Cyberattack – November 2023
blender.org
blender.org
Its not that anyone "wanted" to hurt Blender per se. Its that the DDOS service / black hat group wants to publicly demonstrate themselves and advertise their services.
At least, that's my running theory why otherwise "innocent" projects (like Blender) get attacked like this. Anyone have any other theories why Blender could be targeted?
I haven't heard that Blender has made any real enemies. Neither is likely they'd be able to pay a lot of ransom (they're pretty well funded for a FOSS project, but not in the range that would make them the most attractive ransom target).
It is sufficient for a black market DDOS-as-a-service company to do this for marketing.
Sort of like Vader showing off the Death Star on Alderaan.
I’m so white-hat that I didn’t consider that interpretation.
Grand Moff Tarkin showing off the Death Star to Vader (and everyone else).
But yes, I get your point, even if you misremembered the movie slightly :-). Episode 4 was very intriguing because Grand Moff Tarkin (and the Emperor) are the only two people in Episode4/5/6 that Vader listens to.
I know that there's plenty of Disney spinoffs at this point, but more spinoffs that analyze Grand Moff Tarkin would be a good thing.
In 99% of cases, a DDoS is much less concerning than most other kinds of attacks.
Especially since the Blender website being down has very limited effects on users who already have the software, or are getting it from their operating system's distribution channel.
If you cannot get to your stuff, or you stuff is harder to get to, then there has been a form of compromise in your service. Is it sexy like wannacry or technically advanced? No. But like most things IT, most of the time it is not.
The headline allows for both possibilities. See the example I posted in a sibling post: A headline of "terrorists strike railway station" would make most people imagine a bloodbath with dozens dead, while still being accurate if all that happened was that some ecoanarchists set a trash can on fire and forced an evacuation.
Step one, create DDoS mitigation service.
Step two attack random high traffic sites with advertising and covert DDoS attacks.
Profit?
> Jha and White co-founded a company called ProTraf Solutions, which provided anti-DDoS services to Minecraft servers. Nothing wrong with that, of course. But in order to create new customers, the pair started targeting websites with DDoS attacks and then either tried to extort money to call off the attacks or offered services which they claimed could defend the sites.
many experienced that heavy (IP changing) bot called something like "thesis test" this month...