Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

61–70 of 74 posts

Re: Ask HN: How did Dyn fail to fend off DDOS?

#61

Earlier quoted context omitted.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Apple's HomeKit supports Bluetooth-only devices. Seems like a good design choice right about now.

Until Web Bluetooth opens those devices to exploitation from internet websites. It would be best if Bluetooth remained isolated from web browsers, but the powers that be want websites to be able to talk to them.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#62
post #45
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

I think the more realistic solution is that a vigilante group of hackers continuously scan and take over vulnerable IOT boxes with the intention of bricking and/or disabling their network access would be the most feasible.

There is shodan.io which is pretty good.

The vigilante hackers is for for comic books IMHO. I would trust a 3-letter gov org. Maybe the NSA would be a lot more useful if instead of breaking the internet, trying to fix it.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#63

Earlier quoted context omitted.

last night the consensus was 1.2 tbps.

or 2x krebs, the 2nd? previously largest in history; we could use that or this incident as the future benchmark of ddos capacity. Attacker may have been involved with the 1.5Tb against OVH.

Is Brian Krebs going to become a unit of measurement for ddos attacks? Because that would be awesome.

Ex. "I can't believe our network can't handle that traffic, it is only 20 milliKrebs!"

Re: Ask HN: How did Dyn fail to fend off DDOS?

#64
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

It sounds pretty harsh but I agree. Companies aren't going to take this stuff seriously until it really starts to hurt the bottom line. Now that politicians are starting to wake up to "the cyber" there may finally be the public will to take security seriously.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#65
post #45

Earlier quoted context omitted.

I think the more realistic solution is that a vigilante group of hackers continuously scan and take over vulnerable IOT boxes with the intention of bricking and/or disabling their network access would be the most feasible.

The problem with this idea is that it is illegal, and federal agents are much better at tracking people down on the Internet than they were even 5 years ago. So while I think a lot of us would cheer the vigilantes on, they would be taking a serious personal risk.

If they were so good at that then this wouldn't be a problem in the first place. The hackers can be in the same country as the DDOSers.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#66
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

Feels wrong to blame this on Amazon of all parties.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#67

Earlier quoted context omitted.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Where's the pain-free device with open source, easily upgradeable firmware, that puts all of our IoT devices in their own private network but lets us tunnel through to them? It needs to be easy enough that our (grand)parents could pick one up on Amazon, Best Buy, or Home Depot and plug in and go...

Most better home routers can restrict devices connecting to the internet (either through the Firewall or more comfortably configured through family filters) and offer VPNs to the internal network?

Re: Ask HN: How did Dyn fail to fend off DDOS?

#70

Earlier quoted context omitted.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Where's the pain-free device with open source, easily upgradeable firmware, that puts all of our IoT devices in their own private network but lets us tunnel through to them? It needs to be easy enough that our (grand)parents could pick one up on Amazon, Best Buy, or Home Depot and plug in and go...

If these are connected by cellular, they are given a private network that does not connect to the public internet and are in-accessible from the public internet unless the app provider explicitly chooses to do so
Post reply on HN