Live data from Hacker News

Dutch police take down hornets' nest of DDoS botnets

zdnet.com

11–20 of 63 posts

Re: Dutch police take down hornets' nest of DDoS botnets

#11
Reminds me of that fun time I had to explain to my boss that providing a 'russian contact' of his with a number of servers that would have some sort of 'remote kill switches to delete everything', probably wasn't a smart venture for our hosting business. At some point the cops will come knocking :)

Re: Dutch police take down hornets' nest of DDoS botnets

#12

If even Bulletproof hosts aren't safe why aren't malware authors using P2P infrastructure?

There is a difference between ignoring abuse reports and being immune to a raid by law enforcement. For these authors there is a trade-off between convenience, cost and security: using already available infrastructure is probably easier than to set up your own complicated hosting solution.

If any of them end up getting caught because of the information gathered by this raid they obviously misvalued one of these aspects in their trade-off analysis. Humans all make mistakes.

Re: Dutch police take down hornets' nest of DDoS botnets

#13

"hosting all sorts of badies, from phishing pages to vulnerability scanners, and from crypto-mining operations to malware repositories." Is crypto-mining now a bad thing or is this article leaving out some details that I'm missing?

People mine on systems that they do not own. Try leaving SSH open with weak credentials, or use any software with a recently disclosed RCE. It won't be long until somebody drops a Monero miner.

Re: Dutch police take down hornets' nest of DDoS botnets

#14
post #10
post #8

Earlier quoted context omitted.

It costs 2.50 to check the names of the owners of these companies at the chamber of commerce if that makes you doubt whether or not it's actually the name. This means that the owners were effectively outed by the publication anyway.

Not really, the point of Dutch privacy law (and similar EU laws) in this context is not to deter a dedicated investigator, but to merely put enough of a hurdle in place that everyone reading the article won't see the names of suspects, and they won't show up in web searches etc.

The convention (I don't think it's actually a law) existed before web searches, but it's a nice side effect.

Re: Dutch police take down hornets' nest of DDoS botnets

#15

I love how they don't tell the full name of Marco B. and Angelo K., but do tell that they companies were called "Bos IT Holding BV" and "Kreikamp IT Holding BV".

> Good morning, class. A certain... agitator--

> For privacy's sake, let's call her Lisa S.

> No, that's too obvious. Uh, let's say L. Simpson--

Re: Dutch police take down hornets' nest of DDoS botnets

#16
post #10
post #8

Earlier quoted context omitted.

It costs 2.50 to check the names of the owners of these companies at the chamber of commerce if that makes you doubt whether or not it's actually the name. This means that the owners were effectively outed by the publication anyway.

Not really, the point of Dutch privacy law (and similar EU laws) in this context is not to deter a dedicated investigator, but to merely put enough of a hurdle in place that everyone reading the article won't see the names of suspects, and they won't show up in web searches etc.

Iirc it's not even an actual law, more of an agreement between all news organizations to not publish names like that. I seem to recall Geenstijl(Dutch "news" site) publishing full names and not getting in trouble over it.

Re: Dutch police take down hornets' nest of DDoS botnets

#17

Reminds me of that fun time I had to explain to my boss that providing a 'russian contact' of his with a number of servers that would have some sort of 'remote kill switches to delete everything', probably wasn't a smart venture for our hosting business. At some point the cops will come knocking :)

Kill switch?

Maybe just LUKS with dropbear. Then:

    # cryptsetup luksRemoveKey /dev/mapper/foo

Re: Dutch police take down hornets' nest of DDoS botnets

#18
post #10
post #8

Earlier quoted context omitted.

It costs 2.50 to check the names of the owners of these companies at the chamber of commerce if that makes you doubt whether or not it's actually the name. This means that the owners were effectively outed by the publication anyway.

Not really, the point of Dutch privacy law (and similar EU laws) in this context is not to deter a dedicated investigator, but to merely put enough of a hurdle in place that everyone reading the article won't see the names of suspects, and they won't show up in web searches etc.

Not true.

Not mentioning lastnames is only a convention by journalists and the media. Publishing lastnames in the media is not a violation of the law. News website geenstijl.nl regularly publishes full names of suspects or criminals.

The convention already existed before the internet.

Update: I should have read more comments...

Re: Dutch police take down hornets' nest of DDoS botnets

#19
post #17

Reminds me of that fun time I had to explain to my boss that providing a 'russian contact' of his with a number of servers that would have some sort of 'remote kill switches to delete everything', probably wasn't a smart venture for our hosting business. At some point the cops will come knocking :)

Kill switch? Maybe just LUKS with dropbear. Then: # cryptsetup luksRemoveKey /dev/mapper/foo

Check your local laws on cryptography and destruction of evidence before trying this. You may still be legally obliged to decrypt the material or go to jail.
Post reply on HN