Welcome!

Agile Computing Authors: Harry Trott, Elizabeth White, Carmen Gonzalez, Liz McMillan, Yeshim Deniz

Blog Feed Post

[berkman] “LOIC [low-orbit ion cannon] will tear us apart”: The impact of tool desiogn and media portrayals in the success of activist DDOS attacks

Molly Sauter [twitter:oddletters] (from Berkman and the Center for Civic Media at MIT) is giving a lunchtime Berkman talk. She’s going to focus on Operation Payback, the Dec. 2010 action by Anonymous against those financial services that cut off Wikileaks after Wikileaks made available a massive leak of State Dept. cables. Operation Avenge Assange tried to bring down the sites of those services. Molly sees this as an evolution in media activism, expanding on the use of DDOS tactics by groups in the 1990s; [DDOS = distributed denial of service: flooding a site beyond its capacity to respond, and doing so from multiple sites.]

NOTE: Live-blogging. Getting things wrong. Missing points. Omitting key information. Introducing artificial choppiness. Over-emphasizing small matters. Paraphrasing badly. Not running a spellpchecker. Mangling other people’s ideas and words. You are warned, people.

Molly begins with a simple explanation of DDOS. The flooding can come from a single computer (unlikely), via a volunteer botnet, or botnets that infect other computers; the botnets communicate with a central computer, pounding on the target until it can’t handle the traffic.

Old school activists think of DDOS as a form of censorship, and thus it is not acceptable. For many digitally-enabled activists (e.g., Electronic Disturbance Theater) DDOS is a form of disobedience. For EDT, DDOS is an auxiliary form of activism: “DDOS is something you do when you’re out on the streets so your computer can be at home protesting.” DDOS is sometimes seen as a type of sit-in, although Molly thinks this is inapt. For some, DDOS is a direct form of protest, and in others, it’s an indirect and symbolic action. Anonymous melds these approaches: influence via technology + influence via media + direct action disruption.

Electronic Disturbance Theater [EDT] used Flood Net, a tool that “hurls bits” but that also lets you send a message to show up in the target computer’s error log. Cleverly, if your issue is human rights, the log might read “Human rights is not found on this server.” But, Molly says, these logs are only read by the admin, so it’s really a way for the activist to yell something for the sake of yelling. The EDT restricted targets of Flood Net and set scheduled times. EDT open sourced it in 1999. The language on the Floor Net site is comprehensible only to people who already know about the issues, e.g., Mexican Neo-Liberalism. It is intimidating for those outside of the circle. It is also very tied to a view of activism that ties actions to individuals â?? anonymous individuals, but using Flood Net requires the action of a person.

LOIC — low orbit ion cannon— was developed maybe around 2006, and forked in 2008. By Dec. 2010, versions could run on just about anything — Windows, Mac, on mobiles, within a browser… Molly goes through the differences in the different versions of it. They let you type in a URL, set some options that are set to defaults, and then you press a button. Done! (LOIC is the boss weapon from the game Command & Conquer). The button you press in the abatishchev version is labeled “IMMA CHARGIN MAH LAZER,” a popular meme. It has the same messaging functionality as Flood Net. The default message derives from a 4chan bestiality rape meme that Molly urges us not to google. This version “is focused on the 4chan Anonymous culture set.”

She then compares this to the NewEraCracker version. Very similar. Same “Imma chargin mah lazer” meme, but the rape meme is gone. Instead, it says “u done goofed,” the popular Jessi Slaughter meme. Jessie pissed off Anonymous, so Anonymous sent lots of pizza to her house. Her father posted a defensive video that wasn’t very smart about the Net, which got widely distributed, and which contained the line “you done goofed.” This message is more confrontational than the other version which the recipient would be unlikely to understand at all. This version of LOIC also has a “fucking hive mind mode” that lets you automate the process entirely by plugging it into an IRC server to use volunteer computers [I think].

These tools, especially the second, created a community of activists, especially in hive mind mode. There are many LOIC tutorial videos on YouTube. This reaches out to new people to join, unlike EDT’s use of language that appeals only to those already in the know. Because anyone can use it, it helps Anonymous become a community of trust.

Anonymous has also pushed DDOS as a media manipulation tactic, and used media for recruitment. Molly doesn’t know if it was a conscious decision, but DDOS ended up as a recruitment tactic.

During the four days of Operation Payback, the media coverage was very confused. For example the media weren’t sure that DDOS is illegal. (It is.) Even Gizmodo got wrong how risky DDOS is for the attacker; it wrongly claimed that the target’s log files don’t record the incoming connections during DDOS. Experienced users know to anonymize their packets, but those who came in new and used this easy-to-use tool often did not protect themselves. The Paypal 16 now under indictment were caught because PayPal stored the top 1000 IP addresses. Much of the coverage just quoted Anonymous at length. “Anonymous is a very horizontal org and there’s no press person to talk to,” but, Molly says, there was a “press IRC channel” but the media didn’t know how to use it. Some mainstream articles linked to download sites for LOIC, which may have encouraged people to download it without understanding the legality of using it.

Conclusions: “Operation Payback’s success was due to a confluence of tech, community, and news media factors. Anonymous’ use of DDOS represent an innovation in participant population and tool design. And Anonymous pushes the reframing of DDOS as a tool of media manipulation and biographical impact [how the participants think about themselves], not direct action.”

Q&A

Q: Is the paypal list public?

A: Nope.

Q: Can you bring your research up to date?

A: I’m writing my thesis now. So, no.

Q: How does being identified play into the historical mindset?

A: I got into this topic because I wanted to do my thesis on activism and anonymity. Anonymous challenges the assumption that if you’re anonymous, you’re not serious about your activism. The cultural preference for identified activism comes from the 1960s civil disobedience movement, which in turns comes from Thoreau: you break the law and accept punishment for it. But that privileges those who won’t lose their house and their family if arrested. This puts activism on the shoulders of a particular class. Anonymous disagrees. It says you can engage in civil disobedience without personal consequence.

Q: The Federalist Papers were anonymous because it implicitly was saying that the ideas are important enough not to need names attached. Anonymous not only escapes punishment, it makes it effortless â?? the amount of effort you put in is indistinguishable from that of someone whose computer was infected by a bot.

A: This is the slacktivism argument. Slacktivism challenges the expectations about what activism does. One version says you’re supposed to change something or have a solution. But slacktivism (or clicktivism) is valuable for the biographical impact.

A: Studies have looked into whether eating organic food affects your self image so that you do more, or that you merely congratulate yourself.

A: The ladder of engagement says that the big step is getting on the first rung. My view of slacktivism is that it’s widened that run. Pressing the LOIC button gets people started, and I’m in favor of people starting somewhere, when it is in a considered and useful way.

Q: How about The Jester?

A: He’s an Army veteran who explicitly aligns his morals with pro-US, anti-jihadist, anti-Anonymous DDOS. He claims to be working by himself. I don’t think his actions are ethical because they’re about silencing content. [Molly tells us that she has a presentation on DDOS ethics.]

Q: Why is “fuckng hive mind mode” a community? People are donating bandwidth. But the manual mode, where people actively decide to participate in something, is much more like people being in a community. The participants in FHHM don’t necessarily view themselves as joining in a community, although the federal govt is claiming that they are.

A: I agree. My point with FHHM was that it opens up ways of accessing that community in ways that were not possible before.

Q: LOIC is hosted at github and sourceforge, and tutorials at YouTube. Any attempts to remove?

A: LOIC and tools like it are listed as “stress-testing” tools. And it can be used that way if you aim it at your own server. It’s like a head shop selling a pipe for tobacco. During the four days of the operation, Twitter did try to shut down the Anonymous twitter account.

Q: You seem to be saying that Anonymous is becoming more respectful, shifting out of the “otherized” world of 4chan. Is there quantitative data supporting this?

A: Biella Coleman has done the most research on this. That’s where I’ve gotten my data.

Q: How many people participated?

A: It’s been downloaded hundreds of thousands of times.

Q: When an org provides a press contact, a journalist can always orient around that, bounce off of it. But Anonymous doesn’t work that way. How does Anonymous’ play affect coverage?

A: The media doesn’t know how to deal with orgs like Anon and Occupy. They just speak with random people, none of who speak for the org (because no one does). The opening of the press IRC channel was great, for those who found it. It let the press engage at length. But Anon is usefully weird, and thus hard for the media.

Q: [me] So, will LOIC tear us apart? Civil disobedients accept consequences in part to raise the bar so that people don’t too easily break the law. LOIC lowers that bar. If Anon were attacking services that you like, would you be as sanguine?

LOIC isn’t much used now because it’s dangerous, and there are new tools. It’s hard to take down a site.

Q: As the tools get better?

A: Permanent arms race.

Q: Arrest of Sabu?

A: It won’t kill Anonymous.

Read the original blog entry...

More Stories By David Weinberger

David is the author of JOHO the blog (www.hyperorg.com/blogger). He is an independent marketing consultant and a frequent speaker at various conferences. "All I can promise is that I will be honest with you and never write something I don't believe in because someone is paying me as part of a relationship you don't know about. Put differently: All I'll hide are the irrelevancies."

@ThingsExpo Stories
"LinearHub provides smart video conferencing, which is the Roundee service, and we archive all the video conferences and we also provide the transcript," stated Sunghyuk Kim, CEO of LinearHub, in this SYS-CON.tv interview at @ThingsExpo, held November 1-3, 2016, at the Santa Clara Convention Center in Santa Clara, CA.
Internet of @ThingsExpo, taking place June 6-8, 2017 at the Javits Center in New York City, New York, is co-located with the 20th International Cloud Expo and will feature technical sessions from a rock star conference faculty and the leading industry players in the world. @ThingsExpo New York Call for Papers is now open.
"There's a growing demand from users for things to be faster. When you think about all the transactions or interactions users will have with your product and everything that is between those transactions and interactions - what drives us at Catchpoint Systems is the idea to measure that and to analyze it," explained Leo Vasiliou, Director of Web Performance Engineering at Catchpoint Systems, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York Ci...
The 20th International Cloud Expo has announced that its Call for Papers is open. Cloud Expo, to be held June 6-8, 2017, at the Javits Center in New York City, brings together Cloud Computing, Big Data, Internet of Things, DevOps, Containers, Microservices and WebRTC to one location. With cloud computing driving a higher percentage of enterprise IT budgets every year, it becomes increasingly important to plant your flag in this fast-expanding business opportunity. Submit your speaking proposal ...
WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web communications world. The 6th WebRTC Summit continues our tradition of delivering the latest and greatest presentations within the world of WebRTC. Topics include voice calling, video chat, P2P file sharing, and use cases that have already leveraged the power and convenience of WebRTC.
20th Cloud Expo, taking place June 6-8, 2017, at the Javits Center in New York City, NY, will feature technical sessions from a rock star conference faculty and the leading industry players in the world. Cloud computing is now being embraced by a majority of enterprises of all sizes. Yesterday's debate about public vs. private has transformed into the reality of hybrid cloud: a recent survey shows that 74% of enterprises have a hybrid cloud strategy.
Discover top technologies and tools all under one roof at April 24–28, 2017, at the Westin San Diego in San Diego, CA. Explore the Mobile Dev + Test and IoT Dev + Test Expo and enjoy all of these unique opportunities: The latest solutions, technologies, and tools in mobile or IoT software development and testing. Meet one-on-one with representatives from some of today's most innovative organizations
DevOps is being widely accepted (if not fully adopted) as essential in enterprise IT. But as Enterprise DevOps gains maturity, expands scope, and increases velocity, the need for data-driven decisions across teams becomes more acute. DevOps teams in any modern business must wrangle the ‘digital exhaust’ from the delivery toolchain, "pervasive" and "cognitive" computing, APIs and services, mobile devices and applications, the Internet of Things, and now even blockchain. In this power panel at @...
Data is the fuel that drives the machine learning algorithmic engines and ultimately provides the business value. In his session at Cloud Expo, Ed Featherston, a director and senior enterprise architect at Collaborative Consulting, discussed the key considerations around quality, volume, timeliness, and pedigree that must be dealt with in order to properly fuel that engine.
The WebRTC Summit New York, to be held June 6-8, 2017, at the Javits Center in New York City, NY, announces that its Call for Papers is now open. Topics include all aspects of improving IT delivery by eliminating waste through automated business models leveraging cloud technologies. WebRTC Summit is co-located with 20th International Cloud Expo and @ThingsExpo. WebRTC is the future of browser-to-browser communications, and continues to make inroads into the traditional, difficult, plug-in web co...
"A lot of times people will come to us and have a very diverse set of requirements or very customized need and we'll help them to implement it in a fashion that you can't just buy off of the shelf," explained Nick Rose, CTO of Enzu, in this SYS-CON.tv interview at 18th Cloud Expo, held June 7-9, 2016, at the Javits Center in New York City, NY.
Buzzword alert: Microservices and IoT at a DevOps conference? What could possibly go wrong? In this Power Panel at DevOps Summit, moderated by Jason Bloomberg, the leading expert on architecting agility for the enterprise and president of Intellyx, panelists peeled away the buzz and discuss the important architectural principles behind implementing IoT solutions for the enterprise. As remote IoT devices and sensors become increasingly intelligent, they become part of our distributed cloud enviro...
In 2014, Amazon announced a new form of compute called Lambda. We didn't know it at the time, but this represented a fundamental shift in what we expect from cloud computing. Now, all of the major cloud computing vendors want to take part in this disruptive technology. In his session at 20th Cloud Expo, John Jelinek IV, a web developer at Linux Academy, will discuss why major players like AWS, Microsoft Azure, IBM Bluemix, and Google Cloud Platform are all trying to sidestep VMs and containers...
SYS-CON Events announced today that MobiDev, a client-oriented software development company, will exhibit at SYS-CON's 20th International Cloud Expo®, which will take place June 6-8, 2017, at the Javits Center in New York City, NY, and the 21st International Cloud Expo®, which will take place October 31-November 2, 2017, at the Santa Clara Convention Center in Santa Clara, CA. MobiDev is a software company that develops and delivers turn-key mobile apps, websites, web services, and complex softw...
WebRTC is about the data channel as much as about video and audio conferencing. However, basically all commercial WebRTC applications have been built with a focus on audio and video. The handling of “data” has been limited to text chat and file download – all other data sharing seems to end with screensharing. What is holding back a more intensive use of peer-to-peer data? In her session at @ThingsExpo, Dr Silvia Pfeiffer, WebRTC Applications Team Lead at National ICT Australia, looked at differ...
Growth hacking is common for startups to make unheard-of progress in building their business. Career Hacks can help Geek Girls and those who support them (yes, that's you too, Dad!) to excel in this typically male-dominated world. Get ready to learn the facts: Is there a bias against women in the tech / developer communities? Why are women 50% of the workforce, but hold only 24% of the STEM or IT positions? Some beginnings of what to do about it! In her Day 2 Keynote at 17th Cloud Expo, Sandy Ca...
Fact is, enterprises have significant legacy voice infrastructure that’s costly to replace with pure IP solutions. How can we bring this analog infrastructure into our shiny new cloud applications? There are proven methods to bind both legacy voice applications and traditional PSTN audio into cloud-based applications and services at a carrier scale. Some of the most successful implementations leverage WebRTC, WebSockets, SIP and other open source technologies. In his session at @ThingsExpo, Da...
SYS-CON Media announced today that @WebRTCSummit Blog, the largest WebRTC resource in the world, has been launched. @WebRTCSummit Blog offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. @WebRTCSummit Blog can be bookmarked ▸ Here @WebRTCSummit conference site can be bookmarked ▸ Here
Manufacturers are embracing the Industrial Internet the same way consumers are leveraging Fitbits – to improve overall health and wellness. Both can provide consistent measurement, visibility, and suggest performance improvements customized to help reach goals. Fitbit users can view real-time data and make adjustments to increase their activity. In his session at @ThingsExpo, Mark Bernardo Professional Services Leader, Americas, at GE Digital, discussed how leveraging the Industrial Internet and...
Who are you? How do you introduce yourself? Do you use a name, or do you greet a friend by the last four digits of his social security number? Assuming you don’t, why are we content to associate our identity with 10 random digits assigned by our phone company? Identity is an issue that affects everyone, but as individuals we don’t spend a lot of time thinking about it. In his session at @ThingsExpo, Ben Klang, Founder & President of Mojo Lingo, discussed the impact of technology on identity. Sho...