Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

31–40 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#31
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

While your logic is solid and I do think this would be ideal I struggle to see how this would work. Dropping bombs on a walmart store is clearly unwelcome, sending traffic to walmart's website? Much less clear. You can guess based on the traffic pattern but the only way to really know is to ask walmart if this is welcome traffic (not just a burst because some new product came out). Especially since many cases are DoS…

Well, a government could start by mandating that internet peers authenticate their packages, and cutting the access of bad actors.

People can't do that, and it's a very basic defense.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#32
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

It is just you. In the physical world a military can observe an attack, can announce that it is not cool, and can drive a tank through most intruders.

Now ask yourself this question, would you like to give your military the full access to your infrastructure together with command and control capabilities to do with your devices and the software on them as it pleases according to the situation? If you actually think that in fact you are not okay with 24/7 monitoring and management from a centralized government institution, you should own up to your desires and get your defense together.

Of course, this is a simplistic and extreme scenario. Much of the missed part is about availability and basic institutional capability for military cyber operations, but the fundamental question is: when one demands something from the government, what exactly they wish to give up as a consequence of the proposed solution.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#33

Earlier quoted context omitted.

While your logic is solid and I do think this would be ideal I struggle to see how this would work. Dropping bombs on a walmart store is clearly unwelcome, sending traffic to walmart's website? Much less clear. You can guess based on the traffic pattern but the only way to really know is to ask walmart if this is welcome traffic (not just a burst because some new product came out). Especially since many cases are DoS…

Well, a government could start by mandating that internet peers authenticate their packages, and cutting the access of bad actors. People can't do that, and it's a very basic defense.

"Mandate private companies protect their customers" sounds very different than "the government should protect everyone" even if the result is similar.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#35

Earlier quoted context omitted.

While your logic is solid and I do think this would be ideal I struggle to see how this would work. Dropping bombs on a walmart store is clearly unwelcome, sending traffic to walmart's website? Much less clear. You can guess based on the traffic pattern but the only way to really know is to ask walmart if this is welcome traffic (not just a burst because some new product came out). Especially since many cases are DoS…

Well, a government could start by mandating that internet peers authenticate their packages, and cutting the access of bad actors. People can't do that, and it's a very basic defense.

Start by mandating BCP38 (RFC2827).

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#36
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Indeed. We definitely need laws to hold companies accountable for their IT-related activity. For one, we need to hold commercial vendors accountable - that means especially to refuse to provide security updates for the reasonably expected life time of a piece of software or hardware. But especially, we need the companies using IT systems to be held accountable. The magic word is "defense in depth" - the scenario of t…

A failure to defend yourself is not aiding the enemy. That is insane.

The government provides for the common security. That's one of it's most fundamental jobs.

Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#37
post #36

Earlier quoted context omitted.

Indeed. We definitely need laws to hold companies accountable for their IT-related activity. For one, we need to hold commercial vendors accountable - that means especially to refuse to provide security updates for the reasonably expected life time of a piece of software or hardware. But especially, we need the companies using IT systems to be held accountable. The magic word is "defense in depth" - the scenario of t…

A failure to defend yourself is not aiding the enemy. That is insane. The government provides for the common security. That's one of it's most fundamental jobs. Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

> A failure to defend yourself is not aiding the enemy. That is insane.

Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable.

Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished.

We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#38
post #29

I'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are t…

> If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way.

All the networks of the Internet are already private, just like the networks of AOL and CompuServe were private back in the day: your ISP's network is private, YouTube's network is private, AWS' network is private. It's just that those private networks agree to talk to each other.

Otherwise your ISP would have to re-create YouTube and Reddit/forums and eBay/marketplace and…, and YouTube would have to buildout (inter)national network to connect their video services to people's homes.

Just like AOL and CompuServe had to build out information services and a connectivity infrastructure back in the day.

Now each of the previously walled gardens (messaging, forums, marketplaces, connectivity, etc) is done by its own entity, each taking a slice of the monetary pie for the service(s) they provide.

The Internet is a 'network of networks', but it is also an agreement: an agreement for everyone to talk to everyone else.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#39
post #35

Earlier quoted context omitted.

Well, a government could start by mandating that internet peers authenticate their packages, and cutting the access of bad actors. People can't do that, and it's a very basic defense.

Start by mandating BCP38 (RFC2827).

What stops that? (Both its widespread implementation and making it mandatory)

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#40
post #29

I'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are t…

> If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. All the networks of the Internet are already private, just like the networks of AOL and CompuServe were private back in the day: your ISP's network is private, YouTube's network is private, A…

I think that's kind of semantic. The agreement is what I'm talking about. It makes the Internet open. I can just send you a packet. That's what's in danger here.
Post reply on HN