Why Lizard Squad Took Down PSN and Xbox Live On Christmas Day
DroidJason1 writes Early Christmas morning, hacker group Lizard Squad took credit for taking down PlayStation Network and Xbox Live for hours. This affected those who had received new Xbox One or PS4 consoles, preventing them from playing online. So why did they do it? According to an exclusive interview with Lizard Squad, it had to do with convincing companies to improve their security — the hard way. "Taking down Microsoft and Sony networks shows the companies' inability to protect their consumers and instead shows their true vulnerability. Lizard Squad claims that their actions are simple, take down gaming networks for a short while, and forcing companies to upgrade their security as a result."
Why did they do it? They're assholes.
If you want to prove these companies' inability to protect their customers, you hack into their systems and publish some anonymized but verifiable data. This is just petty vandalism; DDOSing game companies does not endanger customers or their privacy, it just denies them a service they paid for. It's like parking your truck across the entrance to the parking lot, in order to "prove that the mall has poor security".
If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
Given such lofty and noble intentions I'm sure they will be making their names known any day now so that the public can thank them for thei civil service...
These companies were not hacked, there was no data breach or loss of customer or employee information. These were simple DoS attacks. It doesn't take much knowledge or skill. As far as I can tell, their security functioned as intended.
So they wouldn't mind if someone broke into their houses? Since, you know, it was just to force them to upgrade their security.
Denying people access to these services repeatedly is about being griefers not caring about the users' security.
So they ruin the day both for thousands of kids with new consoles and the tech support/security teams for the companies who now have to come in to work on Christmas. I have another theory why they do this on Christmas -- this group of hackers (at a psychological level) are just sad and lonely people who are angry with the world and want to ruin the joy/fun for others.
All a DoS does is prove one thing: That you can field more bandwidth than your target. Unless of course it's one where you exploit the weakness of a target system (e.g. by shutting down a service deliberately using an exploit). Else, a DoS proves little.
If a DoS exposes any kind of security issue, then a global one: That there are techniques that allow you to use little bandwidth on your end to cause the other end to drown in traffic. There are a few documented ways how you could pull this off, the most trivial one would be to spoof the IP address of your target system with some server that sends back a ton of info for a tiny request. E.g, DNS. Such an attack doesn't prove that the target system is vulnerable, it proves that the DNS protocol itself is beyond repair (and yes, it is, and there are secure replacements but ... you know, it's the internet... it works, changing stuff costs money, so...).
So what does the attack prove? Well, I wish I could say it proves without a doubt that MS and Sony have a security that matches the opaqueness of an erotic dancer's dress and should up their security (well, they do, and they should, but this attack doesn't prove that). It proves that we use technology that makes such an attack not only possible but actually trivial. And that EVERY company on the net is susceptible to something like that because unlimited bandwidth does not exist.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
"We're trying to get shopkeepers to install stronger windows", said the kid throwing bricks.
Yeah, that would be like yanking a movie out of a movie theater just based on some threats from terrorists. Nobody would do that.
If you are not allowed to question your government then the government has answered your question.
The greatest part of this is the error message I got when trying to do the update for PS Home in my PS3.
The possible errors where: My ISP, my internet connection, my router.
Funny how they never admit the problem could come from their side, it reminds me exactly the process I have to go trough about every time I need to go to my lab's IT office to get something fixed... now, it obviously can't be their system's fault. The system put in place by the IT department is obviously perfect, it's us - the lousy users - that are obviously doing something wrong.
This was a ddos attack. There's essentially no way to protect yourself from a ddos attack. It doesn't demonstrate a security issue with Xbox live or PSN. It just demonstrates that any cluster of servers anywhere can eventually be overloaded.
None of these protect against a volume-oriented DDoS. Many are DoS only (single / few sources) and do not apply when every IP on the Internet appears to be sending thousands of requests, or more likely, responses. Further, you've completely ignored spoofing of addresses combined with amplification attacks (send out a 64 byte DNS request pretending to be the DDoS target, get 4kB sent to the target). Finally, regardless of the 50-100Gbps pipes MS, Sony and Amazon no doubt have, they're useless when there's 1Tbps of amplified crap directed down the pipes. With the example above, you'd only need about 4Gbps of bandwidth total (40 cheap VPS on "100Mbps" connections) to generate 256Gbps of DDoS.
When 256Gbps of rubbish arrives at your servers or firewalls ... registry settings and kernel tweaks do jack (note that CloudFlare was hit 11 months ago with more than 400Gbps of DDoS, so this is not implausible!)
And since it seems it was apk I'm replying to ... I'm actually half surprised you didn't try to claim that a HOSTS file would magically help.
I tried to get on XBOX Live yesterday, and was having trouble connecting. I figured it was because it was the afternoon and their servers got overloaded with all the people who opened their new systems and tried to get online, and it overloaded the servers. That wouldn't be the first time the xbox servers got overloaded on Christmas. I did a test and it gave me a message right away that it was not my network or isp, it said it was an issue on microsofts side. I tried again like 10 minutes later and it was fine.