Live data from Hacker News

FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

techcrunch.com

1–10 of 35 posts

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#3
I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts.

Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting against the greater good? I have already called all of my senators and congressfolk, as well as written the president (for all that will do). This does not feel effective.

[1](https://www.reddit.com/r/technology/comments/6odans/fcc_now_...)

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#5
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

While I suspect the DDOS was fabricated, the linked reddit comment is flawed.

They claim that because the FCC uses Akamai as a CDN, that the FCC is immune from DDOS attacks. The FCC comment section is heavily reliant on a database, and you could simply overwhelm the database to DDOS that site. I would bet it is unlikely that the FCC utilized a cache for the queries.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#6
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

While I suspect the DDOS was fabricated, the linked reddit comment is flawed. They claim that because the FCC uses Akamai as a CDN, that the FCC is immune from DDOS attacks. The FCC comment section is heavily reliant on a database, and you could simply overwhelm the database to DDOS that site. I would bet it is unlikely that the FCC utilized a cache for the queries.

It really depends, the calls to their database wouldn't be direct, it'd be through a REST API which then communicates with a DB. That REST API likely has some sort of DDOS protection, like for example how cloudflare protects ALL requests to the domain.

But anyway, their excuse that it needs to be secret is BS, DDOS protection methods are widespread and not very secret as it is. They probably just want to keep it secret, because they don't actually have proper DDOS protection.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#7
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

While I suspect the DDOS was fabricated, the linked reddit comment is flawed. They claim that because the FCC uses Akamai as a CDN, that the FCC is immune from DDOS attacks. The FCC comment section is heavily reliant on a database, and you could simply overwhelm the database to DDOS that site. I would bet it is unlikely that the FCC utilized a cache for the queries.

"While I suspect the DDOS was fabricated, the linked reddit comment is flawed."

I too think that the DDOS is bollocks but I wouldn't go so far as to describe the reddit comment as flawed - MNGrrl presents quite a lot of additional evidence alongside the Akamai assertion. If you have some spare time it is worth reading/skimming the rest of the reddit thread. Whilst you are at it, look at the posting history of the highly rated commentators for some contextual bias hints. Follow links as well and lose a lot of time 8)

On balance the official story really does not stack up and I think a fully tooled up investigative journo could tear the FCC to pieces if given enough time and motivation to dot the Is and cross the Ts. The keyword there is motivation ...

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#8
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

As much as I would like to believe it was a government conspiracy I think the far more likely explanation was an attention starved black-hat taking advantage of an incompetent government website.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#9
post #6

Earlier quoted context omitted.

While I suspect the DDOS was fabricated, the linked reddit comment is flawed. They claim that because the FCC uses Akamai as a CDN, that the FCC is immune from DDOS attacks. The FCC comment section is heavily reliant on a database, and you could simply overwhelm the database to DDOS that site. I would bet it is unlikely that the FCC utilized a cache for the queries.

It really depends, the calls to their database wouldn't be direct, it'd be through a REST API which then communicates with a DB. That REST API likely has some sort of DDOS protection, like for example how cloudflare protects ALL requests to the domain. But anyway, their excuse that it needs to be secret is BS, DDOS protection methods are widespread and not very secret as it is. They probably just want to keep it secr…

> But anyway, their excuse that it needs to be secret is BS, DDOS protection methods are widespread and not very secret as it is. They probably just want to keep it secret, because they don't actually have proper DDOS protection.

This.

At what point did the government become a special interest group which does not exist to protect the nation it serves? Providing good security advice is their job.

Even if they do have some super secret techniques, keeping them secret is not a strategy, it's what idiots who don't know anything about technology or computers or network security would do.

I would trust Cloudflare's staff over the FCC's I.T. department every day of the week, and I hate Cloudflare.

Post reply on HN