Why Lizard Squad Took Down PSN and Xbox Live On Christmas Day
DroidJason1 writes Early Christmas morning, hacker group Lizard Squad took credit for taking down PlayStation Network and Xbox Live for hours. This affected those who had received new Xbox One or PS4 consoles, preventing them from playing online. So why did they do it? According to an exclusive interview with Lizard Squad, it had to do with convincing companies to improve their security — the hard way. "Taking down Microsoft and Sony networks shows the companies' inability to protect their consumers and instead shows their true vulnerability. Lizard Squad claims that their actions are simple, take down gaming networks for a short while, and forcing companies to upgrade their security as a result."
If you want to prove these companies' inability to protect their customers, you hack into their systems and publish some anonymized but verifiable data. This is just petty vandalism; DDOSing game companies does not endanger customers or their privacy, it just denies them a service they paid for. It's like parking your truck across the entrance to the parking lot, in order to "prove that the mall has poor security".
If construction was anything like programming, an incorrectly fitted lock would bring down the entire building...
Given such lofty and noble intentions I'm sure they will be making their names known any day now so that the public can thank them for thei civil service...
These companies were not hacked, there was no data breach or loss of customer or employee information. These were simple DoS attacks. It doesn't take much knowledge or skill. As far as I can tell, their security functioned as intended.
So they ruin the day both for thousands of kids with new consoles and the tech support/security teams for the companies who now have to come in to work on Christmas. I have another theory why they do this on Christmas -- this group of hackers (at a psychological level) are just sad and lonely people who are angry with the world and want to ruin the joy/fun for others.
So they just gave you time to think about your game consumption, and the opportunity to think about the "silent" in silent night.
They stopped because they were paid off. Thinking of them as noble or anything less than assholes gives them to much credit.
https://twitter.com/LizardMafi...
Lizard Squad @LizardMafia 10h 10 hours ago
Thanks @KimDotcom for the vouchers--you're the reason we stopped the attacks. @MegaPrivacy is an awesome service.
I think at least some blame does need to be lay at the feat of Sony and Microsoft here, but not because of 'network security' but rather creating the risk in the first place where there does not need to be one.
This was basically a DDOS attack. By and large those are difficult to defend, and the usual defense is just having over whelming resources. Should everyone just go an 90% under subscribe systems just to make the DDOS proof? I don't know does not see practical.
Why do these systems need network access to play a game bought on a disk? That is the bigger question, sure I can understand only supporting multiplayer through a centralized service, my issue is with the activation and phone home crap. There is no "good" reason someone should not be able to use these things without network access for single player experiences.
Customers out realize that the system is brittle because Sony and Microsft created a hard dependency where there never needed to be one. It might not be their fault they are attacked, but they do know or should have know they are targets. Hopefully the lession they take away from this is that basic functionality should be there if you have the system and game disk fresh out of box. Maybe you can't update, download new content, do multiplayer but folks ought to be able to at least play with it even if the network is down.
That way the scope of these little disasters would be limited.
Repeal the 17th Amendment TODAY! Also Please Read http://www.gnu.org/philosophy/right-to-read.html
Or maybe they are more like Snowden and Assange and just egotistical assholes but on a smaller scale.
Need to take a bit of exception here, but mostly because of degree and motive:
* You can agree or disagree with what Snowden did, but you cannot deny that the man acted on principle - more importantly, he put his name and his ass on the line for what he did. Note that he also could have just as easily just anonymously *sold* the info viz. Silk Road/BTC and quietly retired as a zillionare in Ecuador.
* Assange? IMHO he's a narcissistic asswipe (I base this mostly on Cryptome's assessment of Wikileaks' early dealings with them), but again, he put his name and ass out there for better or worse.
* These "lizard" guys? Script kiddies who wanted a 'rep and managed to get paid, then tried to cover it up with some nobility bullshit. Perhaps a smaller-scale version of Assange in the aspect that they wanted a reputation, but unlike Assange, they weren't willing to stick their necks out.
Quo usque tandem abutere, Nimbus, patientia nostra?
None of these protect against a volume-oriented DDoS. Many are DoS only (single / few sources) and do not apply when every IP on the Internet appears to be sending thousands of requests, or more likely, responses. Further, you've completely ignored spoofing of addresses combined with amplification attacks (send out a 64 byte DNS request pretending to be the DDoS target, get 4kB sent to the target). Finally, regardless of the 50-100Gbps pipes MS, Sony and Amazon no doubt have, they're useless when there's 1Tbps of amplified crap directed down the pipes. With the example above, you'd only need about 4Gbps of bandwidth total (40 cheap VPS on "100Mbps" connections) to generate 256Gbps of DDoS.
When 256Gbps of rubbish arrives at your servers or firewalls ... registry settings and kernel tweaks do jack (note that CloudFlare was hit 11 months ago with more than 400Gbps of DDoS, so this is not implausible!)
And since it seems it was apk I'm replying to ... I'm actually half surprised you didn't try to claim that a HOSTS file would magically help.
Another mitigation strategy would be to allow players to directly connect to each other rather than go through a central server. We were able to do this a couple of decades ago, but now we can't? Or rather, it's because the companies want to continue to control what you do after the sale, to sell you the parts of the game they "forgot" to put on the disk.
And when the servers no longer support that game that you and your friends really love because it's become a classic, you're hosed.
"Transparent" is a shit show that trades on every stereotype going. A man in drag is NOT a transsexual.