I'm a little confused. "We actually like this company..." So why did they do this? I'd think the thing to do after finding an exploit would be to notify who has it and give them a reasonable amount of time to correct the problem. I think I'm confused about what LulzSec is all about.
Honestly, my guess is that LulzSec is a bunch of crackers that have decided to do something about the public perception of information security. It's kind of a stretch (understatement), but it lines up. They attack indiscriminately, and in every case make fun of any idiotic security practices. When they attack targets that everybody loves to hate, they do as much damage as possible; when they attack targets that everybody loves, they don't release admin passwords or user DBs, they inform the target of their vulnerabilities, and they generally try to be a service to the community. Most importantly, they're trying to make the entire thing /glamorous/. They want people fifty or a hundred years from now to look back on crackers and Anonymous the same way we look back on cowboys, ninjas, and pirates.
They are essentially defacers, though instead of (just) defacing they go for a press release / dox drop. Defacers do it for the attention. You'll often see reasoning on defaced websites such as "We did it for the glory of Iran" or "Maybe you should secure your users data better!" as if to suggest a greater purpose for the actions, but when you string together all of their targets the reasoning almost always falls flat.
Lulzsec may have given some people the wrong impression by hitting Sony and thus suggesting that they were activist minded like the AnonOps program they grew out of, but they'd always been honest about the real reason from day one: "we do it for the lulz". The lulz in this case are inexorably intertwined with the attention seeking.
It's their namesake. Doing something "for the lulz" is a descendent of 4chan, meaning that you do something with no regard for who it affects or what your relationship with them is, purely for entertainment purposes.
They are a bunch of script kiddies with no professional ethic whatsoever. They also try to get credit for things they haven't even done (e.g., bitcoin temporary crash). In short, ignoring them is the right way to go. HN sucks up to them instead and gives them exposure. Just sad, really.
Either they're incompetent script-kiddies and the fault lies with the admins with unpatched servers, or they are competent and have access to, or have written undisclosed exploits. There is no middle ground, and unless you have some information that we do not, there's no reason to conclude that they are script kiddies. Being mischievous and being intelligent are not mutually exclusive.
>In short, ignoring them is the right way to go. HN sucks up to them instead and gives them exposure. Just sad, really.
It is a noteworthy news event when high profile sites are hacked, regardless of the perpetrators. There are a whole ton of people who use HN to follow tech news.
I'd even go so far as to say a daily streak gets more newsworthy the higher it gets. Have we ever seen a group in the past that hit this many companies in so short a time?