Earlier quoted context omitted.
In principle, that's what the NSA would be doing. When DES was developed and standardized in 1976, the NSA had input in selecting some of the constants that were chosen for it [0]. It wasn't until the late 80s when independent development of differential cryptanalysis [1] came out, and people realized that the DES constants were deliberately chosen to be resistant to this attack. The NSA has since turned away from th…
Or maybe the choice of Dual EC DRBG constants are intended to protect against a new cryptanalysis technique known only to the NSA
TP240PhoneHome Reflection/Amplification DDoS Attack Vector
81–90 of 90 posts
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#82Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
You are liable unless you can pass off that liability to someone else. So the ISP would be liable by default, and would have an incentive to filter their customers, or require them to abide by certain rules, pass some audits, provide proof of insurance or post a large deposit.
You could have insurers who in exchange of automated security scans will insure you, solving the problem for end-users at a reasonable cost.
This will actually encourage internet users (both consumers and businesses) to take security more seriously.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#83Earlier quoted context omitted.
Your comment underestimates the task of remediation. Sure, we can very easily get a list of DDoS source IP addresses. Any decent network operator can get a list of flows matching some DDoS criteria and generate a report of IP addresses. In the case of this TP240 attack, you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with…
> you're talking about ~2600 independent businesses across the world. Assuming you are able to determine the actual source of the traffic and work with a vendor to patch it, you're still tasked with somehow getting 2600 businesses to patch their systems or modify firewall rules. You can be sure that by only null-routing their entire C-class, adjacent customers will loudly complain to the operator who will quickly ide…
Unless you have coordination with the network operators on which those amplifiers are sitting, your null-routing of the amplifier in your own network isn't going to stop it from attacking other targets. If the amplifier is something like a DNS server, then your collateral damage isn't just "adjacent customers", it's potentially thousands of other users and resolvers on your own network. If those amplifiers are on a cloud service provider like AWS, you're going to potentially inflict even more pain onto your own paying customers who will no longer be able to communicate with AWS. You will essentially perform the DoS they were aiming for.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#84We're approaching the limits here, I think.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#85Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#86Tracking down these systems is easy, so these issues can normally be solved pretty easily. Thats because typically any amplification vector doesn't allow the source IP of the amplifier to be spoofed. So as soon as a DDoS attack begins, a sample of the packets can be taken to get a list of the amplifiers used. Those can then be tracked down and patched to no longer act as amplifiers.
We need proper liability laws for malicious traffic. You are liable unless you can pass off that liability to someone else. So the ISP would be liable by default, and would have an incentive to filter their customers, or require them to abide by certain rules, pass some audits, provide proof of insurance or post a large deposit. You could have insurers who in exchange of automated security scans will insure you, solv…
A major issue here is how your smart toaster or MiVoice box can be spamming the internet and there's no real way to realize it for most people.
Since you pitched a controversial solution, let me make one that's probably even more controversial: maybe bandwidth is too cheap. Maybe the problem would fix itself without legal hell if your C&C'd smart toaster / VoIP box had an impact on your ISP bill instead of being folded into your unlimited bandwidth billing.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#87Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#88Once that hits, the device would then be sending the traffic harmlessly to /dev/null for the next 14 hours and be unavailable for attacks.
Not sure about the legal and ethical implications of that.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#89Earlier quoted context omitted.
Usually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person. [0]- In the US; I don't know about anywhere else
In the past what usually happens is the ISP disconnects you until you prove you've fixed whatever it was (sometimes they're nice and block just part of the connection, or give you a warning). Surprisingly enough, the ISP often has no real way of contacting anyone; the easiest is to cut the connection and wait for a complaint.
Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector
#90Earlier quoted context omitted.
> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…
"We are at war with Russia and China on a nation-state level" Not aware of any country in the world that is currently in a declared state of war with Russia and China.
Just how much evidence do you need to realize that the actions of both Russia and China have been - for years now - to undermine Western societies and the global set of rules?