Live data from Hacker News

FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

techcrunch.com

11–20 of 35 posts

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#11
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

While I suspect the DDOS was fabricated, the linked reddit comment is flawed. They claim that because the FCC uses Akamai as a CDN, that the FCC is immune from DDOS attacks. The FCC comment section is heavily reliant on a database, and you could simply overwhelm the database to DDOS that site. I would bet it is unlikely that the FCC utilized a cache for the queries.

Like a dude in a Starbucks on free wifi and a script?

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#12
It's ok, we got Barron and Ajit on it, they're geniuses at the cyber.

In all seriousness, my research following the DDOS/astro-turfing campaign led me to at least some of the astro-turfing being the result of efforts by the Center for Individual Freedom[0] a far right-wing political operation masquerading as a non-profit.

There's an entire shadowy layer of questionable "public advocacy" groups out there tied to unquestionably partisan organizations. And sometimes even the political parties themselves.

The Center for Individual Freedom for example has received monies from Crossroads GPS[1], which is Karl Rove's umbrella organization for disbursing funds raised nationally to further the extreme agenda of the American right-wing and its financial backers, whether that be Putin or the Kochs.

[0]://cfif.org

[1]://www.motherjones.com/politics/2012/04/karl-rove-crossroads-gps-center-individual-freedom/

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#13
Well one way to tell would be to DDoS the FCC and see if it works. But of course they likely don't have anything and are just covering up their fictitious story with gobbledegook. Proving they were DDoS'd by showing evidence of the attack would in no way affect how they protect against it. But then they know that.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#16
post #2

Because obscurity is the best security!... right? FCC knows what's best for everyone.

Isn't DDOS mitigation an area where obscurity is the standard? I am no expert on this but it seems like most providers keep the info about how they filter traffic pretty close to the chest.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#17
post #6

Earlier quoted context omitted.

It really depends, the calls to their database wouldn't be direct, it'd be through a REST API which then communicates with a DB. That REST API likely has some sort of DDOS protection, like for example how cloudflare protects ALL requests to the domain. But anyway, their excuse that it needs to be secret is BS, DDOS protection methods are widespread and not very secret as it is. They probably just want to keep it secr…

> But anyway, their excuse that it needs to be secret is BS, DDOS protection methods are widespread and not very secret as it is. They probably just want to keep it secret, because they don't actually have proper DDOS protection. This. At what point did the government become a special interest group which does not exist to protect the nation it serves? Providing good security advice is their job. Even if they do have…

Not only that, in what way does an independent agency having zero ties to national security or the IC have any right to hold just about* anything secret? This is asinine!

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#18
post #3

I really liked [1]this comment on reddit illustrating evidence that not only was there no cyber attack on the FCC, but that it also self-orchestrated its supposed "DDOS." Curious HN's thoughts. Realistically (or perhaps otherwise), what can Americans without enough money to lobby individually, do to prevent the FCC acting against our greater good, especially in the face of evidence that they are maliciously acting ag…

As much as I would like to believe it was a government conspiracy I think the far more likely explanation was an attention starved black-hat taking advantage of an incompetent government website.

Exactly my thoughts: Don't assume malice when stupidity is an adequate explanation.

https://en.m.wikipedia.org/wiki/Hanlon%27s_razor

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#19
post #16
post #2

Because obscurity is the best security!... right? FCC knows what's best for everyone.

Isn't DDOS mitigation an area where obscurity is the standard? I am no expert on this but it seems like most providers keep the info about how they filter traffic pretty close to the chest.

Not really; no. DDOS mitigation is actually a pretty standard bag of tricks. Cloudflare describes their setup in pretty deep detail via engineering docs. Technically you might have to talk to their sales people to get them, but that's more to fill their sales pipeline than anything.

Re: FCC says its cybersecurity measures to prevent DDoS attacks must remain secret

#20

Translation: their protection is bad and they don't want to reveal its mediocrity publicly, or there was no attack.

My guess is both. The actual volume of semi-automated (there were a few canned form submission tools) negative feedback may have resulted in a DOS (due to unexpected volume), and the mitigation was probably just to write it to /dev/null.
Post reply on HN