Live data from Hacker News

The Mirai Botnet Was Part of a College Student Minecraft Scheme

wired.com

11–20 of 65 posts

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#11
> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared]

This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption?

I don’t understand why every single cyberattack is immediately blamed on Russia or China. It’s an intellectual embarrassment, and especially worse when it’s coming from experts within the community rather than politicians in congress.

But I’m sure the DNC hack was the work of an advanced nation state. Probably had nothing to do with sharing passwords like runner123 over email...

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#12
post #10
post #6

Earlier quoted context omitted.

At least in Germany, it's illegal to leave your car door unlocked. (Not sure about house doors.) The rationale is that it invites crime.

I didn't know that. Is it possible, then, that a person who leaves their door unlocked is punished while the person who stole and dumped the car is not?

And is that not a classic case of victim blaming?

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#14
post #4

Why do these kinds of investigations only ever stop at the perpetrator of the attack? In rushing to market, these IoT companies pushed out a defective, insecure product. Such an attack would not be possible without vulnerable hosts to hijack, so why aren't the IoT hardware companies investigated or fined?

Its not illegal to leave your door unlocked.

Maybe not, but the insurance will shrug at you if you make a claim for theft.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#15
post #9
post #5

Earlier quoted context omitted.

>so why aren't the IoT hardware companies investigated or fined? By whom? Where do you imagine these devices are made / manufactured?

By the police. >Where do you imagine these devices are made / manufactured? It doesn't matter. If Chinese, Thai, US, Spanic or Russian company wants to sell their device in Europe they have to comply to CEER (Council of European Energy Regulators) regulations, we need similar regulating body for software. Since we have lamps and phone chargers that don't blow power sockets and don't burn houses, we need software that…

Are you sure about that last claim? There's a huge load of substandard, fake or not certified electrics coming in, also thanks to big online webshops that send directly to consumers. And the consumers don't care, they have a basic expectation of quality and no idea of things like electrical safety, fire risks or RF emissions.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#16
post #10
post #6

Earlier quoted context omitted.

At least in Germany, it's illegal to leave your car door unlocked. (Not sure about house doors.) The rationale is that it invites crime.

I didn't know that. Is it possible, then, that a person who leaves their door unlocked is punished while the person who stole and dumped the car is not?

Wtf, no. The person stealing the car is of course punished as a thief. (Unless he doesn't get caught, obviously.)

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#17
If IoT botnets become more prevalent (and it doesn't seem like IoT makers have incentives to make their devices more secure), I wonder if ISPs will just start monitoring the traffic patterns of their customers for possible DDoS activity and possibly throttle or cut off their internet connection to stop the attack at its source. Probably would even be compatible with most net neutrality regulations around the world, since it's a security issue.

You could probably hide DoS traffic from a single device by making it very low volume, but if the ISPs coordinate, they still know that the device recently sent packets to a victim of a DDoS attack, making it suspicious.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#18
post #9

Earlier quoted context omitted.

By the police. >Where do you imagine these devices are made / manufactured? It doesn't matter. If Chinese, Thai, US, Spanic or Russian company wants to sell their device in Europe they have to comply to CEER (Council of European Energy Regulators) regulations, we need similar regulating body for software. Since we have lamps and phone chargers that don't blow power sockets and don't burn houses, we need software that…

Are you sure about that last claim? There's a huge load of substandard, fake or not certified electrics coming in, also thanks to big online webshops that send directly to consumers. And the consumers don't care, they have a basic expectation of quality and no idea of things like electrical safety, fire risks or RF emissions.

I read recently that a guy in Poland had his Bitcoin miners Antminers worth 100k USD confiscated at the border check because it was not certified, it didn't have CEER labels: https://translate.google.com/translate?sl=auto&tl=en&js=y&pr...

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#19

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

I think a lot of the speculation was based on the initial size of the attack (620-665gbps).

https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#20
post #8
post #4

Earlier quoted context omitted.

Its not illegal to leave your door unlocked.

It is in some countries. The logic is: if you lock your car, it is harder to steal. If it's stolen because you left it open, it's your fault and you pay for police time and investigation. If a policeman sees your car unlocked they can give you a ticket for leaving that way.

What about those of us that don't want our car window bashed in by some crackhead cause the door is locked? I'd much rather lose a few ones and tens in my coin drawer than buy a new window.
Post reply on HN