Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

81–90 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#81

Earlier quoted context omitted.

In principle, that's what the NSA would be doing. When DES was developed and standardized in 1976, the NSA had input in selecting some of the constants that were chosen for it [0]. It wasn't until the late 80s when independent development of differential cryptanalysis [1] came out, and people realized that the DES constants were deliberately chosen to be resistant to this attack. The NSA has since turned away from th…

Or maybe the choice of Dual EC DRBG constants are intended to protect against a new cryptanalysis technique known only to the NSA

I highly doubt it. Dual EC DRBG basically works by encrypting your seed value with a NSA provided public key. It’s kinda amazing how blatant the back door is.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#82

Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

We need proper liability laws for malicious traffic.

You are liable unless you can pass off that liability to someone else. So the ISP would be liable by default, and would have an incentive to filter their customers, or require them to abide by certain rules, pass some audits, provide proof of insurance or post a large deposit.

You could have insurers who in exchange of automated security scans will insure you, solving the problem for end-users at a reasonable cost.

This will actually encourage internet users (both consumers and businesses) to take security more seriously.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#83

Earlier quoted context omitted.

Your comment underestimates the task of remediation. Sure, we can very easily get a list of DDoS source IP addresses. Any decent network operator can get a list of flows matching some DDoS criteria and generate a report of IP addresses. In the case of this TP240 attack, you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with…

> you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with a vendor to patch it, you're still tasked with somehow getting 2600 businesses to patch their systems or modify firewall rules. You can be sure that by only null-routing their entire C-class, adjacent customers will loudly complain to the operator who will quickly ide…

In general that's not really an option.

Unless you have coordination with the network operators on which those amplifiers are sitting, your null-routing of the amplifier in your own network isn't going to stop it from attacking other targets. If the amplifier is something like a DNS server, then your collateral damage isn't just "adjacent customers", it's potentially thousands of other users and resolvers on your own network. If those amplifiers are on a cloud service provider like AWS, you're going to potentially inflict even more pain onto your own paying customers who will no longer be able to communicate with AWS. You will essentially perform the DoS they were aiming for.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#85
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

maybe one day when the people in charge are at least somewhat technically litterate

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#86

Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.

We need proper liability laws for malicious traffic. You are liable unless you can pass off that liability to someone else. So the ISP would be liable by default, and would have an incentive to filter their customers, or require them to abide by certain rules, pass some audits, provide proof of insurance or post a large deposit. You could have insurers who in exchange of automated security scans will insure you, solv…

Litigation seems too heavy handed for these kinds of attacks.

A major issue here is how your smart toaster or MiVoice box can be spamming the internet and there's no real way to realize it for most people.

Since you pitched a controversial solution, let me make one that's probably even more controversial: maybe bandwidth is too cheap. Maybe the problem would fix itself without legal hell if your C&C'd smart toaster / VoIP box had an impact on your ISP bill instead of being folded into your unlimited bandwidth billing.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#88
Seems like a potential mitigation would be to send the affected devices a small stream of packets that tell them to generate traffic for e.g. an invalid IP, local IP, or their own public IP.

Once that hits, the device would then be sending the traffic harmlessly to /dev/null for the next 14 hours and be unavailable for attacks.

Not sure about the legal and ethical implications of that.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#89
post #58
post #45

Earlier quoted context omitted.

Usually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person. [0]- In the US; I don't know about anywhere else

In the past what usually happens is the ISP disconnects you until you prove you've fixed whatever it was (sometimes they're nice and block just part of the connection, or give you a warning). Surprisingly enough, the ISP often has no real way of contacting anyone; the easiest is to cut the connection and wait for a complaint.

Yep. Sad but true. Nobody bothers to keep their contact info up to date with their ISP it seems. Non-critical stuff sometimes can be mailed to a customer's service address, but often disconnecting someone is all an ISP can do to make them aware they have a problem.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#90

Earlier quoted context omitted.

> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…

"We are at war with Russia and China on a nation-state level" Not aware of any country in the world that is currently in a declared state of war with Russia and China.

The insistence of people on a formal declaration of war is one of the reasons why the situation has escalated so far.

Just how much evidence do you need to realize that the actions of both Russia and China have been - for years now - to undermine Western societies and the global set of rules?

Post reply on HN