Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Understanding the Christmas Attacks on Xbox, PlayStation Networks

What is a “denial of service” attack, and what’s the point?

If you unwrapped a new Xbox or PlayStation game console on Christmas, you probably know by now that Microsoft’s and Sony’s respective online networks have been struggling since yesterday morning.

https://twitter.com/XboxSupport/status/548201960961097728

https://twitter.com/PlayStation/status/548128782671183872

These “denial of service” attacks are not only a problem for people who want to play a multiplayer game online. They also affect anyone trying to register a new account, buy games or use media apps to stream movies and music from the Web. Unlike the recent more sophisticated hack attack at Sony Pictures, the goal appears to be to cause mayhem and headaches for Microsoft and Sony rather than to steal private data or achieve a political goal.

At the time of this writing, Xbox Live is back “up and running” while the PlayStation Network is still “offline.” But what causes this sort of downtime, and why?

It might help to understand what a “denial of service” attack is. I asked cybersecurity researcher Cameron Camp to explain back in August when an anonymous online hacking group called Lizard Squad first targeted PlayStation:

“At the most basic level, it’d be like someone calling your phone 2,800 times and you’re going, ‘Leave me alone, leave me alone, leave me alone,’” Camp said. “When they’re flooding your phone, you can’t get other phone calls. The idea is, what if we could trick other computers into all robot-calling your phone? Now you really can’t take a phone call.”

To “weaponize” this sort of attack, Camp said, hackers can pay to rent computers that have been infected with malware and point them at the same target. Companies like Microsoft and Sony then have to find ways to weed out the bad “phone calls,” often by paying a third-party company to accept all the rerouted requests, filter them and route only the good ones back to the source.

Denial of service attacks are, like a rock thrown through a window, unsophisticated but effective at causing a mess. Unlike the supposedly politically motivated attack on Sony Pictures (which the FBI pinned on North Korea), the closest apparent thing to a goal here is temporary cyber-anarchy.

As in August and in other attacks since, Lizard Squad has taken credit for the downtime on both consoles. In tandem with one of its earlier attacks on the PlayStation Network, the group tweeted a bogus bomb threat against an airplane carrying a Sony executive.

In a strange twist to the latest attacks, Mega founder Kim Dotcom is taking credit for helping to stop them. In order to play the online shooter game Destiny on Xbox Live, he claims to have transferred 3000 premium vouchers to his latest cloud storage website to the hacker group, which thanked him and said it would stop.

https://twitter.com/KimDotcom/status/548264349760901120

https://twitter.com/KimDotcom/status/548275217320001536

https://twitter.com/LizardMafia/status/548329364417708033

I’ve reached out to Sony for further comment. A Microsoft spokesperson shared the following statement:

“Yesterday, some users were unable to sign in to Xbox Live. Our teams worked throughout the holiday to resolve the issue, and Xbox Live core services have now been restored.”

This article originally appeared on Recode.net.

More in Technology

Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander
Life
Why banning kids from AI isn’t the answerWhy banning kids from AI isn’t the answer
Life

What kids really need in the age of artificial intelligence.

By Anna North
Culture
Anthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque messAnthropic owes authors $1.5B for pirating work — but the claims process is a Kafkaesque mess
Culture

“Your AI monster ate all our work. Now you’re trying to pay us off with this piece of garbage that doesn’t work.”

By Constance Grady
Future Perfect
Some deaf children are hearing again because of a new gene therapySome deaf children are hearing again because of a new gene therapy
Future Perfect

A medical field that almost died is quietly fixing one disease at a time.

By Bryan Walsh