Live data from Hacker News

Cloudflare's new DNS attracting 'gigabits per second' of rubbish

zdnet.com

131–140 of 206 posts

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#131
post #63

Earlier quoted context omitted.

It's even easier to steal a phone number. Lots of phone companies still just approve a port if you send them the required paperwork to initiate a port. That means with zero verification from the account holder a number can vanish from your account.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…

> Anyone who relies on SMS for any type of authentication should stop.

Since the problem is that hijacking numbers is easy, shouldn't that apply to “anyone who relies on telephone numbers”, not just “anyone who relies on SMS”?

SMS isn't the only telephobe-number-based second-factor.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#132
post #63

Earlier quoted context omitted.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…

> Anyone who relies on SMS for any type of authentication should stop Err. That's pretty much every implementation of 2FA around the world. Why isn't this more well known ?

Not nearly as many people know how terrible ss7 is and the lack of security/pki/crypto in old-school traditional telecom. It is also a lot more opaque to learn and has higher barriers to entry, and is a very clique like club of "Telco" people.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#133

Awesome, the worlds biggest honeypot? There is literally a finite amount of bandwidth in the existance, let Cloudflare have as much cruft as it wants.

Ignoring the Finite, but years ago, I was introduced to a company that basically did not use a whole routed and public /8 except for... honeypot research.

Was a blast to see some of it and the warstories about how they where able to do some early warnings of nasties that where about to wreak havoc.

Gave them a good insentive to actually design a pretty good toolingset, that never made it past "On Demand Innovation Services" which helped me to clean out a network with a zoo of malware strains. Still would implement it in the different networks I frequent, if it was available.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#134

Earlier quoted context omitted.

Brand. How much would you pay if you were us to associate your brand with privacy/security and speed? Performance. Our core business is making our customers fast and safe. More people using 1.1.1.1 means our Authoritative DNS service inherently faster for anyone who uses it. Recruiting. Our mission is to help build a better Internet. Lots of places the people on our team can work. That they work for us is often becau…

> Our mission is to help build a better Internet. I've been working a lot with open data and I have huge problem with Cloudflare ruining open internet with bot protection and such. The issue I have is that public data is public, be it bot or human. I'm having real issue with you guys saying that your mission is to better the internet when you break shitton of floss apps that are essentially harmless and people who wa…

I agree. Part of what makes the web the web is that anyone has to be able to crawl its data, and build new technology on top.

As long as Cloudflare blocks that, it's hostile.

Maybe a way to register as spider with Cloudflare, and get a token that one passes in the header, with strict rate limits would be much better than the current solution of just showing captchas.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#135
post #63

Earlier quoted context omitted.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…

> Anyone who relies on SMS for any type of authentication should stop Err. That's pretty much every implementation of 2FA around the world. Why isn't this more well known ?

This is why the recent NIST guidelines on 2FA explicitly discourage using SMS. (Search for ‘SMS’ in the document: https://pages.nist.gov/800-63-3/sp800-63b.html)

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#136
post #119
post #4

I've seen some of the papers where people look at big chunks of unused address space and watch the probes etc. It is really quite amazing. Once I screwed myself royally by accidentally turning RIP on for the upstream side of my router (connected to the cable modem) and it advertised 192.168/16 which Comcast accepted and started routing random stuff from the local exchange to my router. It was pretty funny talking to…

Even for regular IPv4s you often get upwards of 20-40k SSH probes per day trying common passwords against root. IPv6 largely makes this go away since it's too big to brute force scan.

Yes, but the volume in kbps is tiny.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#137
post #63

Earlier quoted context omitted.

Worse. Some very large carriers don't even look at the supporting documentation (bill, LOA) submitted with port orders unless there's a rejection from the losing carrier and they want to double check the address entered or something. Hijacking numbers is crazy simple. Same for hijacking the SMS functionality of any number in the US (voice traffic remains untouched). In about 10 minutes you can start receiving SMS dir…

> Anyone who relies on SMS for any type of authentication should stop Err. That's pretty much every implementation of 2FA around the world. Why isn't this more well known ?

The beauty of it is cases like Google's. They have this bizarre 2FA security-theater Google Authenticator thing, but then nearly force everyone to have their phonenumber as a "backup device".

Guess what the send you when you forget your 2FA or password? Yep, an SMS. So out the door goes the whole point of 2FA. Your three factors (account name / email address + password + Google Authenticator) have now been reduced to one factor: your email address.

I can rent a mobile tower in Malaysia or some other asian country, advertise your phonenumber as roaming there for about €10/h and start intercepting all your shit. Or just get your telco's inept service dept to forward your number somewhere else.

Lessons here:

1. Even the giants get it wrong. 2. There is no security anywhere in the tech world. Literally everything is broken. Your electronic car locks / starter system, your phone, your internet, everything is horribly horribly horribly broken beyond any imagining, even for hyper-tech savvy people. 3. Remove your phonenumber as a backup device from your google account and never use it as a backup device every again.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#138

Earlier quoted context omitted.

Does all this garbage traffic affect the performance of Cloudflare's servers? There must be some cost (performance and $$$) to filter this traffic. Was that a consideration when deciding whether to use 1.1.1.1 instead of some other IP address? :)

Cloudflare is anycast announcing the space from something like 30 to 50 unique POPs worldwide, so the volume of shit traffic is significantly decentralized. It's not like 40 Gbps is hitting one location.

They scaled up recently and now have ~150 POPs. They specialised on DDOS defense from the start so traffic volume isn't an issue for them. Everything below 100gbit/s globally will probably be well within normal fluctuations. But I guess they talk to ASNs that send a lot of garbage and ask them to investigate on their side.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#139

Earlier quoted context omitted.

I have a problem with these comments because they're basically a false dichotomy. No, CloudFlare can't ensure they play fair. Can your ISP? Who can? Because these sorts of comments read to me as "yeah, you're the best right now, but are you perfect? No.". Nobody claimed perfection, and there's value in being the best.

Cloudfares CEO was guaranteeing that they have an external auditors to ensure the company keeps its word. I'm asking whether the same auditors can ensure that the CEO himself won't decide one morning to go against this word wrt this topic. In the same way that a ToS might state "we will never sell your data to third parties" and a CEO can't break that promise, what guarantee beyond "some external people are looking a…

I'd bet that if they one day drop that promise from their page they'll quickly hit the HN front page. If you don't trust, just monitor their policy page for diffs.

Re: Cloudflare's new DNS attracting 'gigabits per second' of rubbish

#140
post #13

Earlier quoted context omitted.

It was reworded enough times to make their promise vague and not well defined.

I’m Cloudflare’s CEO. What questions do you have? I’ll start: do we ever store 1.1.1.1’s users’ IPs? No. They’re never written to disk. And APNIC never has access to them. What data do you provide to APNIC? We give APNIC reports on non-DNS data that’s hitting 1.1.1.1. It includes information like: what protocols are sending data to the IP, what’s the volume, where it it coming from? For DNS users of 1.1.1.1, we never…

Do you plan to publish usage statistics over the coming weeks? I'd be keen to know what kind of (valid DNS) volumes you've seen since the announcement. And if there are any obvious patterns of ASNs or countries using it a lot (unless you don't want to disclose that to avoid being blocked there).
Post reply on HN