit because all the noobs out there that don't have a CSO, don't hire matasano, don't have sufficient change review policies, don't have a 24x7 ops team with live instrumentaion and don't have DDOS protection are id1ots. Sure, any one of them can be pointed and laughed at and said they're losers. But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug. And also a failure of our own security industry for selling ineffective, labor intensive solutions and pricing most of the rest beyond the reach of most potential customers.
And I dare say that Lulzsec isn't going to have much of an impact on any of that.
I find the first assertion idiotic and the last begging the question.
patio11 made a similar point about armed robbery, I mean seriously, what is wrong with you?
It's fucking stupid. If someone gets shot a lot of cops will turn up within minutes. They'll devote a lot of manpower to it. In some of your states the perpetrator will be executed.
There's a response. There's a massive immediate manhunt. Will people stop idiotically claiming that a serious, sickening crime is anything like hacking someone's server please?
And to get back on topic, if someone gets hacked it's brushed under the carpet if possible if it's even noticed. People aren't even checking if it's happened.
Where's the abnormal activity alert built into windows or linux? Or Apache or IIS?
And that is why this stuff is easily avoidable. Much like a lock on your door isn't going to stop a determined thief from breaking in, simple protections won't stop a determined attacker from breaking into your site. But in an age where adding CSRF tokens is simple, SQLi protection is nearly guaranteed by using an ORM and/or parameterized queries, XSS is largely mitigated by filtering on templates, etc, it's not that hard to remove the low-hanging fruit from your site. Even with these, you will still have vulnerabilities, but a drive-by attack like those executed by Lulzsec will not work.
> But taken in aggregate, it's not all their 30,000,000 individual failures, it's a failure of the computer industry that has long pushed speed and ease over safety and continues to sweep the current security environment under the rug.
It's easier than ever to write secure code without even trying. If you follow, say, a basic Django tutorial, you won't be vulnerable to XSS and SQLi unless you color outside the lines. Add in CSRF middleware, and suddenly CSRF attacks (and a large amount of reflected XSS with them) are mitigated. These are not difficult things, and the software industry is getting better and better about making secure coding the rule, not the exception.
this is the epitome of capitalism. your comment was spot on until the edit.
last sony thing I paid was a cassette walkman. then after betamax, minidisc, memory stick, etc, etc, etc... you have to be a sucker to support them. sad but true.
anyway, by not consuming from a company with low market ethic, I also avoided a company with bad network security ethic. they would be hacked? could be. but if nintendo is hacked, I can at least just change my password not my name and credit card.
for similar reasons I also avoid apple, j&j, and a few others.
Sure in your case, of an informed technology enthusiast. The average customer, however, is not aware of shoddy security practices endangering his data. Which novadays means his personal finances, too. Also, the average decision maker at the companies in question is not aware of your protest, either; it takes press attention to make him aware.
This is heavy information disparity; the market self-regulation cannot happen in such case. The customers simply cannot make informed (!) choices, nor put pressure on the website operators. Curiously enough, many of the decisionmakers at the companies may also be unaware of seriousness of the risks just as well.
LulzSec steps in. By grabbing headlines they aim to inform the widest audience of what goes on, and force press to take on the hard subject. Let's hope the press does the job well, so capitalism can do its at last.
about attention to my little protest, I assure you, they pay more attention to sales volume than media noise.
Unlike gunshot wound, where a person lands in a hospital, or morgue, or goes missing, data can be, and indeed is, copied quietly. Of gunshots, people are informed most of the time; of security breaches, barely ever. Cops investigate most gunshots, but do they know of most security breaches?
The big hope is the press will at last start paying attention to (in)security of our data. Thus the headline-grabbing tactics.
The other half is that corporations don't shoot people, people shoot people. And to the wit, people don't store 200.000 bank accounts on a web server, corporations do. You can -- and should -- hold corporations to a somewhat higher standard when it comes to affording decent protection for customers. It's no coincidence LulzSec weren't after granny-loves-her-cat blogs, but after commercial services.
They only bring up all the silent malicious hacking that happens as an argument that we shouldn't care so much about what they're doing.
But! On today's internet, consumer needs certain services on-line 24/7, and is hit hard if they are down. One's stock quotes, bank account, credit/debit card processor, ticket booth, office suite, and last but clearly not least, the daily fix of WoW. Hell, a lot of people can't even read or write any email without the WWW interface.
Being vulnerable to DDoS is just as unexcusable for some business internet services as being vulnerable to SQL injection; only diffirence is the protection applies at different layer.
Most of the targets in this case are not critical services like bank accounts or ticket booths -- those companies DO spend the extra money on protection (more servers, in this case).
Let me ask; do you run a web business? Any website? Is it vulnurable to DDoS?
They're right too. I'm not saying what they're doing is good, or even necessary like some vigilante stories portray, but they're right that we should be devoting just as much attention and effort denouncing and trying to catch the doubtless countless people, who like they, tried some simple attacks and discovered that most security systems are almost trivial to breach, and are taking real advantage of it, not just putting it on the internet and watching the lulz unfold.
Online security is poor for the same reason airport security is. Good security would take enough time and money to make the whole thing economically unviable.
Airport security in the US is poor because the policies are a series of politically convenient patches applied to a broken system. In Israel, where the threat of terrorism is far greater, their airport security is both much more effective and much less invasive. Why? Because it was designed to work, from the ground up. They don't hire legions of idiots at minimum wage or close to it to do their security. They hire ex-military and ex-mossad people to surveil travellers. They have highly-trained people who know how to spot potential terrorists, and multiple layers of security (usually just someone saying hi and engaging in light chatter) that catch the vast majority of problem people before they get anywhere close to an airplane.
The US system is expensive, invasive, and ineffective. That doesn't mean airport security in general is doomed to fail, it means the US is incompetent at it.
What I don't agree with is their use of DDoS attacks against sites like cia.gov.
DDoS attacks are pointless. All they point out is how a site has limited resources for dealing with so many concurrent connections.
Sites should deploy onto an infrastructure they feel is adequate to deal with the expected load plus some additional room for growth and spikes.
I'm sure the cia.gov doesn't get hit very hard on a normal day so they didn't go crazy on infrastructure which is understandable. A DDoS proves nothing and prevents people from accessing data.
If you're going to hack, please wear a white or grey hat.
I'm not justifying the attacks and I agree that they are the wrong way to go about this business, but it would be naive to suggest that the DDoS attacks are a minor inconvenience.
I pay US taxes and I don't want the cia.gov site to be on the same type of hardware as say Google just to be DDoS "proof".
They shouldn't be connected with a 33.6 modem but to ask all sites to upgrade everything to prevent DDoS is insane.
Who could afford to start a web site if they had to lay out all of that cost?
At this point, he seems like a false positive based on his recent comments. It's a pity that there's no real procedure for being unhellbanned, even if the user discovers that they are, other than starting a new account.
But a DDOS attack is, at heart, nothing more than a brute-force attack - flooding a single website / IP with so much traffic that it can't respond. No matter how much fancy technology you add, if you have a 100Mbps link, and someone's sending 1Gbps of data at you, you're out of luck.
And, yes, I realize that there are companies that specialize in protecting against DDOS attacks - generally, they move content to a CDN and use some intelligent filtering to drop packets (i.e. people that request multiple times in succession, etc.). But this still is reliant on the fact that their connections are large enough that they can actually process all this data.
If a large country decided to use all it's available Internet bandwidth to DDOS, there's not much anyone can do about it.
In short: DDOS attacks will likely always be around - they might require higher bandwidth (country-scale or thereabouts), but it's not "fixable".
1. Per-device reputation removes the concept of anonymity. If I can look up the "reputation" of the device that sent me a packet, I can track it perfectly too.
2. Authenticating every device (beside the practical challenges) is very inconvenient. What happens if I move countries? Buy a new phone? Or a new network card?
And there's more issues that I won't list :)
Problems aside, I agree with the statement: "the underlying assumption [...] that anyone anywhere on the network should be able to drop an unlimited amount of data onto the link headed to me [...] needs to be justified".
I think the most practical solution to this would simply be forcing ISPs (through legislation would be best) to look a little closer at their traffic. If I'm running an ISP, and I see a computer making 100 requests/second to a single website for more than a minute, I'm immediately thinking "DDOS". Yes, there's privacy issues, but most ISPs already do some sort of traffic shaping (see: Sandvine), so it shouldn't be that much of a stretch.
Arguments welcome ;-)
If you're adding the signatures, you presumably need to spend CPU time to authenticate it, and bandwidth to send the data, plus the actual content. Why not just have the middle-man soak up the extra requests, cache the data, and fan it out that way?
Some protocols are immune to DDOS: like BitTorrent and Freenet. HTTP wasn't designed to deal with DDOS.
This point was raised a few months back in relation to PayPal and Visa getting DDoSed because of Wikileaks: DDoS attacks could be the new digital age version of a protest, a disruption of normal activities to draw attention to a particular cause (whether or not that cause is worthy is secondary). In that sense, DDoS attacks are very relevant.
This is a common complaint among blackhats: they see whitehats as being in the game for the money and taking advantage of the unenlightened as much as they [the blackhats] themselves do.
I don't really know what to make of it.
Whitehats are only taking advantage of the unenlightened as much as a mechanic is taking advantage of someone who doesn't know anything about cars - they provide experience and expertise and offer a service for a high price - at least, a higher price than if the client knew how to fix it themselves.
How do I know that my jeweler isn't gouging me on my fiancee's 2 caret diamond ring? Because I know that there's a fixed quantity of available diamonds, and almost everyone would buy them at a given price. And if I need to verify that, I can go to the jeweler down the street. Everyone would buy security consulting at a given price, but that quantity is even more limited than 2 caret diamonds.
Why is my house worth a third less than what it was 3 years ago? Because there's at least a third fewer potential buyers than there was when I bought it. I wasn't "price gouged" or fooled in either instance.
Whitehats specialize in security and it frees up our time to specialize and produce excess value for others. It's not a conspiracy. If Steve Jobs and LeBron James aren't tricking people into giving them money, neither are whitehats. It's the free market and, believe it or not, it produces wealth.
Meanwhile...
http://en.wikipedia.org/wiki/Chemical_vapor_deposition_of_di...
Your jeweler is always gouging you when you buy diamonds.
Preying on the weak for profit
They both kind of have a sociopath sound to them
A society driven by preying on the weak for profit is far more distressing.
I don't think it's as visible to us as it used to be, but I think it's still very much there.
The person who is weak in this case is a customer. This customer is lacking in skills related to computer security. The person who is preying on the weak is someone who invested time into learning about the skills that the customer does not know. Let's say this customer was a farmer. He is using the money he too got from preying on the weak non-farmers to purchase protection.
In the case of preying on the weak for fun we also have some things being hidden behind the words. For example, fun in this case means stealing identities, trying to ruin relationships, and sending dildos to innocents.
It's cool though for the author because by having things written in these terms its easy for people to talk past each other. They don't realize the context in which he has placed the words in the article. When other people see the terms its easy to think that maybe "preying on the weak for profit" is referring to blackhats instead of capitalism.
Another thing worth pointing out is that the person who is volunteering to give away the information for free is actually someone who also put in a lot of time to learn all the things that the customer didn't know. So when he says "I could teach it to him quickly" he is really saying "I will provide the same service in exchange for you're weekend." The thing is that when these two "companies" compete only the one charging money is going to stay afloat. So the dildo sending altruist who wants fun to be the basis of society goes back to sending dildos while the guy who charged the money actually does the job.
In economics, the invisible hand, also known as invisible hand of the market, is the term economists use to describe the self-regulating nature of the marketplace. This is a metaphor first coined by the economist Adam Smith in The Theory of Moral Sentiments... For Smith, the invisible hand was created by the conjunction of the forces of self-interest, competition, and supply and demand, which he noted as being capable of allocating resources in society.
Do car mechanics pray on weak for profit because not everyone learned how to fix their car? They trust mechanics because they devoted many years of their life at becoming good at what they do. Does that make them sociopaths? logic fail.
You could also say that white hat hackers provide a service of security for the benefit of those that spend their time creating other things.
Mayhap that time has arrived.
It enables people who would rather be disconnected to disconnect themselves, and gives sociopaths the ability to do far more.
The internet doesn't create people without empathy, it reveals that deep down, a lot of humanity didn't have it to begin with. The way society is starting to structure itself, though, lets that shine through more clearly.
A lot? I doubt LulzSec is more than five people. For every pathological script-kiddie there are ten Free Software hackers. The Internet has revealed new ways for people to be destructive, but it has also revealed more ways that they can be constructive.
Compare:
I doubt society was ever much more virtuous than it is today, but we do hear about the problems more. There is the orthogonal and much more serious issue that many more people today feel unfulfilled in their lives than they did before, but I can't even begin to address that -- read Infinite Jest by David Foster Wallace if that interests or concerns you.
a person, as a psychopathic personality, whose behavior is antisocial and who lacks a sense of moral responsibility or social conscience.
This happens far more often than people realise.
That's a damn shame.
What seemed most admirable about Anonymous is that as much as they were also in it for lulz and pure chaos, underneath there seemed to be a kind of idealism. Idealism is seductive, nihilism is off-putting.
When LuLzSec state that they don't care, and don't even care if they get arrested, that's definitely nihilistic and kind of sad.
Certainly they too in their juvenile ways were close to making a good point. A point about shocking incompetence when handling and storing sensitive customer data. A point about unethical behavior in government. And I believe them when they say they have stuff that they've chosen not to release. So they are not in fact true sociopaths or true nihilists. I guess that makes it even sadder when they say they don't care about anything but lulz.
It seemed like there was idealism lurking because there was!
http://en.wikipedia.org/wiki/Its_a_Good_Life_(The_Twilight_Z...
That episode also made it into the Twilight Zone movie directed by John Landis.
See you next Wednesday!
At least not yet, anyway.
For Anonymous, they're driven by strong moral convictions in their attacks these days (e.g. look at this puppy killer, let's fuck him up). The wayward person on the internet is of no interest to them. I've had my info posted on 4chan in full - address, phone number, email, facebook, screen names for other things, etc, with no lasting effects. Got spammed a bit, had some strange things arrive in the mail, but nothing malicious. They'll only be mean if they think you deserve it.
LulzSec is out there with a different purpose - they want publicity. The ddos attack they just ran wasn't to strategically take out services, it was to gain publicity by temporarily taking out unimportant but socially obvious targets. The CIA website was the public facing one, the only purpose it served was to be a PR job for the CIA. Smearing their PR site gets people looking. Smearing some random guy on the internet does not.
Basically, you're not important enough to warrant attention, nor am I, and nor are most people.
[Edit: by "good plan" I mean that their plan had a good chance of success, not that it was beneficial. That part is still up for debate.]
Their plan was not good, insofar as it caused pain for a great many people. What they did was not okay, and should not be lauded as a positive thing for the Internet at large.
The problem is that their antics are even being considered as anything other than the terroristic (in the real sense of the word, not the post 9/11 hyped up nonmeaning it tends to carry today) acts that they are.
If someone broke into a hospital and flung all of the patient records out onto the street, we wouldn't be having this discussion; they'd absolutely be considered criminals. So what if the glass they broke to get into the hospital wasn't shatter-proof? Sure, the hospital security would be improved, but there are a great many ways to go about fixing the problem without compromising the privacy if hundreds of thousands of people.
None of them have managed it.
I'm glad they didn't -- this way I can still have some privacy. cracking tools are becoming more sophisticated
IMHO, it's easier to break into someone's home than into someone's server.The result more predictable too, as you can find tools that can crack open doors, windows, anything. And if all else fails, you can just watch the house until somebody makes an error, like leaving the window open by themselves (although experts don't have to do this).
Real security can only be achieved through serious investments into state of the art alarms, safe-deposit boxes and by being a paranoid.
Another way to do it would be to plant GPS devices in each and every human and track each movement into a centralized database, while good thieves will find ways to block that signal anyway; and that's how all of the proposals for a more "secure" Internet sounds to me - basically punishing honest citizens in the name of security.
Do you really think they're industry workers? I'd peg most of them as high school kids. Probably with the occasional creepy thirty-something thrown in for good measure.
This is not realistic, however.
Do they really need a manifesto?
I'd guess mid-thirties for these guys, at least for whomever is putting out their twitter updates. This is someone who is basically immune to white-knighting and is a truly hard-core realist. It takes quite a while for someone reasonably intelligent to become that cynical, and then a while longer for them to act on it.
Anyway, I'm a fan of these guys. While I wouldn't do what they are doing myself, I certainly understand the mindset. I'm not quite sure I understand the arguments against what they're doing. The knee-jerk reactions of wanting to call them wrong frequently seem more immature to me than their recent campaigns. The real world is messy, and LulzSec's work is a valid reflection of that.
As far as the comparisons to sociopathic thinking, that's just ignorant. Sociopaths generally don't care about anyone but themselves and that's obviously not the case here. A sociopath would never release any of this data, and would simply use it for their own advantage, regardless of who was harmed.
LulzSec is gleaning entertainment here from the unwashed masses to be sure, but they aren't out there enslaving people with debt, indoctrinating them with religion, shooting them for protesting, putting them in cages for drug offenses, etc. All of which is completely legal, and in my opinion, far more sociopathic than releasing some bit personal data or playing a few practical jokes on people.
To me, the important thing is that LulzSec says that it derives pleasure from causing harm to people -- like the people who used to add poison to bottles of Tylenol, package the Tylenol back up again and place it back on the supermarket shelf. Although they could be saying that to cover up their real agenda, most writers (and especially most writers who have the tech skills needed to do what LulzSec has done) could not fake an admission of this sort as well as this text would have to have been faked.
Since it is natural human behavior to rationalize an antisocial motivation with a more socially-acceptable cover story, you would expect LulzSec to say things like, "We are doing this to bring public attention to how terrible security is." But if it is a rationalization, and it sure seems that way to me, surely it would be a mistake to focus on it and not the true motivations.
>they've also called out the internet on its generally abysmal attention span.
What an surprizing interpretation! I interpreted the parts about boredom as a continuation of the author's honestly disclosing his own motivations, not anything about internet users in general.
Neither of these are novel concepts: we've heard about abysmal internet security (FireSheep) and low attention spans (Nicholas Carr[0, 1] and Jonah Lehrer[2]) repeatedly over the last couple of years.
This release may seem profound to you, but LulzSec proposes no solutions to the problems they're creating. They're too nihilistic to put on white hats, and they deserve none of your praise as a result.
[0] http://www.theatlantic.com/magazine/archive/2008/07/is-googl...
[1] http://www.amazon.com/Shallows-What-Internet-Doing-Brains/dp...
[2] http://scienceblogs.com/cortex/2010/04/attention_and_intelli...
Do published books and articles in The Atlantic, Wired, and NYT not work for you? Those are a few of the news sites that have covered declining attention spans.
As for internet security--anyone who can do something about it already knew there was a problem. On the consumer end, what are users supposed to do? Add symbols to their passwords? That would delay GPU- or SSD-based brute force techniques by, what, 10 seconds?
Consumers are supposed to start using tools like KeePass or LastPass. Adding symbols to a simple 6-character password doesn't help. Adding symbols to a high-entropy 20-character password and never using a password twice makes you basically immune to this kind of thing.
The mainstream press has (so far) done a terrible job on password education. You see long lists of rules that nobody but a security professional or hacker would follow. It needs to be boiled down to something simple, like:
Use a password manager to assign unique, random 15 character passwords for all accounts, protecting them with a strong master password.
I put together a guide based on this concept here:
http://www.filterjoe.com/2011/04/14/passwords-guide-without-...
Unfortunately, this (and probably other) good password guide(s) get far less attention than the latest Sony exploit.
However I realised that I have become significantly more careful with password reuse now because there are no companies I absolutely trust to keep my information from leaking out.
LulzSec is just a group of teenagers (or someone alone). And they are really really funny. (This is not a compliment..)
If so, it should help reduce the impact of a broad, simultaneous attack across many sites from much more dangerous foes. I am not saying it is right, but it may be more effective than the legislation our congress comes up with to protect us, with fewer nasty side effects.
Some would say, "With your wallet!". But what happens when it's your wallet that gets stolen (electronically)?
What do you think?
[1] - if you know any examples, I'd be glad to hear them.
[2] - "Maybe this company is bad, but hell, the competition is 10 minutes further walking from me...", etc.
Still, it seems to have taken a lot of convincing of people and companies before it started to work.
Standing outside and watching my TV for 10 minutes? Please leave before I call the police.
Creepy guy with zoom-lensed camera in a van trying to peek through my bathroom curtains? I have already called the police.
While it isn't intuitive to us programmers and hacker types, when it comes to law and courts, intent matters more than action.
If you enter the unlocked door and write "HI YOU FORGOT TO LOCK YOUR DOOR" with lipstick on the bathroom window, you're alerting the owner to a bad security practice by giving them a good scare. It is A Good Thing, because you likely prevented them losing their stuff.
If you enter the unlocked door and start smashing and stealing stuff, you are technically still alerting the owner to a bad security pracice, but it is now A Bad Thing. By "being" the worst case, you only guaranteed something that was only likely to happen.
You probably have this opinion because you think it's the cool way to think, that these 'hackers' have a great function in society, but lets shift the analogy: do you think your government should be able to do the same? If there was a story about the US government doing this stuff, HN would go insane with tirades about how the government is out to get us.
But no, not if it's lulzsec, not if it's some cracker kid. It's the romantic fantasy of the teenage computer hacker, rebelling against the world and saving the day... I mean posting your nudes on facebook. Everyone here emphasizes with it so much that they're blind to the reality that it's just wrong to invade the privacy of others, under any circumstance.
The only exception I could think of would be to invade the privacy of an oppressive government.
In other words, for the lulz.
Yes it is. What the fuck is it? Nightowl would be more believable, and true.
Isn't that happening right now and by the people with pens?
That's all that's going to happen as kids like Assange and Lulzsec keep up with their criminal shenanigans. Governments are going to say, "Enough is enough!" and lock it down like in China.
If the NSA can partner with ISPs to scan internet traffic for phishing, viruses, etc ...the obvious next step is Lulzsec mentions or member mentions...in IRC, email, etc..
There is no such thing as hiding when attacking the internet, sooner or later you become the bitch
LulzSec on the other hand would probably be the ones breaking into the dentists office and drawing a penis on the patients face with black marker, just to wait for them to wake up and laugh at them.
:)