Live data from Hacker News

The Mirai Botnet Was Part of a College Student Minecraft Scheme

wired.com

31–40 of 65 posts

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#31
post #29
post #27

Earlier quoted context omitted.

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

But that does not excuse knee-jerk reactions. >China or Russia would be my first guesses Why? If this is just based on it being a massive attack, then there's no basis to automatically blame China/Russia. Have you not noticed this trend? Every time there's a big attack or new strain of malware, it's always China/Russia/North Korea, and that finger pointing is before any concrete evidence? Honestly, it's xenophobic an…

> Why?

Occam's razor? If the majority of large, coordinated attacks and malware come from those countries it seems reasonable to suspect them initially, doesn't it? He said they were "guesses". He straight up told you he was speculating. That's not xenophobic, that's statistical probability.

> Even if there's a good chance it is them, should we not believe in innocent until proven guilty?

Yes, but if no speculation is allowed until after a conviction then how would anyone ever be investigated? We would never be able to accuse anyone of anything!

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#32
post #26

Earlier quoted context omitted.

Yeah, but its akin to banning drugs through the mail. Unless we open and inspect everything mailed into a country (which would be a massive make work program of the likes we've rarely seen), you can't stop it all. AliExpress, Deal Extreme and eBay are going to keep selling goods with fake CE and UL labels that are substandard, despite regulations to the contrary. If your country does need a make work program, hiring…

Sure, you can't stop all of them, but stopping 96% would be enough.

Your never going to get into the high double digits, as is most postal services have a pitiful catch rate for drugs, expanding that to cover electronics doesn't mean that catch rate will magically improve.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#33
post #27

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

While I agree with your basic premise, everybody gets things wrong sometimes, I still feel this was needles dramatization by Schneier when I read it back then.

Somebody with his experience should know better than to throw guesswork attribution haphazardly around like that (at least not without a very big disclaimer), especially in a climate that was, and still is, pretty hawkish on "cyberwar turning hot".

Because it's exactly his experience and prestige which gives the uninformed the impression that his "Russia/China" attribution was based on something solid, and not just mere guesswork without any basis on evidence at all.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#35
post #27

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

I don't want to throw more shade at Schneier than needs to be thrown, but I want to point out that you've pointed out basically two† real credentials:

* He has a masters degree.

* He wrote a bunch of popular books, and reaped a lot of fame from them.

I work, part-time, in the cryptography space his best-known books cover. His most popular book, Applied Cryptography, is not well regarded in the field. Opinions differ on Cryptography Engineering --- I like it a lot --- but he's a coauthor on that book, alongside a practicing cryptographer of significant renown. The rest of those books are non-technical.

I've worked in security since the mid-1990s, and Schneier has been a presence in the industry that whole time. And his Mirai attribution is far from the dumbest thing he's had to say.

I want to be careful because I'm sure Schneier is very good at what he's good at. My concern is that in addition to that --- without intending to be --- he's also insidiously "famous for being famous", and that his takes on things like DDoS attribution are thus taken more seriously than they should be. There are HN commenters that I think have more reliable takes on what's happening in the computer underground than Schneier.

He should write HN comments rather than pieces that get syndicated into magazines. He'd be an excellent HN commenter. :)

(You might add that he's a co-author of some well-known cipher and hash designs, and IIRC the sole author of Blowfish, his best-known design. [Don't use Blowfish.])

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#36
post #29

Earlier quoted context omitted.

But that does not excuse knee-jerk reactions. >China or Russia would be my first guesses Why? If this is just based on it being a massive attack, then there's no basis to automatically blame China/Russia. Have you not noticed this trend? Every time there's a big attack or new strain of malware, it's always China/Russia/North Korea, and that finger pointing is before any concrete evidence? Honestly, it's xenophobic an…

> Why? Occam's razor? If the majority of large, coordinated attacks and malware come from those countries it seems reasonable to suspect them initially, doesn't it? He said they were "guesses". He straight up told you he was speculating. That's not xenophobic, that's statistical probability. > Even if there's a good chance it is them, should we not believe in innocent until proven guilty? Yes, but if no speculation i…

He doesn't look silly because he guessed at a state-level attribution --- state-level attacks certainly happen. He looks silly because the attacks he chose to attribute to state actors were in fact being conducted by a small number of teenaged Minecraft players.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#37
https://www.justice.gov/opa/pr/justice-department-announces-...

FBI indictments

> JIIA further participated in a Border Gateway Protocol (BGP) hijacking scheme in which JIIA and co-conspirators fraudulently gained control over IP addresses that were in legitimate use by third parties. JIIA conducted these activities to consolidate and maximize the power of the Mirai botnet. [1]

Uhh what?

[1] https://www.justice.gov/opa/press-release/file/1017581/downl...

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#39

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

> > “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared]

> This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this.

Perhaps by being not a native speaker of English and not living in the USA I miss some cultural subtleties, but I would call Bruce Schneier's statement really cautious:

- He clearly states he does not know who is the culprit (really cautious - as it should be!)

- He clearly states that his statement is based alone on feeling

- He rather clearly outlines that his guesses for China or Russia are based on the correctness of the assumption that a national state is behind it

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#40
post #29

Earlier quoted context omitted.

But that does not excuse knee-jerk reactions. >China or Russia would be my first guesses Why? If this is just based on it being a massive attack, then there's no basis to automatically blame China/Russia. Have you not noticed this trend? Every time there's a big attack or new strain of malware, it's always China/Russia/North Korea, and that finger pointing is before any concrete evidence? Honestly, it's xenophobic an…

> Why? Occam's razor? If the majority of large, coordinated attacks and malware come from those countries it seems reasonable to suspect them initially, doesn't it? He said they were "guesses". He straight up told you he was speculating. That's not xenophobic, that's statistical probability. > Even if there's a good chance it is them, should we not believe in innocent until proven guilty? Yes, but if no speculation i…

> Occam's razor? If the majority of large, coordinated attacks and malware come from those countries it seems reasonable to suspect them initially, doesn't it?

Not really, just because attacks come from a certain country domain does not mean that said countries government is sponsoring said attacks. Even the CIA/NSA use hijacked foreign servers for their operations, that's why attribution of this stuff is so difficult.

I'd also be interested in how you define "large and coordinated attacks" because if you track by something like Norse Attack Map [0] then your Occam's Razor would suddenly point at the US, at least right now.

> Yes, but if no speculation is allowed until after a conviction then how would anyone ever be investigated? We would never be able to accuse anyone of anything!

There's a difference between "speculation" and flat out misrepresenting the probabilities. At this point, it should be pretty clear, especially to any expert in the field, that the Internet is a massive force multiplier and the regular rules of "You need big influence to have big impact" have pretty much never applied to it.

People need to account for that in their attempts at attribution instead of going the lazy route of blaming "The axis of evil" for it, which this lazy China/Russia/NK attribution basically boils down to.

[0] http://map.norsecorp.com/#/

Post reply on HN