IP-WARS.NET - a forward command post of the IP Wars
create account| Front Page|Mission|Standard Operating Procedures|Operating Instructions(aka FAQ's)|Privacy Policy|Site Stats/Info|Admin Actions|Search
Sections:General|IP|SCO v World |Microsoft|grok*/OSRM|IPW Site Meta|Logbooks|Diaries|Legal Documents|View All Articles
Display: Sort:
RFC: Incorporating IPW | 119 comments (109 topical, 10 editorial, 1 hidden)
Attacking IPW (4.33 / 6) (#16)
by heimdal31 (heimdal31_ip_warsNO@SPAM.threenorth.com) on Mon Sep 12th, 2005 at 21:46:57 EST
(User Info) http://www.threenorth.com/sco
I suppose that I'm approaching this from a network security standpoint.  Given the different approaches, how would I, as a well-funded attacker, attempt to take the site down.  Let me say, that I like the idea and doing it in the F/OSS tradition of being open about the problems so you can deal with a number of potential ones before they occur.

I'd appreciate if others could add to the list.  I think it is similar to some of the things that we did when deciding how to moderate, what license to use and other policies when first setting it up and wanting to insure that certain things did not happen.

Ways to attack a corporate structure:

  1. Make IPW a living hell to deal with because of the trolls.  (Look what one or two dedicated, unpaid individuals were able to do).  Then, buy out the shares of the top holders.  Voila.  Instant control.

  2. If it is still possible to add new corporate members, then buy up enough shares, distributed amongst enough different people, to kick it over the 3?? shareowners threshold that forces the company public and subject to a slew of additional regulations and accounting issues.  That may take longer, but it will suck funds out of the coporation pretty darn quickly.

  3. Sleepers who eventually begin posting clearly copyrighted material which cause legal attacks from more than one well-funded opponent.

  4. I'm sure I could find a patent or two that the site violates.

  5.  Variation of 1.  Just take it over.  Look what we did to the Yahoo SCOX and CKX boards.  If a large enough group of posters wanted to, they could easily take it over to the point where sharholders may own shares and be paying for it all, but they have no control.  It needn't even be a troll attack.  It could be hijacked for some other legitmate cause that most of us care little about or that most of us will end up on different sides of.  At that point, I can see people perhaps selling their shares in disgust.

I'm repeating here what I said in a comment that ColonelZen quoted, but if we go the corporat route, we need to make it so that we have a large number of shareholders and that it takes a significant subset of those to reach a majority.  I don't know how we do that.  Colonel if you and Dio each toss in a thousand and I toss in a hundred, it will take twenty one of me to get more votes than the two of you.  Now, I happen to think that I'd vote with the two of you on most issues, so when we are talking you and Dio, it doesn't bother me that much, particularly if you and Dio together only represented 20%.  However, if you, Dio and two others were more than 50%, I would worry.

Given that we are unlikely to make money, how do we raise funds after the initial stake is gone?  Will we continually issues shares year after year?  (If so, see problem 2.)  It's not even like we get enough page views that we can sell ads--which I'd hate to see anyway.

Distributed structure attack:

  1.  see 3 above.  Post clear copyright violations.

  2.  see 4 above.  Patent suit against each node.

  3.  likely attacks on any synchronization protocol.  (What happens if I publish simultaneous comments at all nodes?  How do the nodes authenticate their content?  Can I break into that and poison it all?  How do they authenticate passwords?  Can I own one node, leave it alone and get enough info to then impersonate any poster--and with the distributed nature, disproving that it was you that posted could be very difficult.)

  4. Volunteer to host a node and then try some of the tricks in 3.

Other random questions:

Who gets access to the logs?  I'm serious.  I've been fascinated at what I can glean looking at the threenorth logs.  I don't publicize that except maybe a hit or two in an e-mail.  You can't let every shareholder access them, because that would effectively be no privacy whatsoever, which will drive many away.  Someone else suggested not logging IPs at all, but you may need them if you ever get a DDOS attack--or if someone does cross a legal line.

Who makes decisions that may require more than zero ratings?  Jeff has nuked spam posts.  He has removed a few truly obnoxious posts and/or diary.  If you have a copyright violation, you need to react quickly.  Some one or ones will need to be empowered to do that.  Who?  Who watches the watchers?  Can shareholders recind a decision if fifty percent disagree?

How do you count votes, if you are going to have shareholders involved in the day to day running?  I mean, in normal shareholder meetings, you announce the meeting, send out proxies, require a quorum the majority of the quorum carries the day.  If you are talking more than annual meetings, how far in advance must they be announced?  What happens when someone gets disinterested and simply leaves?  What happens if too many do and you can't get a quorum?  (Is that attack number 6?)

I know there are more.  If you're serious, you need to start thinking about these situations and how to answer them, because I don't expect too many people to plop down more than beer money until these and other issues are more clear.

---Tim Rushing

  • Re: Attacking IPW by ColonelZen, 09/12/2005 23:23:30 EST (4.00 / 5)
  • Re: Attacking IPW - site control by ColonelZen, 09/12/2005 23:42:28 EST (4.00 / 6)
  • Re: Attacking IPW by pgk, 09/13/2005 02:35:58 EST (4.00 / 7)
    • Re: Attacking IPW by ColonelZen, 09/13/2005 09:51:42 EST (4.00 / 6)
  • Re: Attacking IPW - Troll problem by ColonelZen, 09/12/2005 22:41:01 EST (3.83 / 6)
  • Re: Attacking IPW - control of ownership by ColonelZen, 09/12/2005 22:59:22 EST (3.83 / 6)
    • Re: Attacking IPW - control of ownership by heimdal31, 09/13/2005 00:00:48 EST (4.00 / 5)
  • Re: Attacking IPW by deepdistrust, 09/13/2005 20:43:45 EST (3.83 / 6)
    • Re: Attacking IPW by codswallet, 09/14/2005 00:17:21 EST (3.85 / 7)
      • Re: Attacking IPW by heimdal31, 09/14/2005 21:47:03 EST (3.80 / 5)
        • Re: Attacking IPW by codswallet, 09/15/2005 09:33:52 EST (4.16 / 6)
      • Re: Attacking IPW by deepdistrust, 09/15/2005 00:27:43 EST (3.50 / 6)
        • Re: Attacking IPW by ColonelZen, 09/15/2005 09:08:30 EST (3.85 / 7)
        • Re: Attacking IPW by codswallet, 09/15/2005 10:54:51 EST (3.83 / 6)
          • Re: Attacking IPW by deepdistrust, 09/15/2005 14:51:50 EST (3.85 / 7)
            • Re: Attacking IPW by codswallet, 09/16/2005 18:43:10 EST (3.71 / 7)

RFC: Incorporating IPW | 119 comments (109 topical, 10 editorial, 1 hidden)
Display: Sort:

Links

Firefox 2

Use OpenOffice.org

Add to Technorati Favorites

Join EFF Today

ToTehMoon web site button

~ Merkey v The Internet et al Docs
~ Yahoeuvre
~ tuxrocks.com (SCO cases legal docs)
~ scofacts.org
~ eagle.petrofsky.org
~ Zen's Den
~ Yahoo SCOX Message Board
~ Lamlaw
~ Microsoft Watch
~ Groklaw
~ Korgwal - a Groklaw mirror
~ nosoftwarepatents.com
~ Flame Warriors
~ SCOXE Wars
~ Get your Merkey Number here!
~ Digital Law Online

Recent Comments

Breaking News and External Article Comments
General News – General Articles
by ColonelZen, January 5
60 comments
» SCO Lifeboat List from Stats_for_all – AncientBrit, May 6
» Not a single comment on the Novell... – sphealey, Jul 22
» Re: Not a single comment on the Novell... – AncientBrit, Aug 8

Eagle Loses Appeals
General News – General Articles
by JCausey, December 15
1 comment
» Re: Eagle Loses Appeals – br3n, Jan 7

The Chinese Room Revisited, Thoughts on...
General News – Diary
by ColonelZen, November 24
1 comment
» Re: The Chinese Room Revisited,... – ColonelZen, Nov 24

How to Transition a Windows Shop to Linux
General News – General Articles
by JCausey, November 21
3 comments
» Re: How to Transition a Windows Shop to... – ColonelZen, Nov 22
» Re: How to Transition a Windows Shop to... – JCausey, Nov 23
» Re: How to Transition a Windows Shop to... – ColonelZen, Nov 23

Advocacy
General News – Diary
by br3n, October 29
3 comments
» Re: Advocacy – br3n, Nov 2
» Re: Advocacy – ColonelZen, Nov 2
» Re: Advocacy – br3n, Nov 4

Very Bad News for Darl and Ralph
SCO v The World – Diary
by ColonelZen, October 13
7 comments
» Re: OT advocacy – br3n, Oct 26
» Re: OT advocacy – JCausey, Oct 28
» Re: OT advocacy – br3n, Oct 29

Some SCOX Financial Analysis
SCO v The World – SCO Related Articles
by JCausey, September 21
13 comments
» Re: Some SCOX Financial Analysis – br3n, Oct 3
» Re: Some SCOX Financial Analysis – ColonelZen, Oct 3
» Re: Some SCOX Financial Analysis – br3n, Oct 6

Open Source in Education - Opening Doors
General News – General Articles
by JCausey, September 28
1 comment
» Re: Open Source in Education - Opening... – br3n, Sep 29

An IPOWER ful experience
General News – Diary
by ColonelZen, September 25
6 comments
» IPOWER SysAdmin Doesn't Do Weekends!! – ColonelZen, Sep 29
» Re: An IPOWER ful experience – ColonelZen, Sep 29
» Re: An IPOWER ful experience – ColonelZen, Sep 29

Learning C#
Microsoft – Diary
by ColonelZen, September 23
1 comment
» Re: Learning C# – ColonelZen, Sep 23

Comment search...

Recent Diaries

SCO has a Potential and Credible BILLION Dollar Liability
by ColonelZen - March 15

The Chinese Room Revisited, Thoughts on Consciousness
by ColonelZen - November 24
1 comment


Advocacy
by br3n - October 29
3 comments


An IPOWER ful experience
by ColonelZen - September 25
6 comments


Learning C#
by ColonelZen - September 23
1 comment


Getting ruby DBI for Mysql and Postgresql working on FC 6
by ColonelZen - March 7

Declaration of Linus Torvalds
by nedu - February 13
1 comment


Declaration of M. Douglas McIlroy
by nedu - February 12
6 comments


Declaration of Ulrich Drepper
by nedu - February 11
1 comment


Declaration of K. Y. Srinivasan
by nedu - February 11


More Diaries...

Login

Make a new account

Username:
Password:

SourceForge Logo Powered by Scoop

All trademarks and copyrights on this page are owned by their respective companies or owners.
Comments, articles and logbooks are owned by the Poster. By posting on the ip-wars.net web site, all posters grant a license to ip-wars.net to publish the content and release it pursuant to the Creative Commons License that covers the rest of the site. For more details, please check out the Standard Operating Procedures. Also, please read the Privacy Policy for the site. Finally, DO NOT send e-mail to the site owner (Jeff Causey) unless you have read and agree to the terms regarding e-mail included in the Standard Operating Procedures.
Everything else © 2004, 2005, 2006, 2007 ip-wars.net and Jeffrey G. Causey and is licensed under a
Creative Commons License
This work is licensed under a Creative Commons License.