Live data from Hacker News

I'm being cyberattacked by Tesla, Inc

dreamstation.systems

91–100 of 127 posts

Re: I'm being cyberattacked by Tesla, Inc

#91
post #79

Earlier quoted context omitted.

One solution is to not set up and run a computer program that relies on bad information to perform automated cyber-attacks on third parties.

How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?

Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.

Re: I'm being cyberattacked by Tesla, Inc

#92
post #91

Earlier quoted context omitted.

How do you suggest I determine the information is bad, if the domain is hosted on tesla.com, and Tesla says I am authorized to test it? Should I inspect all 1,368 subdomains on tesla.com by hand, and then do the same for 400+ bug bounty programs?

Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.

The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?

Re: I'm being cyberattacked by Tesla, Inc

#93
post #82

Earlier quoted context omitted.

Yes. I have personally done this before, the correct sequence of moves is: 1. Call your neighbor, ask for permission. 2. Check the door 3. Lock the door If you don’t have their phone number, you are not on good enough terms to touch their lock.

This is why the checking doors / neighborhood analogy isn't a good one. Having one person with poor computer security negatively impacts everyone. Hacked sites turn into phishing landing pages, exploit kit hosting, stolen data dumps, and launching off points for attacks on everyone else. The vuln scanning ShadowServer is doing is meant to be a public good, which is why they share the info with ISPs and governments. S…

It is a good analogy because thieves stealing from one house successfully gives them resources and incentivizes them stealing from the same area again.

And even if you remove the analogy, ShadowServer means good, but good intentions doesn’t necessarily make their action moral or legal.

Yes, compromised servers can be used by hackers as means to commit crimes. But when these groups scan the entire internet, they do cause harm as well, as shown in the original linked article. Much less harm than a black hat, but they still waste time and resources from innocent third parties.

It’s fair to ask if the harm they cause is worth the good they do.

Re: I'm being cyberattacked by Tesla, Inc

#94

I would assume the fastest way to actually make this stop would be to setup a bunch of honeypot exploits, trigger their detection and someone will figure out what they did wrong. Other than not, with these huge companies you have 0 recourse.

I wonder if source IP can be ping triangulated, then total ping count displayed as "Tesla MAU: +/-x% today", "Suspected ownership changes this month: xxx cars" by apparent home location changes, then residential and Tesla-unrelated locations excluded server side, and plotted on the map, then finally the whole system exposed to the public Internet and shared to SpaceX fans.

"Hey Texas Model S #345 just left KXYZ, moving at >100mph towards the pad. Everyone get cameras out!"

It'll be gone by lunchtime that day.

Re: I'm being cyberattacked by Tesla, Inc

#95
post #91

Earlier quoted context omitted.

Yes, unless you think that trying to do a bug bounty is a good excuse to participate in DoS.

The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?

You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?

Re: I'm being cyberattacked by Tesla, Inc

#96
post #95

Earlier quoted context omitted.

The OP says they have received 50,000 requests in about a month. What service is being denied by 0.01 requests per second?

You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?

I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.

Re: I'm being cyberattacked by Tesla, Inc

#97
To OP robinpie:

I understand that Tesla is treating your NTP server, a volunteer server and part of the greater volunteer pool of NTP servers, as their own infrastructure.

However, I can't tell from the article if the scans originate with:

A.) IT staff at Tesla that are scanning exposed services on what they perceive, or claim wrongly, as their own network for vulnerabilities.

B.) Somehow a rogue operator (read botnet)

C.) A rogue operator who is using the cars themselves to run exploit scans?

C would be the most alarming and concerning.

Re: I'm being cyberattacked by Tesla, Inc

#98
post #95

Earlier quoted context omitted.

You're now confident that the other 399+ domains you mentioned are not under any sort of duress because they're controlled by people who are away of what's happening?

I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.

Okay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners.

Re: I'm being cyberattacked by Tesla, Inc

#99

I’m pretty sure this way they’ve hardcoded the NTPs is actually against the ToS for use of the NTP pool too. The way a vendor embedding NTP is _meant_ to do so is documented here: https://www.ntppool.org/en/vendors.html On another note, back when I ran a web hosting business we hosted a few NTP servers in the pool. It’s such a simple thing to give back, and worth anyone who can make a stable contribution doing so.

> The pool is currently keeping the time of an estimated 5-15 million systems accurate.

When was this page last updated? I would expect that number to be in the hundreds of millions these days, perhaps even billions.

Re: I'm being cyberattacked by Tesla, Inc

#100
post #98

Earlier quoted context omitted.

I feel confident that no system exposed to the internet should have a problem with 50,000 requests per month! If they do, they probably shouldn't run a public NTP server, or have a public IP address at all.

Okay, so you're just confident in exactly how many requests everyone else in the world will be making if you try to pentest resources unbeknownst to their owners.

Are you confident you are not viewing too many pages on HN? What if many other people are also trying to read this thread?

I think this line of reasoning doesn't make any sense. The internet is not an inherently safe network regardless of what we wish for; we can't wish away the bad activity, and it's only going to increase. The activity that helps prevent the bad activity from working is a net positive.

Post reply on HN