4 ms·
extortionists. There's a growing band of pirates (the web kind) who hold sites to ransom via their massive botnets, in exchange for payment -- 'protection mone
by imajes 15y ago
extortionists.
There's a growing band of pirates (the web kind) who hold sites to ransom via their massive botnets, in exchange for payment -- 'protection money'.
- pavel_lishin 15y agoBut why Github? Wouldn't a less tech-savvy business be much more likely to cave in, and have a better cash flow? (e.g., porn and gambling sites?)
- wahnfrieden 15y agoUptime is very valuable to github. For example, I can't easily deploy to my site when githubs down. I suspect many others have bought into its availability too.
- cdelsolar 15y agoI had a very slow deploy earlier this week; if it had gotten canceled in the middle of it that would have been pretty bad. Maybe the deployment script should copy the repo head to one of my own servers and continue from there? What do people do?
- thibaut_barrere 15y agoRandom thoughts but: - Github are obviously very successful and may have money - their clients are reacting quickly on twitter so attackers might think they have an edge in terms of pressuring
- reinhardt 15y agoNot in that line of business but I'd expect any porn and gambling site with half-decent cash flow to be quite tech-savvy when it comes to securing it from all the DDOSers, fraudsters and other hostile entities they have to deal with daily.
- ketralnis 15y agoSure, which is why you attack them too.
- baddox 15y agoDo any of these extortionists have a reputation for actually stopping the attack once they get paid? I certainly wouldn't trust some random group that's currently DDOSing me enough to pay them.
- Jach 15y agoMy thoughts exactly. I'm inclined to believe with another commenter that they just picked GitHub as testing grounds. Especially depending on the sum of money demanded, I can imagine it being cheaper to either spin up more servers to handle the load, or hire a DDoS specialist to help you out, or make it someone else's problem by moving behind a thirdparty CDN.
- cgag 15y agoWouldn't it be in their favor to stop? No one would pay them if they had a reputation of continuing the attack after being paid. It also seems like it'd be a waste of their resources to keep going.
- Tobu 15y agoUnless they changed their mind and decide since you paid so easily, you might have a little more. There's no reputation to maintain in this activity.
- pavel_lishin 15y agoFool me once, shame on you. Why would they pay out again, if the attackers have made it clear that there's no reward for paying?
- spitfire 15y agoWould you want to have an identifiable reputation if you're DDoSing people? Your logic is sound - why trust a criminal? But it's not like there's a better business bureau from organized crime.
- Monkeyget 15y agoIt reminds me of the Vikings. They would plunder throughout Europe including modern day France. It got so bad that the coasts ended up practically abandoned. The rich and weak Frank empire, a bad combination, resorted to the disastrous policy of bribing the invaders to leave. It only served to mark the Franks as a good target and emptying the treasury. The Vikings would leave, plunder some other place and come back for more. In the end, the Franks ended up giving part of their land on the coast : Normandy. This served to settle the invaders down while making THEM have to protect their newly acquired territory against other vikings.
- blibble 15y agoor just bored kiddies, happens quite a lot