Earlier quoted context omitted.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.
Apple's HomeKit supports Bluetooth-only devices. Seems like a good design choice right about now.
Ask HN: How did Dyn fail to fend off DDOS?
61–70 of 74 posts
Re: Ask HN: How did Dyn fail to fend off DDOS?
#62It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…
I think the more realistic solution is that a vigilante group of hackers continuously scan and take over vulnerable IOT boxes with the intention of bricking and/or disabling their network access would be the most feasible.
The vigilante hackers is for for comic books IMHO. I would trust a 3-letter gov org. Maybe the NSA would be a lot more useful if instead of breaking the internet, trying to fix it.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#63Earlier quoted context omitted.
last night the consensus was 1.2 tbps.
or 2x krebs, the 2nd? previously largest in history; we could use that or this incident as the future benchmark of ddos capacity. Attacker may have been involved with the 1.5Tb against OVH.
Ex. "I can't believe our network can't handle that traffic, it is only 20 milliKrebs!"
Re: Ask HN: How did Dyn fail to fend off DDOS?
#64It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…
Re: Ask HN: How did Dyn fail to fend off DDOS?
#65Earlier quoted context omitted.
I think the more realistic solution is that a vigilante group of hackers continuously scan and take over vulnerable IOT boxes with the intention of bricking and/or disabling their network access would be the most feasible.
The problem with this idea is that it is illegal, and federal agents are much better at tracking people down on the Internet than they were even 5 years ago. So while I think a lot of us would cheer the vigilantes on, they would be taking a serious personal risk.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#66It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…
Re: Ask HN: How did Dyn fail to fend off DDOS?
#67Earlier quoted context omitted.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.
Where's the pain-free device with open source, easily upgradeable firmware, that puts all of our IoT devices in their own private network but lets us tunnel through to them? It needs to be easy enough that our (grand)parents could pick one up on Amazon, Best Buy, or Home Depot and plug in and go...
Re: Ask HN: How did Dyn fail to fend off DDOS?
#68I wonder how much of this would be mitigated/avoided if folks would just change to something other than the default credentials on IoT devices? Is it that simple? or am I missing something?
Re: Ask HN: How did Dyn fail to fend off DDOS?
#69This attack method is hard to prevent
Re: Ask HN: How did Dyn fail to fend off DDOS?
#70Earlier quoted context omitted.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.
Where's the pain-free device with open source, easily upgradeable firmware, that puts all of our IoT devices in their own private network but lets us tunnel through to them? It needs to be easy enough that our (grand)parents could pick one up on Amazon, Best Buy, or Home Depot and plug in and go...