Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

71–74 of 74 posts

Re: Ask HN: How did Dyn fail to fend off DDOS?

#71
post #55

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

Just eliminate default passwords completely. The first person that opens the box, or applies a license key, sets the password and it must be strong.

Yes. But keep in mind that these where in part maintenance accounts not visible to users. The areas that also need to be kept in mind are manufacturing, maintenance, repair and upgrades.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#72
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

>"A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start." Wait why is Amazon responsible? Why should they be sued?

They sell lots of the garbage, and have a track record of ignoring supply chain issues.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#73
post #55

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

Just eliminate default passwords completely. The first person that opens the box, or applies a license key, sets the password and it must be strong.

A better solution is for each physical instance of a device to have a default password that is strong and unique (and encoded in the firmware, such that a factory reset of the device doesn't make it default to a non-unique PW).

There are a few other ways to handle the problem of securing endpoint devices. For example, for devices that are intended to use a local aggregator, gateway, or proxy of some sort you can get around the issue (and improve the UX) by avoiding passwords entirely, and requiring that the device instead be paired with a base station through a physical action the user performs (pressing a button on both, knocking them together, etc.) instead.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#74
post #65

Earlier quoted context omitted.

The problem with this idea is that it is illegal, and federal agents are much better at tracking people down on the Internet than they were even 5 years ago. So while I think a lot of us would cheer the vigilantes on, they would be taking a serious personal risk.

If they were so good at that then this wouldn't be a problem in the first place. The hackers can be in the same country as the DDOSers.

But then wouldn't they be better off doing DDOSing for hire? Just a thought
Post reply on HN