Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.
Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.
Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn't have a contingency plan).
If I'm a customer of Basecamp it looks to me like 37Signals is couching this as if they are the victims here, when really I am the victim. They're business isn't being disrupted... mine is! I pay them to abstract me away from the gory details... if I wanted to deal with that stuff I'd pay people to build it in house. My job as a customer isn't to sympathize with an outage, it's to move to a service that won't have one.
After turning in a term paper a day late a wise professor once told me "It doesn't matter if your excuse is true, it's still an excuse." The basic facts are the job didn't get done, and the person to blame is the person who didn't get the job done. Any modern web service that doesn't take the simple effort to sign up for cloudflare or their ilk to reduce attack surface doesn't deserve my money. (Admittedly a harsh perspective to take, but one many do take)
There is an entire movement in Sicily dedicated to highlighting and frequenting businesses that refuse to pay protection money, because in the past, paying was the norm.
Since that's not the kind of society I want to live in, I'd rather stand firm behind a company that refuses to deal with criminals. If companies give in as a matter of convenience to retain customers who turn a blind eye, that will only make the criminals stronger.
Now, certainly, there are measures they can take to mitigate the problem, but with all the things to do in a business, I suppose it's the kind of thing that might not be on the front burner until it happens. There are all kinds of bad, destructive things that could happen in the world, but if you spend all your time worrying about what could happen, you won't have a viable business. It's a tricky balancing act, and I'm willing to cut some slack to someone being targeted by criminals.
If 37Signals was a bitcoin exchange, aka a known target of DDOS attacks, the mood here would be drastically different... yet we've hit a tipping point where it seems everyone is equally at risk. DDOS attacks have become a sad cost of doing business on the internet, and just because you acknowledge that fact and try to prevent yourself from being a target doesn't mean you're capitulating to the criminal enterprise.
In fact, I don't see a better way of sticking it to the thugs than responding with "Hahaha, do your worst. We'd love to see if the money we're paying X COMPANY is worth it." And then you get to write a totally different blog post, one where you get to brag about your excellent foresight and how you have proven to your customers that the money they pay you buys a top-notch service.
That's not wise, it's just being an asshole. Reasonable people understand that things happen sometimes despite our best efforts. You can spend your life railing at people getting hit by metaphorical meteors, until you're hit by one yourself, or you can take a minute to work with people, be a little flexible, and win your time "investment" back many times over in return.
And Cloudflare is hardly a panacea for DDOS attacks.
I think most Basecamp users are savvy enough to understand that there's nobody to blame except for the extortionists responsible for this attacck.
Basecamp is actually the name of the company now, they aren't 37Signals anymore.
you're seriously comparing handing in a term paper late to being targeted for extortion by an international crime syndicate?
of course handing in a term paper late is unexcusable - it's just a fucking essay and there's no reason why it should be late because you probably had weeks to do it.
waking up to find your entire network infrastructure under siege (and anything ELSE you put up as a contingency, because it's on the internet, remember?) is not some shit you can be "no excuses" hardcore about because this is in the real world which is complex, unlike slacking on a paper, which is very simple.
reasonable people know this, which is if you read their TOS and other SLA agreements, this is all spelled out for you. nobody wants ot hear "NO EXCUSES!" from some guy paying $50/month while gigabits worth of malicious traffic is pounding at your door.
the truth is it's YOUR business, just like basecamp is THEIR business which they are QUITE obviously in the middle of running. if you're concerned your $50 saas product is not delivering the goods, it's on YOU to find an alternative.
The fact that this is on a Github Gist, as opposed to a static page (like on s3), suggests an audience that would understand those subtleties.
Straight up murder doesn't quite fit the situation here.
I prefer Github's recent response [0], clear and helpful but without the rhetoric.
[1] http://lesswrong.com/lw/e95/the_noncentral_fallacy_the_worst...
I blackmail my kids all the time... ("Wash your hands after using the bathroom or you will put 25 cents in this jar")
I was actually marveling at how precise the wording is in this piece. Curious how different these things can come across.
Calling someone "a criminal", meanwhile, degrades their status to that of a common mugger; someone in the lower class who needs to commit crime to survive, and who doesn't have the intelligence required to come up with a clever crime.
Hackers are generally aesthetes--we tend to value our intelligence, curiosity, etc. more than we value our moral fibre. We can appreciate stories like "A hacked into B to see if it was possible, and reported the vulnerability all responsible-like, but then they threw him in jail! How horrible!" because we think the positive-status from the display of intelligence makes it less likely, rather than more, that they were genuinely seeking to harm the people they hacked.
Because of this, I think we here are scared of being potentially associated with dumb, low-status, lower-class criminals more than we are of just being considered evil. People hire "evil, black-hat" hackers. Nobody hires a dumb hacker.
There is moral judgement involved with calling someone a criminal, and rightfully so. Taking what other people have created by force or extortion degrades society.
(and as a message to the DDOSer - they're likely to be reading this too and reminding them it is criminal and law enforcement is involved might make them reconsider the attack)
There's certainly a bit of knowing your audience here.
Burglary and murder happen too. No reason to hold your language back. Not even lawyers and prosecutors do, and they deal with those everyday.
For the company loosing millions or the Basecamp client whose unable to enter his account, that "those things happen" is not much of a response.
> This attack was launched together with a blackmail attempt that sought to have us pay to avoid this assault.
The original comment said that because DDoS could be illegal, is was different from openly carrying a fire-arm; that assumes that openly carrying a firearm isn’t illegal. It often is, outside of the US -- hence my response.
I would have appreciated you didn’t downvote me before you understood that.
> This is like a bunch of people blocking the front door and not letting you into your house. The contents of your house are safe -- you just can’t get in until they get out of the way.
It is. Only 4 words into the DDoS announcement and I rolled my eyes. I think that's a record for DHH.
I am not completely sure what this even means, but I am sure there is irony in there!