# NY Times website hacked for 2 days--how vulnerable are we all?

**URL:** <https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431>\
**Category:** Factual Questions\
**Created:** [August 28, 2013, 7:32pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431 "2013-08-28T19:32:37Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [August 28, 2013, 7:32pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/1 "2013-08-28T19:32:37Z")

</div>

The New York Times website has been hacked by the Syrian army, and has been unusable for the past two days.( Short but serious [article describing the damage](http://www.forbes.com/sites/andygreenberg/2013/08/28/syrian-hack-of-nytimes-com-and-twitter-could-have-inflicted-much-more-than-mere-embarrassment/) ).

This isn’t a typical simple attack like a denial-of-service. The hackers got into the domain-name registration system,( at a company called Melbourne-IT), and took full control of the web site.

> [@](#):
>
> According to Melbourne IT, one of its resellers’ accounts was compromised, giving the attackers the ability to change which DNS servers resolve their clients’ sites, essentially hijacking the sites’ traffic potentially including all web traffic and email.

Mebourne-IT is a “domain registrar” company–I don’t know what that means, but I assume that they know everything about how the WWWeb works at the highest levels, and have very good security experts.

And I assume the NYTimes is a large enough entity that it has a full computer department , with in-house employees working 24 hours a day–including computer security experts.  
Yet they have been hacked and rendered helpless for the past couple days.

Now, at a news site, the amount of damage the hackers can do is limited…  
They can steal credit card info from all the website’s paying subscribers, (and they can publish fake news if they want to), but that is not the end of the world.

What worries me is : If this can happen to the NYTimes, can it also happen to, say, the large banks?  
Or what about the stock markets? etc, etc, etc  
I assume that military hardware is kept separate from us common folk who use Windows and regular web browsers, so the 1980’s movie _War Games_ was not realistic. And I suppose the same is true of major government institutions like the Fed.  
But what about the regular banks? They are open to any citizen who logs into his account from a totally unsecured computer. They presumably route their customers through companies like MelbourneIT mentioned above.  
This seems like a bad James Bond movie…  
Is there a realistic possibility that an evil genius with a cat on his lap could actually sit in his bunker and take control of major institutions? Does Citibank or Wells Fargo have better computer security than the NY Times? Could one hacker shut down an entire economy?

in short…Are we all doomed? 🙂

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [August 28, 2013, 7:40pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/2 "2013-08-28T19:40:34Z")

</div>

> [@chappachula](#):
>
> Mebourne-IT is a “domain registrar” company–I don’t know what that means, but I assume that they know everything about how the WWWeb works at the highest levels, and have very good security experts.

That is a hilariously naive assumption. There are approximately eleven billion domain registrars in the world and most of them are run by dolts.

> [@](#):
>
> And I assume the NYTimes is a large enough entity that it has a full computer department , with in-house employees working 24 hours a day–including computer security experts.  
> Yet they have been hacked and rendered helpless for the past couple days.

The NY Times has been on the verge of bankruptcy for years and has made massive cutbacks in every department, but that’s not really relevant. “They” haven’t been hacked. Their DNS provider was.

> [@](#):
>
> What worries me is : If this can happen to the NYTimes, can it also happen to, say, the large banks?

Yes, and it has.

> [@](#):
>
> Or what about the stock markets? etc, etc, etc

If you mean the actual trading platforms, its unlikely. If you mean electronic brokers, yes, and it has.

> [@](#):
>
> I assume that military hardware is kept separate from us common folk who use Windows and regular web browsers, so the 1980’s movie _War Games_ was not realistic. And I suppose the same is true of major government institutions like the Fed.

Whatever helps you sleep at night…

> [@](#):
>
> But what about the regular banks? They are open to any citizen who logs into his account from a totally unsecured computers. They presumably route their customers through companies like MelbourneIT mentioned above.

No, my feeling is most banks run their own DNS or use reputable DNS providers, but plenty of smaller banks probably don’t. In any case, bank websites can be and often are breached, either through DNS shenanigans, or simple credential phishing.

> [@](#):
>
> This seems like a bad James Bond movie…  
> Is there a realistic possibility that an evil genius with a cat on his lap could actually sit in his bunker and take control of major institutions?

No. The cat would be in the way of the keyboard.

> [@](#):
>
> Does Citibank or Wells Fargo have better computer security than the NY Times?

Citibank and Wells Fargo? Yes. Aunt Mabel’s Credit Union and Pie Shop in Peoria? Maybe.

> [@](#):
>
> Could one hacker shut down an entire economy?

No.

> [@](#):
>
> in short…Are we all doomed? 🙂

Yes.

---

<div class="post-metadata">

**Author:** ![Claverhouse](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@Claverhouse](https://boards.straightdope.com/u/Claverhouse)\
**Post date:** [August 28, 2013, 7:46pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/3 "2013-08-28T19:46:32Z")

</div>

> [@chappachula](#):
>
> Mebourne-IT is a “domain registrar” company–I don’t know what that means, but I assume that they know everything about how the WWWeb works at the highest levels, and have very good security experts.

Both of those are extremely adorable assumptions.  
Seizing the high ground of the domain registration merely entitles the attacker to redirect the address to another site — which could be an altered copy of the real thing — and means the ‘owners’ of the domain cannot control the use of that domain name: it gives no access to the site or any of it’s databases.

I would say domain-hijackers should be shot; but being in Syria that wish might be redundant.

---

<div class="post-metadata">

**Author:** ![Jonathan\_Chance](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/jonathan_chance/32/701_2.png) [@Jonathan\_Chance](https://boards.straightdope.com/u/Jonathan_Chance)\
**Post date:** [August 28, 2013, 10:13pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/4 "2013-08-28T22:13:46Z")

</div>

Yes, this is much being overblown. It wasn’t even the NYT that was hacked.

[Relevant XKCD.](http://xkcd.com/932/)

---

<div class="post-metadata">

**Author:** ![Shalmanese](https://avatars.discourse-cdn.com/v4/letter/s/45deac/32.png) [@Shalmanese](https://boards.straightdope.com/u/Shalmanese)\
**Post date:** [August 28, 2013, 11:25pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/5 "2013-08-28T23:25:20Z")

</div>

> [@Claverhouse](#):
>
> Both of those are extremely adorable assumptions.

MelbourneIT is an extremely reputable, enterprise domain registrar. The Huffington Post and Twitter also trust MelbourneIT to handle their domains. It’s not like the NYTimes got their domain from Bob’s DNS Shack.

---

<div class="post-metadata">

**Author:** ![Greg\_Charles](https://avatars.discourse-cdn.com/v4/letter/g/839c29/32.png) [@Greg\_Charles](https://boards.straightdope.com/u/Greg_Charles)\
**Post date:** [August 28, 2013, 11:38pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/6 "2013-08-28T23:38:11Z")

</div>

OK, first, the hackers are a group calling themselves the Syrian Electronic Army, not the actual Syrian army.

Second, if I’m understanding it right, they just took control of DNS servers and redirected traffic from the NYT to their own server. Imagine that someone is able to convince all the taxi drivers in NYC that the Empire State Building is in New Jersey. You hop in a cab, and, oh no! It looks to you like terrorists have destroyed the ESB and turned it into a 7/11! That’s what happened here. The NYT website was fine, but no one was able to get to it. Instead they were shunted off to the hackers site.

Incidentally, my bank, and I assume most others, send a secret confirmation back to me, based on my user name, before I enter my password. If that confirmation isn’t right, I’m not supposed to log in. That would prevent this kind of hack from compromising my account. Even if they perfectly simulated the bank’s login page, they wouldn’t know the secret confirmation.

---

<div class="post-metadata">

**Author:** ![Claverhouse](https://avatars.discourse-cdn.com/v4/letter/c/13edae/32.png) [@Claverhouse](https://boards.straightdope.com/u/Claverhouse)\
**Post date:** [August 28, 2013, 11:47pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/7 "2013-08-28T23:47:31Z")

</div>

> [@](#):
>
> MelbourneIT is an extremely reputable, enterprise domain registrar. The Huffington Post and Twitter also trust MelbourneIT to handle their domains. It’s not like the NYTimes got their domain from Bob’s DNS Shack.

Good for them.

My registrars are very well-regarded too: didn’t stop someone copying part of my then email address and tricking them into transferring a domain into their control. Took six months with ENOM to get it back. ( I also have thoughtful feelings regarding ENOM, and still more thoughtful feelings regarding ICANN, all of which are highly respected bodies that work just well enough. )  
The fact that some bastard pulled it off against MelbourneIT shows that they are no better at security than my registrars — who are admirable most of the time.

I don’t think most people realise how shaky the security foundations of the web are. Real intrusive hacking has taken place against the very strongest tech firms in recent years, including Apple, Facebook, Microsoft, Oracle and the Linux Foundation. If these can’t be utterly secure, it’s a lot to assume the average domain reseller has mad security skillz.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [August 29, 2013, 12:07am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/8 "2013-08-29T00:07:32Z")

</div>

> [@chappachula](#):
>
> This isn’t a typical simple attack like a denial-of-service. The hackers got into the domain-name registration system,( at a company called Melbourne-IT), and took full control of the web site.

Generally speaking, DNS attacks are much easier than actually hacking a company’s web server directly. Most of the time, they can be pulled of as a “social attack”. (Meaning: no computers were involved, they just called up the DNS provider and pretended to be an employee of the NYT, and the DNS provider didn’t do due diligence verifying their claim.)

> [@chappachula](#):
>
> Mebourne-IT is a “domain registrar” company–I don’t know what that means, but I assume that they know everything about how the WWWeb works at the highest levels, and have very good security experts.

That’s… quite an assumption. Not true however. See above.

> [@chappachula](#):
>
> And I assume the NYTimes is a large enough entity that it has a full computer department , with in-house employees working 24 hours a day–including computer security experts.  
> Yet they have been hacked and rendered helpless for the past couple days.

That’s… quite an assumption. Newspapers and other “offline” businesses generally have a lot of trouble recruiting competent IT help and, from my experience, many of their web operations are outsourced anyway.

In any case, that isn’t relevant, since NYT wasn’t actually hacked, their DNS provider was. Right? For all we know, the NYT servers are secured like Fort Knox.

> [@chappachula](#):
>
> Now, at a news site, the amount of damage the hackers can do is limited…  
> They can steal credit card info from all the website’s paying subscribers, (and they can publish fake news if they want to), but that is not the end of the world.

This type of attack doesn’t give the attacker any access to the company’s servers. The DNS provider is a completely different company at a completely different location running completely different servers. So unless NYT is lying about what happened, there’s no risk of data being lost.

> [@chappachula](#):
>
> What worries me is : If this can happen to the NYTimes, can it also happen to, say, the large banks?  
> Or what about the stock markets? etc, etc, etc

This type of attack can be used against anybody with a domain name. But, again, the attacker doesn’t gain any access to the company’s servers.

> [@chappachula](#):
>
> But what about the regular banks? They are open to any citizen who logs into his account from a totally unsecured computer. They presumably route their customers through companies like MelbourneIT mentioned above.

The data isn’t routed through the DNS provider. The DNS provider is like a phone book. If you use the phone book to look up the number of your local pizza place, your phone call isn’t routed through the phone book. The company that published the phone book has no way of knowing whether you like pepperoni.

> [@chappachula](#):
>
> This seems like a bad James Bond movie…  
> Is there a realistic possibility that an evil genius with a cat on his lap could actually sit in his bunker and take control of major institutions? Does Citibank or Wells Fargo have better computer security than the NY Times? Could one hacker shut down an entire economy?
> 
> in short…Are we all doomed? 🙂

No. There’s a possible that they could redirect the domain to a fake sign on page and steal login data from customers. That’s about the sum of it.

---

<div class="post-metadata">

**Author:** ![moriah](https://avatars.discourse-cdn.com/v4/letter/m/b2d939/32.png) [@moriah](https://boards.straightdope.com/u/moriah)\
**Post date:** [August 29, 2013, 2:39am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/9 "2013-08-29T02:39:29Z")

</div>

Actually, The NYTimes website is rather unsophisticated. I wouldn’t be the least bit surprised if it got hacked.

---

<div class="post-metadata">

**Author:** ![tellyworth](https://avatars.discourse-cdn.com/v4/letter/t/977dab/32.png) [@tellyworth](https://boards.straightdope.com/u/tellyworth)\
**Post date:** [August 29, 2013, 2:54am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/10 "2013-08-29T02:54:07Z")

</div>

> [@Greg\_Charles](#):
>
> Second, if I’m understanding it right, they just took control of DNS servers and redirected traffic from the NYT to their own server.

Sort of. But to be specific: it was the domain registrar that was hacked, and the domain registration records that were changed. Not DNS servers or DNS providers.

Sources: [NYT](http://news.nytco.com/2013/08/28/business/media/hacking-attack-is-suspected-on-times-web-site.html?smid=tw-nytimes) and [Twitter](http://status.twitter.com/post/59528478030/twitter-service-issue).

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [August 29, 2013, 2:54am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/11 "2013-08-29T02:54:11Z")

</div>

> [@moriah](#):
>
> Actually, The NYTimes website is rather unsophisticated. I wouldn’t be the least bit surprised if it got hacked.

Unsophisticated doesn’t necessarily mean insecure. Hosting a site full of static HTML pages eliminates a huge number of possible attack vectors, for example.

And actually the NYT employs quite a bit of interesting technology. I know some of the guys there who developed a completely custom application profiling tool, which they’ve since open-sourced. It’s very useful.

---

<div class="post-metadata">

**Author:** ![levdrakon](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@levdrakon](https://boards.straightdope.com/u/levdrakon)\
**Post date:** [August 29, 2013, 3:01am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/12 "2013-08-29T03:01:01Z")

</div>

The NYT tells me I can only read their precious articles ten times a month and than I must pay and in response I say NYT can suck me and I hope they go down in hacker flames.

Their news gets pushed to the front of my news aggregator and is not my fault. I don’t necessarily want your stuff. Go to hell, NYT.

---

<div class="post-metadata">

**Author:** ![friedo](https://avatars.discourse-cdn.com/v4/letter/f/8edcca/32.png) [@friedo](https://boards.straightdope.com/u/friedo)\
**Post date:** [August 29, 2013, 3:22am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/13 "2013-08-29T03:22:33Z")

</div>

So because you don’t like their business model, they should be the victim of a crime?

In that case I’m heading down to the Wal-Mart with my rifle in tow.

---

<div class="post-metadata">

**Author:** ![levdrakon](https://avatars.discourse-cdn.com/v4/letter/l/49beb7/32.png) [@levdrakon](https://boards.straightdope.com/u/levdrakon)\
**Post date:** [August 29, 2013, 4:18am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/14 "2013-08-29T04:18:34Z")

</div>

Oh well then I’m calling the patriot act police on you mister! See you in Gitmo!

---

<div class="post-metadata">

**Author:** ![chappachula](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@chappachula](https://boards.straightdope.com/u/chappachula)\
**Post date:** [August 29, 2013, 4:37am UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/15 "2013-08-29T04:37:54Z")

</div>

> [@Claverhouse](#):
>
> Both of those are extremely adorable assumptions.

awww,shucks, guys…I didn’t know I was so cute …  
But seriously–I know nothing about domains and how the web works, so I just really, really want to believe that there are smarter people than me who prevent the world from collapsing.

> [@](#):
>
> That is a hilariously naive assumption. There are approximately eleven billion domain registrars in the world and most of them are run by dolts

But I guess I’m wrong… 🙂

> [@](#):
>
> Seizing the domain registration merely entitles the attacker to redirect the address to another site — which could be an altered copy of the real thing. It gives no access to the site or any of its databases.

Well, that made me feel better—UNTIL I read…

> [@](#):
>
> What worries me is : If this can happen to the NYTimes, can it also happen to, say, the large banks?  
> **Yes, and it has.**
> 
> Or what about the stock markets? etc, etc, etc  
> If you mean electronic brokers,\*\* Yes, and it has.\*\*

But I suppose we are all okay…because :

> [@](#):
>
> No. The cat would be in the way of the keyboard 🙂

---

<div class="post-metadata">

**Author:** ![ftg](https://sea3.discourse-cdn.com/straightdope/user_avatar/boards.straightdope.com/ftg/32/2801_2.png) [@ftg](https://boards.straightdope.com/u/ftg)\
**Post date:** [August 29, 2013, 8:39pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/16 "2013-08-29T20:39:19Z")

</div>

Note that a DNS redirect can lead to more direct site cracking.

E.g., employees logging into “[mail.nytimes.com](http://mail.nytimes.com)” would be redirected to the attackers’ web site which is doing a man-in-the-middle thing. The attackers feed the employees pages that are basically the real pages but are intercepting the user names and passwords. (If done right, the user doesn’t see anything different.) If you get the right employees’ login info, you can really do some damage.

One interesting thing I read about the NYT attack is that employees were warned about it via email. Umm, don’t you want them to **not** use email at all, so phone messages and such would be a better idea?

Scarfing up subscriber logins would be trivial but not nearly as damaging except to reputation.

(Note that MITM attacks can also be used to fake logins at banks and stuff that have those personalized user login pics and phrases. Which can be avoided by SSL stuff, which can be avoided by spoofed certs, which …)

Also, if certain internal web pages are doing lookups for webpages using the full domain name, they could be fooled as well into going to outside sites. If the programs executing these web pages have high privileges, lots of bad things can happen.

Etc.

In short, a DNS hijack is a _very_ bad thing.

---

<div class="post-metadata">

**Author:** ![Blakeyrat](https://avatars.discourse-cdn.com/v4/letter/b/ecd19e/32.png) [@Blakeyrat](https://boards.straightdope.com/u/Blakeyrat)\
**Post date:** [August 29, 2013, 9:27pm UTC](https://boards.straightdope.com/t/ny-times-website-hacked-for-2-days-how-vulnerable-are-we-all/667431/17 "2013-08-29T21:27:26Z")

</div>

Notifying employees in the office via email _should_ be fine, unless NYT is set up very strangely, their intranet has its own DNS provider which is where their email client would look for its server.

For remote employees, who would have to engage the public DNS servers, you have a good point.
