Live data from Hacker News

The Mirai Botnet Was Part of a College Student Minecraft Scheme

wired.com

41–50 of 65 posts

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#41

"young American computer savants" Ah so Mum or Dad paid a doctor to diagnose them as autistic after the fact.

What does autism have to do with it?

Maybe because the word savant was used which is oftentimes used to describe a smart person with autism.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#42

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

I think a lot of the speculation was based on the initial size of the attack (620-665gbps). https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...

Right. The problem is the premise that it would take a state-level adversary to generate that kind of traffic, and not a single-digit number of disgruntled teenaged Minecraft players.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#43

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

Wired is misusing that quote, since it does not pertain to Mirai specifically, but to cyberwarfare in general.

Here's the source titled "Someone Is Learning How to Take Down the Internet", dated September 2016:

https://www.schneier.com/blog/archives/2016/09/someone_is_le...

The source paragraph does not mention Mirai at all (nor does the article):

> Over the past year or two, someone has been probing the defenses of the companies that run critical pieces of the Internet. These probes take the form of precisely calibrated attacks designed to determine exactly how well these companies can defend themselves, and what would be required to take them down. We don't know who is doing this, but it feels like a large nation state. China or Russia would be my first guesses.

You should actually read the whole article to get a sense of where he is coming from.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#44
post #29
post #27

Earlier quoted context omitted.

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

But that does not excuse knee-jerk reactions. >China or Russia would be my first guesses Why? If this is just based on it being a massive attack, then there's no basis to automatically blame China/Russia. Have you not noticed this trend? Every time there's a big attack or new strain of malware, it's always China/Russia/North Korea, and that finger pointing is before any concrete evidence? Honestly, it's xenophobic an…

This is not as much about xenophobia (as xenophobic as USA is) but about not having an egg on your face.

Companies seems to love to throw "state sponsored" around because it sounds better to imply that you were so secure that only North Korea, Russia or China had a chance and at that level of attack (by such a state that openly challenges USA so often) it's not your fault you got breached because it's implied everyone would be. Equifax ran outdated Apache Struts for a few days after a patch and information about the vulnerability was out and now China is being pointed at with really flimsy (IMO) evidence[0].

On the other hand no one probably wants to defend China, North Korea and Russia and it sounds much cooler to be fighting against their state hackers than script kiddies and saying that all these "high profile state attacks" were script kiddies is basically shitting on the security industry in a way.

[0] - http://www.dailymail.co.uk/news/article-4937010/Clues-sugges...

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#45

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

Wired is misusing that quote, since it does not pertain to Mirai specifically, but to cyberwarfare in general. Here's the source titled "Someone Is Learning How to Take Down the Internet", dated September 2016: https://www.schneier.com/blog/archives/2016/09/someone_is_le... The source paragraph does not mention Mirai at all (nor does the article): > Over the past year or two, someone has been probing the defenses of…

Yes, but still. I read the article when it was first published and felt it was the usual "evil communism" bs (which I honestly wouldn't have expected from Mr. Schneider), and this time around we actually got a definite answer proving these kind of claims wrong. Nowadays every time some news pop up revolving around cyber attacks more sooner than later someone points at China or Russia, with some very vague evidence at best. "Oh, we found a Russian text string embedded in the binary, it MUST have been written by the Russian government."

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#46
post #35
post #27

Earlier quoted context omitted.

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

I don't want to throw more shade at Schneier than needs to be thrown, but I want to point out that you've pointed out basically two† real credentials: * He has a masters degree. * He wrote a bunch of popular books, and reaped a lot of fame from them. I work, part-time, in the cryptography space his best-known books cover. His most popular book, Applied Cryptography, is not well regarded in the field. Opinions differ…

Thanks for the perspective. How would you classify him if ranked against the other usual high profile “security personalities?”. Often an individuals ability for self promotion can place a shadow over their true ability making it difficult to discern their true qualities when not a subject matter expert on the topic at hand.

On the book front, would be keen to gain your perspective on the following crypto book that was recently published -

https://www.nostarch.com/seriouscrypto

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#47
post #35
post #27

Earlier quoted context omitted.

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

I don't want to throw more shade at Schneier than needs to be thrown, but I want to point out that you've pointed out basically two† real credentials: * He has a masters degree. * He wrote a bunch of popular books, and reaped a lot of fame from them. I work, part-time, in the cryptography space his best-known books cover. His most popular book, Applied Cryptography, is not well regarded in the field. Opinions differ…

"There are HN commenters that I think have more reliable takes on what's happening in the computer underground than Schneier."

Can you name them?

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#48
post #46
post #35

Earlier quoted context omitted.

I don't want to throw more shade at Schneier than needs to be thrown, but I want to point out that you've pointed out basically two† real credentials: * He has a masters degree. * He wrote a bunch of popular books, and reaped a lot of fame from them. I work, part-time, in the cryptography space his best-known books cover. His most popular book, Applied Cryptography, is not well regarded in the field. Opinions differ…

Thanks for the perspective. How would you classify him if ranked against the other usual high profile “security personalities?”. Often an individuals ability for self promotion can place a shadow over their true ability making it difficult to discern their true qualities when not a subject matter expert on the topic at hand. On the book front, would be keen to gain your perspective on the following crypto book that w…

Serious Crypto is strong, and JP Aumasson is the real deal. I might still want both Cryptography Engineering and Serious Crypto; Serious Crypto is far more detailed and up-to-date, but Cryptography Engineering has valuable perspective on a lot of nuts-and-bolts stuff.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#49
post #48
post #46

Earlier quoted context omitted.

Thanks for the perspective. How would you classify him if ranked against the other usual high profile “security personalities?”. Often an individuals ability for self promotion can place a shadow over their true ability making it difficult to discern their true qualities when not a subject matter expert on the topic at hand. On the book front, would be keen to gain your perspective on the following crypto book that w…

Serious Crypto is strong, and JP Aumasson is the real deal. I might still want both Cryptography Engineering and Serious Crypto; Serious Crypto is far more detailed and up-to-date, but Cryptography Engineering has valuable perspective on a lot of nuts-and-bolts stuff.

Great! That’s all I need to hear - will place an order.

Re: The Mirai Botnet Was Part of a College Student Minecraft Scheme

#50
post #27

> “We don’t know who is doing this, but it feels like a large nation-state. China or Russia would be my first guesses.” [Bruce Schneier when Mirai first appeared] This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption? I don’t understand why every s…

> Schneier is a so-called expert who has testified in front of congress Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier. Credibility wise he .. - has a master's degree in computer science - was awarded an honorary Ph.D from the University of Westminster in London - is chief technology officer of B…

Just to clarify, he’s not with BT any longer, but with IBM Resilient:

He has been working for IBM since they acquired Resilient Systems where Schneier was CTO.

Post reply on HN