5 ms·
Obviously anyone can "take credit" for things like this, but if this[1] is true, then jesus. Edit: Since it's topical, I enjoy listening to Chuck Rossi in inte
by bombtrack 12y ago
Obviously anyone can "take credit" for things like this, but if this[1] is true, then jesus.
Edit: Since it's topical, I enjoy listening to Chuck Rossi in interviews or presentations.
Releng 2014 - Keynote 1: Chuck Rossi, Release Engineering, Facebook Inc. | Talks at Google [2]
[1] https://twitter.com/lizardmafia/status/559963134006292481 https://twitter.com/lizardmafia/status/559963134006292481
[2] http://youtu.be/Nffzkkdq7GM?t=4m39s http://youtu.be/Nffzkkdq7GM?t=4m39s
- danso 12y agoA few years ago, who would've guessed that Twitter would be the major service still standing during such a mass attack?
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- SEJeff 12y agoBefore they had Mesos, they wouldn't have.
- thrownaway2424 12y agoThey had to leave twitter up so they could have somewhere to post?
- Hexcles 12y agolol. Might simply because people see white whales too often and that's not a surprise.
- joshhagler 12y agoI am not familiar with Lizard Mafia, do they have a history of famous hacks?
- typon 12y agoThey hacked Malaysian Airlines website yesterday. The wiki page goes into more detail: http://en.wikipedia.org/wiki/Lizard_Squad http://en.wikipedia.org/wiki/Lizard_Squad
- shiftpgdn 12y agoThat was Cyber Caliphate, not Lizard Squad.
- bombtrack 12y agoMore DDoS than hacking, but yea. http://venturebeat.com/2014/12/30/fbi-confirms-lizard-squad-under-investigation-for-psn-xbox-live-attacks/ http://venturebeat.com/2014/12/30/fbi-confirms-lizard-squad-... http://krebsonsecurity.com/2015/01/another-lizard-arrested-lizard-lair-hacked/ http://krebsonsecurity.com/2015/01/another-lizard-arrested-l... http://www.bbc.co.uk/newsbeat/30306319 http://www.bbc.co.uk/newsbeat/30306319
- Untit1ed 12y agoObviously Tinder falls with Facebook, but HipChat's definitely still working for me...
- ykumar6 12y agoHipchat is down for me
- andyfleming 12y agoThe site is down. Not sure about the actual service.
- philip1209 12y agoThey report issues: http://status.hipchat.com/ http://status.hipchat.com/
- MasterScrat 12y agoWhat is the connection between Tinder and Facebook?
- jsmthrowaway 12y agoWhen you use Tinder, you are looking at and using Facebook profile data, as well as logging in via Facebook.
- obstinate 12y agoWould be fascinated to see them take on big G. E: not that I support these guys in any way. Just curious what would happen -- and whether we might all learn something about DDoS mitigation from such an event.
- nostrademons 12y agoGoogle gets DDoSed all the time. You don't hear about it because, well, the DDoS SREs are very, very good at what they do.
- mjdesa 12y agoSREs?
- deleted 12y ago[deleted]
- detaro 12y agoSite Reliability Engineers
- nostrademons 12y agoSite Reliability Engineer. It's a Google (+Facebook)-specific title that is sort of like a sysadmin or devops, but instead of keeping the system up, they write code that keeps the system up. They also have a different negotiating position vs. engineering than in many other companies, eg. SREs have veto power over many architectural decisions in the code, and it's more "we'll build the system that can stay upright with a minimum of pagerstorms" vs. "you build the system and throw it over the wall to us and then we'll keep it upright through our self-sacrificing heroism."
- jsmthrowaway 12y agoApple hires SREs who are actually sysadmins that occasionally code, complicating the title somewhat. This is not unique to them. nostrademons's explanation of SRE is the correct one, IMO. The architecture is key. Engineering has to be built to allow that. It has helped me in the past to say SREs are concerned more with the operation of a service than a group of machines offering a service; it's almost like a service operations developer. When a company thinks in terms of services and abstracts the machine away, i.e., containers, scheduling, Mesos, Omega/<unnamed>, intelligent CI/CD, service discovery, now you're getting into SRE territory instead of SA territory. The architecture involvement distinguishes SRE from devops for me. You should be able to trust SRE to build services, not just run engineering output. Teams that congeal out of Xooglers tend to preach SRE well, and there is the occasional company (Twitter and Foursquare come to mind) that applies the title and interacts with the team as intended.
- markthethomas 12y agoWow.
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- eridius 12y agoI gotta say I'm finding it hard to accept their word that they're responsible for Facebook. I haven't paid much attention but I'm under the impression that they primarily just deal in DDoS's and other crude attacks, and I have a hard time imagining that they could cause a large enough DDoS to affect the massive juggernaut that is Facebook. Especially since Facebook just came back up and is now perfectly responsive and showing no signs of being under strain.
- thrownaway2424 12y agoYeah, it doesn't seem like a DoS since facebook was reachable and serving error pages, and instagram was reachable and serving blank pages. It _does_ seem like an intrusion or other security incident though because I'd be surprised to learn that instagram shares lots of critical infrastructure with facebook. It seems more likely that someone hit the panic button for both sites.
- kevan 12y agoI wasn't even getting DNS resolution for any of the affected sites.
- eridius 12y agoSome sort of security incidence does seem more plausible than a DDoS, although I can't think of what would affect Facebook, Instagram, Tinder, Hipchat, and AIM simultaneously. I'm also having a hard time imagining what sort of security incident would result in Facebook deliberately shutting down their web presence, even for a few minutes. And all of the other potential attacks, such as DNS or CDN, seems like it a) wouldn't affect everyone simultaneously, and b) wouldn't even work because sites like Facebook don't have a single point of failure, there's always backups and backups for the backups.
- hrrsn 12y agoTinder uses Facebook's API heavily. It's not surprising it went down with Facebook
- 12y ago
- austinl 12y agoI doubt it was them, though think it's worth watching since Facebook will definitely have a post-mortem. If it's not DDoS/security related, then it would be kind of embarrassing for Lizard Squad (which is why I'm surprised to see them claim it). For example, Facebook's last major downtime was caused by a main database failure – nothing to do with any vulnerabilities: https://www.facebook.com/notes/facebook-engineering/more-details-on-todays-outage/431441338919 https://www.facebook.com/notes/facebook-engineering/more-det... Edit: I'm guessing the multiple services going down at once has to do with Akamai. It seems like there's some speculation about the storm on the east coast and their Boston datacenter.
- coffeecheque 12y agoLS have claimed responsibility for other services too though - HipChat, for example. It's unlikely all would suffer from internal issues at once. Though, as has been said before, anyone can claim responsibility. We'll soon see.
- sroerick 12y agoYeah, lets see "Blizzard Squad" try this when all of the east coast isn't trapped inside.
- baby 12y agoyour Chuck Rossi was awesome! If you have other amazing videos like this to share I'm all hear!