Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

41–50 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#41

Earlier quoted context omitted.

Sorry but Walmart has cameras, guards, and most importantly locked windows and doors. Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility. It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the co…

The correct equivalency would be the roads leading to the Walmart. If a Walmart were blocked by people pointlessly driving on the road to make the Walmart effectively unreachable, police would intervene and clear the road of the noise.

There is no such thing as a "correct equivalency".

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#42
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Depends. Do you want the government to control the internet?

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#43
post #39
post #35

Earlier quoted context omitted.

Start by mandating BCP38 (RFC2827).

What stops that? (Both its widespread implementation and making it mandatory)

You mean what that protects against?

It provides the first part of my post, authenticating the packages.

The second part is cutting out misbehaving connections. On this case on the article, it would be trivial, and governments should be on the ISP shoulders making them make call everywhere and cutting some of their clients. But there are many attacks where the ISPs don't have enough information to act if they implement something like BCP38.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#44
post #20

Earlier quoted context omitted.

Sorry but Walmart has cameras, guards, and most importantly locked windows and doors. Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility. It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the co…

I think the question is about foreign government operations. If North Korean agents threw up some graffiti on a Wal-Mart and stole some soda, the private security would not be expected to handle the situation on their own. Even if the stakes seem low, that's an international incident.

That's... a very weird, reaching argument to make. And also not an international incident, since it's just some graffiti, not espionage or assassination or whatever. I'm not sure what point you're trying to make here.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#45
post #13

Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

It could be easily solved by the operator, but that doesn't mean it's easy for the victims to get the operators to fix their stuff. These amplifiers are already run by people who ignored the software manufacturer's directions. What are the odds they will actually install the new version that's harder to abuse?

Usually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person.

[0]- In the US; I don't know about anywhere else

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#46
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Well stated.

We also have a tendency to conflate the requirements on software systems with respect to security threats as being somewhat similar to the requirements on other kinds of engineering with respect to safety and environmental threats, and I think that does a disservice to the vastly different scope of responsibility involved.

When I see people arguing that software engineers need to treat security as seriously as, say civil engineers treat structural stability when designing a bridge, or mechanical engineers treat vehicle crash safety, I agree to an extent, but I also think it’s worth considering:

Most bridges are not designed to actually survive being deliberately attacked with the kinds of weapons nation states can bring to bear on them. When militaries get involved, bridges tend to fail.

Likewise, civilian car safety testing does not make cars that are able to survive attacks that nation state actors can carry out with things like tanks, mines, or drones.

We need to be realistic in our expectations for what level of military threat civilian systems can reasonably be expected to deal with unaided.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#47
post #20

Earlier quoted context omitted.

Sorry but Walmart has cameras, guards, and most importantly locked windows and doors. Just because nobody has figured out (or bothered to invest into) building the equivalent of basic security doesn't mean it's the state's responsibility. It is the government's responsibility to make sure companies take their responsibilities of protecting their customers' data, and the internet more broadly from the impact of the co…

I think the question is about foreign government operations. If North Korean agents threw up some graffiti on a Wal-Mart and stole some soda, the private security would not be expected to handle the situation on their own. Even if the stakes seem low, that's an international incident.

I am pretty sure that it does not matter who stole the soda - North Koreans or locals. Either way it is up to store security to catch them and hand over to police. Police may then hand NKs over to someone else, but this doesn't change what store security must do.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#48
post #20

Earlier quoted context omitted.

I think the question is about foreign government operations. If North Korean agents threw up some graffiti on a Wal-Mart and stole some soda, the private security would not be expected to handle the situation on their own. Even if the stakes seem low, that's an international incident.

That's... a very weird, reaching argument to make. And also not an international incident, since it's just some graffiti, not espionage or assassination or whatever. I'm not sure what point you're trying to make here.

The original argument is that it's weird private businesses have to protect themselves against state actors such as foreign governments. The equivalent would be if Walmart was expected to protect itself while a foreign governments special forces raided their stores.

Of course I'm not sure that's how it's playing out anyway, as I'm certain that the relevant three letter agencies are interested in foreign state actors digital incursions, it's just a very delicate situation and not as simple or clear cut as the Walmart example.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#49
post #29

I'm really concerned that DDOS attacks are going to lead to the death of the open Internet and its balkanization and isolation behind walled gardens. If you look at where Cloudflare and some of the big clouds are going with their private networks, private backplanes, and "secure your traffic by putting it all over our network" zero trust plans it seems to be going that way. If open peering and the open Internet are t…

It's interesting that you say that, because we've already sort of balkanized around ISPs. However, CDNs and DDOS protection popped up around services that ISPs couldn't provide. Maybe the dream is for ISPs to provide these services as well, making it more tenable for regular users to self-host.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#50
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

We rolled over to state-sponsored election meddling. There’s no way we’re going to care about this.
Post reply on HN