LIZARD SQUAD is Back. Planning XBL Attack. "Biggest attack yet". [UP: XBL/PSN Down]

East Coast US (PA)... PlayStation app on my phone is working. I'm about to try my console.
 
Has anyone moved from being angry at Lizard Squad, disappointed with Finest Squad, and annoyed with Sony?

I mean, how can they not withstand some botnet that a bunch of chavs spin up on your authentication servers? It's far on Sony's shoulders now and they SHOULD be embarrassed.

giphy.gif
 
Oh my god. I just wanna play some Minecraft with my girlfriend.
She got me Driveclub and a sony gold headset for christmas, want to take em for a spin.

Its fucking boxing day here, the psn has been down since yesterday morning for Australia.
Sooooooooooooooooooooooo over it >_<
 
That being said; Who is actually to blame?

The people instigating the attack are first, and primarily, at fault. After that is said and done, it is very difficult to determine what exactly is the "acceptable" amount of mitigation a corporation should be spending for - the average for the year + 50% just in case? 200% the average? Or should they take into account the year over year exponential increase in botnet size, and just go all-out and try to secure against the inevidable 1000Gbps - a logistically crazy feat to try, both in terms of hardware and financial investment. So, those costs go to the corporation. In a perfect world, the corporation would shoulder the costs so that nothing bad ever happens to the consumer. We don't live in that world, so likely, things would become more expensive for the end-user. How that plays out, nobody knows.

I do! Do you realize that is not okay? That it's preventable and that these types of auth servers CAN be secured against massive targeted denial of service?

Mitigation is possible. Outright defense and prevention, impossible. Mitigation comes at a cost, financially, and at a less than ideal end-user experience. Sony *should* invest in better infrastructure, Microsoft is doing an okay job I think, but since they're already thinking of just shitcanning the entire Xbox division, who knows how the board would vote when the question comes up: should we spend more money to prevent once or twice a year ddos attacks from being so bad to the end user, or just stop making consoles?

The Feds haven't been able to track down the previous attacks. MS hasn't been able to stop these attacks either. They all need to hire better talent.

image.php


Well, that's not suspicious at all. :P

That aside - the big-time DDoS mitigation companies hire some pretty incredible talent, but their talents do come at a price. I don't even want to imagine what a full Norse hookup costs, the full package.
 
and it does nothing for them IRL cuz if people find out who they are, they would be in trouble. so yea, it's a waste of time.

you're right and I agree, but if I had to create a profile I would say their online personas are just as, if not more, important to them. It also probably gives them a sort of superiority complex knowing what they did, and thinking they're too good to be caught or something.
 
The difference is that Microsoft and Sony won't lose any real money here, so they really just don't care. Things might or might not be back up tomorrow, but most of us here won't be returning any consoles since we already own them.

I beg to differ. Sony and MS are losing millions over this.
 
I can't understand how Live and PSN crumble in the face of a DDOS. Microsoft has been doing this kind of service for over a decade, does Azure shit the bed when this happens? And Google's services never seem to go down.
 
Yep, poor architects are a problem from garages to IT solutions.

The architects built your garage for the two cars you own, as you planned. The 1,000 cars that just showed up unannounced and are trying to park in your garage are the millions of dummy logins from the rented servers clogging up your queues.

You are mad at the architects for not being able to suddenly make your garage accommodate 1000 cars, rather than the dbag that sent the invitation to everyone at work.

But you don't seem to have a grasp on how this works so the analogy is lost on you. So go ahead and be mad at Sony for not having magic dust in their data centers.

Edit: auto correct fails
 
I do! Do you realize that is not okay? That it's preventable and that these types of auth servers CAN be secured against massive targeted denial of service? Because there are tons of vendors and corporations that can't afford to lose that kind of a battle?

The difference is that Microsoft and Sony won't lose any real money here, so they really just don't care. Things might or might not be back up tomorrow, but most of us here won't be returning any consoles since we already own them.

Dude, they took Bnet down aswell, awhile back.

Stop blaming the victim here, its cool to want better service, hell, we all want to play our damn games.
Direct your anger at those responsible, not Sony and MS.
 
In a perfect world, the corporation would shoulder the costs so that nothing bad ever happens to the consumer. We don't live in that world, so likely, things would become more expensive for the end-user. How that plays out, nobody knows.

Thanks for the reply.
I hope somebody makes a Lizard Squad movie.
Show how silly they are, show them getting hacked, show them going to jail.
Full arc, audience would feel great at the end.
 
Most certainly did, but all they see is the reality of a Christmas horribly ruined for their kids. The toughest part of it was their kids calling me on their own using their parent's phone to ask for assistance in getting the system operational. I knew there was nothing that could fix it in that moment, but I didn't want to just dismiss their requests for help altogether and just hang up because they sounded way too damn excited, so I basically went along with the whole thing, taking them through some stuff while explaining to them in the simplest way possible what was actually taking place, and that it in no way meant their new xbox was somehow damaged.

Bit dramatic... Especially when you consider that the console works perfectly fine offline.
 
Looks like Finest Squad wants to teach Lizard Squad a lesson by posting all their personal info online: including parents' names and pictures, home addresses, and the schools they attend.

One of them is a kid in gradeschool smh.

Lizard Squad's latest tweet was "going dark, goodbye for now."
 
DDoS attacks are distributed service interruptions, not security breaches. No one will be required to change their passwords or shred their credit card information after this.
 
The architects built your garage for the two cars you own, as you planned. The 1,000 cars that just showed up unannounced and are trying to park in your garage are the millions of dummy logins from the rented servers clogging up your queues.

You are mad at the architects for not being able to suddenly make your garage accommodate 1000 cars, rather than the dbag that sent the invitation to everyone at work.

But you don't seem to have a grasp on how this works do the analogy is lost on you. So go ahead and be mad at Sony for not having magic dust in their days centers.

Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.
 
I can't understand how Live and PSN crumble in the face of a DDOS. Microsoft has been doing this kind of service for over a decade, does Azure shit the bed when this happens? And Google's services never seem to go down.

Every year, the large botnets grow in size and scope exponentially. We've seen DDoS attacks go from 1.4Gbps to 400+Gbps in just three years. Google only seems to never go down, because they have super redundancy and backup structures in place, but they are not immune either as was evident when Michael Jackson died.

MS has decent enterprise solutions that seem to have slightly above average mitigation and bounce-back from something like this, but it's all going to boil down to how much money they're willing to spend protecting services.

Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

There is, at best, mitigation when it comes to the really large attacks. DDoS uses the very nature of how the internet works against itself, so it's a complex problem. The only true protection against a DDoS attack is to turn off your servers. But then, how would legit customers connect? There is a great video of some DDoS mitigation in action here: http://www.dailymotion.com/video/x14r6yg_prolexic-in-action-mitigating-a-160-gbps-ddos-attack_news
 
The architects built your garage for the two cars you own, as you planned. The 1,000 cars that just showed up unannounced and are trying to park in your garage are the millions of dummy logins from the rented servers clogging up your queues.

You are mad at the architects for not being able to suddenly make your garage accommodate 1000 cars, rather than the dbag that sent the invitation to everyone at work.

But you don't seem to have a grasp on how this works so the analogy is lost on you. So go ahead and be mad at Sony for not having magic dust in their data centers.

Edit: auto correct fails

Someone just got schooled.
 
Looks like Finest Squad wants to teach Lizard Squad a lesson by posting all their personal info online: including parents' names and pictures, home addresses, and the schools they attend.

One of them is a kid in gradeschool smh.

Lizard Squad's latest tweet was "going dark, goodbye for now."
I get the feeling they're the same person and they're releasing fake garbage to get more attention.
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.
It's essentially a war of attrition. Companies increase mitigation efforts for the attacks while attackers increase the size and scope of the attack.
 
Looks like Finest Squad wants to teach Lizard Squad a lesson by posting all their personal info online: including parents' names and pictures, home addresses, and the schools they attend.

One of them is a kid in gradeschool smh.

Lizard Squad's latest tweet was "going dark, goodbye for now."

This is what I never understood about hackers - or cheaters or a number of other people : What makes you think if you can't do something that someone else doesn't have the same abilities you do and also disagree with what you're doing? This thought is what keeps me from ever using my abilities for evil atleast.

I get the feeling they're the same person and they're releasing fake garbage to get more attention.

"Prank videos", "reality" tv, news articles, Facebook contests.... it's 2014, nothing is real anymore, don't believe anything without proof.
 
Looks like parts of XBL are up now. I can see the store and the like, but the friends list is acting up. See how many friends are on, but the list doesn't fully show up.

Central time zone, BTW. Nebraska in specific.
 
I get the feeling they're the same person and they're releasing fake garbage to get more attention.

Yeah I would honestly be surprised if it wasn't the same people. Just trying to get more people to fall in to their "hacking" soap opera.

Edit: I just feel bad for young kids getting a console for Christmas and not being able to play. I remember when I got my SNES and later PSOne and 64, and it was the greatest feeling ever.
 
Not blaming MS and Sony... but man it must suck to not be able to play on something you are paying for (PS+/Live) due to something completely out of either party's hands.
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

Not whenever the urge arrives it took a long time to setup this and it will take a long time again if things are properly taken care of. There is a reason there is 1 or 2 per year and not 50-100. It's not stoppable currently though that's correct. And if the setup remains then yes it can happen again. And it probably will happen again. Sony doesn't have the net cash flow to do all the proper improvements necessary to start proper mitigation on there servers its something that would be applied slowly over time. MS that's a different story and they are doing OK from what it looks like but no company is impentrable even google can succumb to this type of attack with enough effort from outside parties.
 
Explain it to me again then - also, care to tell me what part of infosec you're in?

smh...

The worst part is all you need is a basic understanding of the internet to understand why this isn't preventable. You don't need to be in "infosec"

This thread just people coming in without reading the rest of the thread or understanding how the internet works and complaining about companies being stupid and/or greedy over and over again while they try to defend themselves instead of learning why the problem exists.
 
Anonymous posted a picture of one of the guys on Twitter along with his address:

edit: link removed

If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.
 
Forgive my ignorance, but you and others are making it sound as if there is no defense against this. Is that correct? If so, really sucks that some asshole can do this whenever the urge arrives.

It's ok, this really isn't everybody's thing. But yes, for the most part there is no defense for this type of attack.

The only thing that would defend against this is having a network infrastructure 100 times the size you actually need. At which the cost of live and psn would be unfeasible.

Anyone telling you it's preventable within the bounds of the current infrastructure of the current services without a major restructuring is just trying to sell you something.
 
So I turned off my ps4 hours ago and decided to watch some movies instead.

What's the word on the #VirginSquad ladies and gents? Did their Mom's make them go to bed yet? I don't feel like reading through the past several pages to get caught up on the saga.

Where's Lionel?
 
Looks like Finest Squad wants to teach Lizard Squad a lesson by posting all their personal info online: including parents' names and pictures, home addresses, and the schools they attend.

One of them is a kid in gradeschool smh.

Lizard Squad's latest tweet was "going dark, goodbye for now."
Translation:"mummy said It's bedtime"
 
Anonymous posted a picture of one of the guys on Twitter along with his address:

If that's true or not I have no idea.

Saw where a bunch of people were supposedly driving to his address to beat the shit out of him.

Not good.

I dont think you are allowed to be posting peoples personal info on here.

Edit: looks like things are going to get a little crazy..

Would suck if that guy is innocent though.
 
Top Bottom