Click here to close now.

Welcome!

Search Authors: Elizabeth White, Vormetric Blog, Trevor Parsons, Carmen Gonzalez, Liz McMillan

Blog Feed Post

[berkman] “LOIC [low-orbit ion cannon] will tear us apart”: The impact of tool desiogn and media portrayals in the success of activist DDOS attacks

Molly Sauter [twitter:oddletters] (from Berkman and the Center for Civic Media at MIT) is giving a lunchtime Berkman talk. She’s going to focus on Operation Payback, the Dec. 2010 action by Anonymous against those financial services that cut off Wikileaks after Wikileaks made available a massive leak of State Dept. cables. Operation Avenge Assange tried to bring down the sites of those services. Molly sees this as an evolution in media activism, expanding on the use of DDOS tactics by groups in the 1990s; [DDOS = distributed denial of service: flooding a site beyond its capacity to respond, and doing so from multiple sites.]

NOTE: Live-blogging. Getting things wrong. Missing points. Omitting key information. Introducing artificial choppiness. Over-emphasizing small matters. Paraphrasing badly. Not running a spellpchecker. Mangling other people’s ideas and words. You are warned, people.

Molly begins with a simple explanation of DDOS. The flooding can come from a single computer (unlikely), via a volunteer botnet, or botnets that infect other computers; the botnets communicate with a central computer, pounding on the target until it can’t handle the traffic.

Old school activists think of DDOS as a form of censorship, and thus it is not acceptable. For many digitally-enabled activists (e.g., Electronic Disturbance Theater) DDOS is a form of disobedience. For EDT, DDOS is an auxiliary form of activism: “DDOS is something you do when you’re out on the streets so your computer can be at home protesting.” DDOS is sometimes seen as a type of sit-in, although Molly thinks this is inapt. For some, DDOS is a direct form of protest, and in others, it’s an indirect and symbolic action. Anonymous melds these approaches: influence via technology + influence via media + direct action disruption.

Electronic Disturbance Theater [EDT] used Flood Net, a tool that “hurls bits” but that also lets you send a message to show up in the target computer’s error log. Cleverly, if your issue is human rights, the log might read “Human rights is not found on this server.” But, Molly says, these logs are only read by the admin, so it’s really a way for the activist to yell something for the sake of yelling. The EDT restricted targets of Flood Net and set scheduled times. EDT open sourced it in 1999. The language on the Floor Net site is comprehensible only to people who already know about the issues, e.g., Mexican Neo-Liberalism. It is intimidating for those outside of the circle. It is also very tied to a view of activism that ties actions to individuals â?? anonymous individuals, but using Flood Net requires the action of a person.

LOIC — low orbit ion cannon— was developed maybe around 2006, and forked in 2008. By Dec. 2010, versions could run on just about anything — Windows, Mac, on mobiles, within a browser… Molly goes through the differences in the different versions of it. They let you type in a URL, set some options that are set to defaults, and then you press a button. Done! (LOIC is the boss weapon from the game Command & Conquer). The button you press in the abatishchev version is labeled “IMMA CHARGIN MAH LAZER,” a popular meme. It has the same messaging functionality as Flood Net. The default message derives from a 4chan bestiality rape meme that Molly urges us not to google. This version “is focused on the 4chan Anonymous culture set.”

She then compares this to the NewEraCracker version. Very similar. Same “Imma chargin mah lazer” meme, but the rape meme is gone. Instead, it says “u done goofed,” the popular Jessi Slaughter meme. Jessie pissed off Anonymous, so Anonymous sent lots of pizza to her house. Her father posted a defensive video that wasn’t very smart about the Net, which got widely distributed, and which contained the line “you done goofed.” This message is more confrontational than the other version which the recipient would be unlikely to understand at all. This version of LOIC also has a “fucking hive mind mode” that lets you automate the process entirely by plugging it into an IRC server to use volunteer computers [I think].

These tools, especially the second, created a community of activists, especially in hive mind mode. There are many LOIC tutorial videos on YouTube. This reaches out to new people to join, unlike EDT’s use of language that appeals only to those already in the know. Because anyone can use it, it helps Anonymous become a community of trust.

Anonymous has also pushed DDOS as a media manipulation tactic, and used media for recruitment. Molly doesn’t know if it was a conscious decision, but DDOS ended up as a recruitment tactic.

During the four days of Operation Payback, the media coverage was very confused. For example the media weren’t sure that DDOS is illegal. (It is.) Even Gizmodo got wrong how risky DDOS is for the attacker; it wrongly claimed that the target’s log files don’t record the incoming connections during DDOS. Experienced users know to anonymize their packets, but those who came in new and used this easy-to-use tool often did not protect themselves. The Paypal 16 now under indictment were caught because PayPal stored the top 1000 IP addresses. Much of the coverage just quoted Anonymous at length. “Anonymous is a very horizontal org and there’s no press person to talk to,” but, Molly says, there was a “press IRC channel” but the media didn’t know how to use it. Some mainstream articles linked to download sites for LOIC, which may have encouraged people to download it without understanding the legality of using it.

Conclusions: “Operation Payback’s success was due to a confluence of tech, community, and news media factors. Anonymous’ use of DDOS represent an innovation in participant population and tool design. And Anonymous pushes the reframing of DDOS as a tool of media manipulation and biographical impact [how the participants think about themselves], not direct action.”

Q&A

Q: Is the paypal list public?

A: Nope.

Q: Can you bring your research up to date?

A: I’m writing my thesis now. So, no.

Q: How does being identified play into the historical mindset?

A: I got into this topic because I wanted to do my thesis on activism and anonymity. Anonymous challenges the assumption that if you’re anonymous, you’re not serious about your activism. The cultural preference for identified activism comes from the 1960s civil disobedience movement, which in turns comes from Thoreau: you break the law and accept punishment for it. But that privileges those who won’t lose their house and their family if arrested. This puts activism on the shoulders of a particular class. Anonymous disagrees. It says you can engage in civil disobedience without personal consequence.

Q: The Federalist Papers were anonymous because it implicitly was saying that the ideas are important enough not to need names attached. Anonymous not only escapes punishment, it makes it effortless â?? the amount of effort you put in is indistinguishable from that of someone whose computer was infected by a bot.

A: This is the slacktivism argument. Slacktivism challenges the expectations about what activism does. One version says you’re supposed to change something or have a solution. But slacktivism (or clicktivism) is valuable for the biographical impact.

A: Studies have looked into whether eating organic food affects your self image so that you do more, or that you merely congratulate yourself.

A: The ladder of engagement says that the big step is getting on the first rung. My view of slacktivism is that it’s widened that run. Pressing the LOIC button gets people started, and I’m in favor of people starting somewhere, when it is in a considered and useful way.

Q: How about The Jester?

A: He’s an Army veteran who explicitly aligns his morals with pro-US, anti-jihadist, anti-Anonymous DDOS. He claims to be working by himself. I don’t think his actions are ethical because they’re about silencing content. [Molly tells us that she has a presentation on DDOS ethics.]

Q: Why is “fuckng hive mind mode” a community? People are donating bandwidth. But the manual mode, where people actively decide to participate in something, is much more like people being in a community. The participants in FHHM don’t necessarily view themselves as joining in a community, although the federal govt is claiming that they are.

A: I agree. My point with FHHM was that it opens up ways of accessing that community in ways that were not possible before.

Q: LOIC is hosted at github and sourceforge, and tutorials at YouTube. Any attempts to remove?

A: LOIC and tools like it are listed as “stress-testing” tools. And it can be used that way if you aim it at your own server. It’s like a head shop selling a pipe for tobacco. During the four days of the operation, Twitter did try to shut down the Anonymous twitter account.

Q: You seem to be saying that Anonymous is becoming more respectful, shifting out of the “otherized” world of 4chan. Is there quantitative data supporting this?

A: Biella Coleman has done the most research on this. That’s where I’ve gotten my data.

Q: How many people participated?

A: It’s been downloaded hundreds of thousands of times.

Q: When an org provides a press contact, a journalist can always orient around that, bounce off of it. But Anonymous doesn’t work that way. How does Anonymous’ play affect coverage?

A: The media doesn’t know how to deal with orgs like Anon and Occupy. They just speak with random people, none of who speak for the org (because no one does). The opening of the press IRC channel was great, for those who found it. It let the press engage at length. But Anon is usefully weird, and thus hard for the media.

Q: [me] So, will LOIC tear us apart? Civil disobedients accept consequences in part to raise the bar so that people don’t too easily break the law. LOIC lowers that bar. If Anon were attacking services that you like, would you be as sanguine?

LOIC isn’t much used now because it’s dangerous, and there are new tools. It’s hard to take down a site.

Q: As the tools get better?

A: Permanent arms race.

Q: Arrest of Sabu?

A: It won’t kill Anonymous.

Read the original blog entry...

More Stories By David Weinberger

David is the author of JOHO the blog (www.hyperorg.com/blogger). He is an independent marketing consultant and a frequent speaker at various conferences. "All I can promise is that I will be honest with you and never write something I don't believe in because someone is paying me as part of a relationship you don't know about. Put differently: All I'll hide are the irrelevancies."

@ThingsExpo Stories
SYS-CON Events announced today that robomq.io will exhibit at SYS-CON's @ThingsExpo, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. robomq.io is an interoperable and composable platform that connects any device to any application. It helps systems integrators and the solution providers build new and innovative products and service for industries requiring monitoring or intelligence from devices and sensors.
The 17th International Cloud Expo has announced that its Call for Papers is open. 17th International Cloud Expo, to be held November 3-5, 2015, at the Santa Clara Convention Center in Santa Clara, CA, brings together Cloud Computing, APM, APIs, Microservices, Security, Big Data, Internet of Things, DevOps and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal today!
SYS-CON Events announced today that Litmus Automation will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Litmus Automation’s vision is to provide a solution for companies that are in a rush to embrace the disruptive Internet of Things technology and leverage it for real business challenges. Litmus Automation simplifies the complexity of connected devices applications with Loop, a secure and scalable cloud platform.
While not quite mainstream yet, WebRTC is starting to gain ground with Carriers, Enterprises and Independent Software Vendors (ISV’s) alike. WebRTC makes it easy for developers to add audio and video communications into their applications by using Web browsers as their platform. But like any market, every customer engagement has unique requirements, as well as constraints. And of course, one size does not fit all. In her session at WebRTC Summit, Dr. Natasha Tamaskar, Vice President, Head of Cloud and Mobile Strategy at GENBAND, will explore what is needed to take a real time communications ...
As Marc Andreessen says software is eating the world. Everything is rapidly moving toward being software-defined – from our phones and cars through our washing machines to the datacenter. However, there are larger challenges when implementing software defined on a larger scale - when building software defined infrastructure. In his session at 16th Cloud Expo, Boyan Ivanov, CEO of StorPool, will provide some practical insights on what, how and why when implementing "software-defined" in the datacenter.
SYS-CON Events announced today that Solgenia will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY, and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. Solgenia is the global market leader in Cloud Collaboration and Cloud Infrastructure software solutions. Designed to “Bridge the Gap” between Personal and Professional Social, Mobile and Cloud user experiences, our solutions help large and medium-sized organizations dr...
Internet of Things (IoT) will be a hybrid ecosystem of diverse devices and sensors collaborating with operational and enterprise systems to create the next big application. In their session at @ThingsExpo, Bramh Gupta, founder and CEO of robomq.io, and Fred Yatzeck, principal architect leading product development at robomq.io, will discuss how choosing the right middleware and integration strategy from the get-go will enable IoT solution developers to adapt and grow with the industry, while at the same time reduce Time to Market (TTM) by using plug and play capabilities offered by a robust I...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on Twitter at @MicroservicesE
After making a doctor’s appointment via your mobile device, you receive a calendar invite. The day of your appointment, you get a reminder with the doctor’s location and contact information. As you enter the doctor’s exam room, the medical team is equipped with the latest tablet containing your medical history – he or she makes real time updates to your medical file. At the end of your visit, you receive an electronic prescription to your preferred pharmacy and can schedule your next appointment.
Wearable technology was dominant at this year’s International Consumer Electronics Show (CES) , and MWC was no exception to this trend. New versions of favorites, such as the Samsung Gear (three new products were released: the Gear 2, the Gear 2 Neo and the Gear Fit), shared the limelight with new wearables like Pebble Time Steel (the new premium version of the company’s previously released smartwatch) and the LG Watch Urbane. The most dramatic difference at MWC was an emphasis on presenting wearables as fashion accessories and moving away from the original clunky technology associated with t...
SYS-CON Events announced today the IoT Bootcamp – Jumpstart Your IoT Strategy, being held June 9–10, 2015, in conjunction with 16th Cloud Expo and Internet of @ThingsExpo at the Javits Center in New York City. This is your chance to jumpstart your IoT strategy. Combined with real-world scenarios and use cases, the IoT Bootcamp is not just based on presentations but includes hands-on demos and walkthroughs. We will introduce you to a variety of Do-It-Yourself IoT platforms including Arduino, Raspberry Pi, BeagleBone, Spark and Intel Edison. You will also get an overview of cloud technologies s...
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch of Docker's initial release in March of 2013, interest was revved up several notches. Then late last...
The WebRTC Summit 2015 New York, to be held June 9-11, 2015, at the Javits Center in New York, NY, announces that its Call for Papers is open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 16th International Cloud Expo, @ThingsExpo, Big Data Expo, and DevOps Summit.
SOA Software has changed its name to Akana. With roots in Web Services and SOA Governance, Akana has established itself as a leader in API Management and is expanding into cloud integration as an alternative to the traditional heavyweight enterprise service bus (ESB). The company recently announced that it achieved more than 90% year-over-year growth. As Akana, the company now addresses the evolution and diversification of SOA, unifying security, management, and DevOps across SOA, APIs, microservices, and more.
The list of ‘new paradigm’ technologies that now surrounds us appears to be at an all time high. From cloud computing and Big Data analytics to Bring Your Own Device (BYOD) and the Internet of Things (IoT), today we have to deal with what the industry likes to call ‘paradigm shifts’ at every level of IT. This is disruption; of course, we understand that – change is almost always disruptive.
SYS-CON Events announced today that SafeLogic has been named “Bag Sponsor” of SYS-CON's 16th International Cloud Expo® New York, which will take place June 9-11, 2015, at the Javits Center in New York City, NY. SafeLogic provides security products for applications in mobile and server/appliance environments. SafeLogic’s flagship product CryptoComply is a FIPS 140-2 validated cryptographic engine designed to secure data on servers, workstations, appliances, mobile devices, and in the Cloud.
GENBAND has announced that SageNet is leveraging the Nuvia platform to deliver Unified Communications as a Service (UCaaS) to its large base of retail and enterprise customers. Nuvia’s cloud-based solution provides SageNet’s customers with a full suite of business communications and collaboration tools. Two large national SageNet retail customers have recently signed up to deploy the Nuvia platform and the company will continue to sell the service to new and existing customers. Nuvia’s capabilities include HD voice, video, multimedia messaging, mobility, conferencing, Web collaboration, deskt...
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
SYS-CON Events announced today that Cisco, the worldwide leader in IT that transforms how people connect, communicate and collaborate, has been named “Gold Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. Cisco makes amazing things happen by connecting the unconnected. Cisco has shaped the future of the Internet by becoming the worldwide leader in transforming how people connect, communicate and collaborate. Cisco and our partners are building the platform for the Internet of Everything by connecting the...
Temasys has announced senior management additions to its team. Joining are David Holloway as Vice President of Commercial and Nadine Yap as Vice President of Product. Over the past 12 months Temasys has doubled in size as it adds new customers and expands the development of its Skylink platform. Skylink leads the charge to move WebRTC, traditionally seen as a desktop, browser based technology, to become a ubiquitous web communications technology on web and mobile, as well as Internet of Things compatible devices.