Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

51–60 of 74 posts

Re: Ask HN: How did Dyn fail to fend off DDOS?

#51

Earlier quoted context omitted.

The code for it has been released on Github, so there are now likely to be many botnets.

I'm not too sure. I have heard that the attack also fixed the security vulnerability (changing the default root password) after installing the back door so other people cannot use it. Although the source code is out there, those will not be able to control all those devices.

I'm not sure. Maybe that's the case for the passwords which can be changed via the administrative app but I read many of these are in firmware and not able to be disabled or changed:

“The issue with these particular devices is that a user cannot feasibly change this password,” Flashpoint’s Zach Wikholm told KrebsOnSecurity. “The password is hardcoded into the firmware, and the tools necessary to disable it are not present.

- https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

That's not to say it couldn't flash the devices but I don't recall seeing that capability in the Mirai source and haven't read about it doing so.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#52
post #34

Earlier quoted context omitted.

Change the default admin password. The original Mirai program tried a little over 60 passwords and it would just brute force into an IoT device.[1] From what I read, it seems that one specific manufacturer in China is the owner of a lot of devices used in the Mirai botnet attacks.[2] 1: https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi... 2: (I cannot find the link, but it was an article from yesterday) ED…

Brian Krebs pegged a company called XiongMai: https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

That article also mentions the credentials are in the firmware.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#53

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

Security is a process. We might be able to browbeat (insert clueless-about-security manufacturer here) into making an investment in secure firmware. Maybe they'll even get it right. But our experience is that additional security holes are always found, even in software written by knowledgable and motivated teams.

These devices need to have an update mechanism. The manufacturer needs to have an ongoing security effort, across their whole device line (probably a significant investment in development resources and process -- consider that right now, the firmware for a device is probably coming off of a firmware dev's laptop; I've seen this happen at a big company). And devices will have to be sunset, to control the ongoing cost. Consumers will love that.

I don't think we're doomed, exactly, but it's probably always going to be a problem. And there's probably a market for embedded firmware application layers that don't suck, for starters.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#54
post #45
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

I think the more realistic solution is that a vigilante group of hackers continuously scan and take over vulnerable IOT boxes with the intention of bricking and/or disabling their network access would be the most feasible.

The problem with this idea is that it is illegal, and federal agents are much better at tracking people down on the Internet than they were even 5 years ago. So while I think a lot of us would cheer the vigilantes on, they would be taking a serious personal risk.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#55

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

Just eliminate default passwords completely. The first person that opens the box, or applies a license key, sets the password and it must be strong.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#56

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

Just eliminate default passwords completely. The first person that opens the box, or applies a license key, sets the password and it must be strong. Techniques are weak and even years later the bill comes due.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#57

I've been wondering if the UDP nature of a DNS server makes it harder to protect. Particularly coupled with the amplification attacks that DNS makes possible.

Yes, it does. But no, it does not seem to make any difference this one time.

In a DNS based amplification attack, you use several DNS servers to take down some other unrelated service, this time it's just a lot of devices in a botnet attacking the DNS servers directly.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#58
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

You can't litigate your way to a fix. Lots of those devices will be in parts of the world where your lawsuit can't reach. Asia, Eastern Europe, Africa. We must engineer better solutions.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#59
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

>"A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start."

Wait why is Amazon responsible? Why should they be sued?

Re: Ask HN: How did Dyn fail to fend off DDOS?

#60
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

That's a game of whack a mole, and even if you whack them down, the devices are already out there and are going to stay online for years.

The only thing that will make a dent at the problem quickly, is wholesale filtering of all Internet traffic by all network providers originating from the IP addresses identified for being part of these botnets.

Post reply on HN