Live data from Hacker News

The internet is held together with spit and baling wire

krebsonsecurity.com

51–60 of 176 posts

Re: The internet is held together with spit and baling wire

#51
post #18

Held together with spit and baling wire as it is, the fact that it mostly works proves that the overall architecture is robust.

> proves that the overall architecture is robust. Not really. What it shows is the stark difference between two ideologies. The first camp contains people who believe in Postel's Law, "be conservative in what you do, be liberal in what you accept from others". The second camp has people who recognize that the current world is not a cooperative network of researchers: "all input is untrusted". Krebs is absolutely in t…

But the two philosophies aren't really in contention. Proper adherence to Postel's law also includes accepting malicious traffic (and then doing something reasonable with it, like black-holing it).

The "liberal in what you accept" part is mostly honest acceptance of the reality of the network: you cannot control the information sent to your service, only how you respond to it.

Re: The internet is held together with spit and baling wire

#52
post #13

Earlier quoted context omitted.

What original topology are you talking about? There was never a time when your end consumer device could be used as even a semi-reliable web server.

If you have a cable connection today, you can serve reliably just fine. Throughput isn’t the best and there are other minor issues, but it’s reliable enough for most people’s purposes.

Coaxial cable connections in the US have such meager upload bandwidth that cable ISPs do not even bother advertising or specifying a minimum upload bandwidth.

Re: The internet is held together with spit and baling wire

#53
post #26

Earlier quoted context omitted.

Deprecating unencrypted HTTP is a big systemic improvement even though some individual sites may not benefit much. It's a network effect. (What's the money grab given free let's encrypt certs?)

Lets encrypt from what I understand require time consuming updates every few months. My host provider also does not allow me to install them manually, further complicating the process, and conveniently they sell certs for $125 a year... Per site. It's been a thorn in my side because we're too big to easily move now.

You are absolutely not meant to do the updates manually.

Re: The internet is held together with spit and baling wire

#54
post #26

Earlier quoted context omitted.

Deprecating unencrypted HTTP is a big systemic improvement even though some individual sites may not benefit much. It's a network effect. (What's the money grab given free let's encrypt certs?)

Setting up, monitoring and maintaining LE isn't free

Whether or not that's true, it's not a money grab.

Re: The internet is held together with spit and baling wire

#55

Earlier quoted context omitted.

But monitoring and maintenance are things someone needs to do if they operate a site, period.

But if you're independently running, paying for, and managing multiple sites, it's a HUGE burden. It also kills innovation for independent devs and startups, and dramatically raises the cost/investment threshold for this kind of innovation. Pricing on cert services is also far too high when everyone's concern and agreement should be security as a basis for operations. It's not something that should be an upcharge or…

And, indeed, if you build your site via a service provider or platform, an SSL solution is usually provided.

Building a site from scratch in this day and age is a lot more analogous to building your house from scratch. Nobody to blame but yourself if you buy substandard locks and thieves get in. Only here the metaphor breaks down, because if you aren't encrypting your HTTP traffic and it is intercepted, it's your users who suffer, not the site owner.

I, too, pine for the days of simpler internet. But that was a function of the user base, not the technology. It was always insecure... it simply hadn't been exploited yet. Now that it has, and is, site administrators owe it to users to secure their connections.

Re: The internet is held together with spit and baling wire

#56

Earlier quoted context omitted.

But monitoring and maintenance are things someone needs to do if they operate a site, period.

But if you're independently running, paying for, and managing multiple sites, it's a HUGE burden. It also kills innovation for independent devs and startups, and dramatically raises the cost/investment threshold for this kind of innovation. Pricing on cert services is also far too high when everyone's concern and agreement should be security as a basis for operations. It's not something that should be an upcharge or…

Setting up certbot is easy, not a big burden for indie devs. Or if you want to know nothing about tls & certs, just get hosting that comes with tls.

Re: The internet is held together with spit and baling wire

#57
post #42

And Google requiring (costly and/or time consuming) SSL certs to be applied on all sites to "ensure security" was also a big industry money making nightmare for many independent (non-income-driven) sites that is still playing out badly, and not providing much more security. Two factor authentication and account verification is really an elaborate corporate sham to get people's phone numbers and PII for free. It doesn…

Honest question (IT/security noob) -- why does it not provide that much more security? I like verifying that my traffic is going where I want.

With Encryption being applied to every site as a requirement is relatively new since google made it a requirement in Chrome.

Previously it was only required for secured transactions like purchases and working on health care records etc... And very rightfully so.

Now Google Chrome flags even simple (informational) sites for not being encrypted, and (quite possibly) rightfully so because of the potential for tracking/abuse, but adding encryption to a site is costly for independent sites (not hosted on social media or corporate platforms like blogs etc...

You shouldn't be required to encrypt a baking recipe site if you don't want to... Ultimately laws should discourage data abuse, and/or encryption should be inherently provided for every site/app uniformly by all web host providers (natively and inherently, and at a far lower price than it is now, generally speaking).

Too many people are running widely varying encryption measures, and implementing security in too many different ways to ensure that it is stable across the Internet. Security is best when it is uniform, fortified by rules and regulations, and updated ritually.

Re: The internet is held together with spit and baling wire

#58
post #29

Earlier quoted context omitted.

"The internet routes around failure" hasn't been true for a long time. It refers to the original topography which has been replaced with a hub and spoke model. Remove a few hubs and you have disabled a large portion of the internet.

If by “remove a few hubs” you mean level a few major colo’s then ok, but as far as I can tell there is not any single strand of glass or single switch or single server that can take everything down with it.

You don't need to level the colos, you just need someone to make a typo in a router config that gets deployed live so the whole colo is unreachable. How many times have we seen an AWS/CloudFlare/otherLargeProvider have this happen to them?

Re: The internet is held together with spit and baling wire

#59

Earlier quoted context omitted.

If you have a cable connection today, you can serve reliably just fine. Throughput isn’t the best and there are other minor issues, but it’s reliable enough for most people’s purposes.

Coaxial cable connections in the US have such meager upload bandwidth that cable ISPs do not even bother advertising or specifying a minimum upload bandwidth.

Yeah, but I’ve been able to stream music from my desktop to my phone while driving and run a web server with reasonable performance on one.

Re: The internet is held together with spit and baling wire

#60

It's Anti-Fragile. If it breaks all the time, everybody is highly experienced at patching together new workarounds, mechanisms for fail over are in place and regularly tested, and there's whole classes of corner case bugs that get flushed out to be stomped (or nurtured as cherished pets) instead of breeding in the dark and jumping out at you all at once. How can the "Internet routes around failure" be trusted without…

"The internet routes around failure" hasn't been true for a long time. It refers to the original topography which has been replaced with a hub and spoke model. Remove a few hubs and you have disabled a large portion of the internet.

Disabled? Throttled down the speed by half? Yes. But to disconnect whole regions, you have to do conscious sabotage and even Mubarak did not manage to switch off Egypt when he wanted to and gave orders to.
Post reply on HN