Live data from Hacker News

Global Internet slows after 'biggest attack in history'

bbc.co.uk

91–100 of 159 posts

Re: Global Internet slows after 'biggest attack in history'

#91

Earlier quoted context omitted.

Wouldn't it just be easier to, I dunno, unplug something? Or turn something off? Why would you fuck up the lines...

You can't "turn off" that bunker, it has multiple diesel generators and lots of fuel reserves. It also has clean water reserves and air filtering capabilities, so you can't gas the people inside. Physically cutting its uplink lines would be IMHO the most efficient way to neutralize that datacenter.

Or just getting all their peering exchanges to null route packets in and out. Advantage being that it's cheaper, more effective and less lawsuit prone.

Re: Global Internet slows after 'biggest attack in history'

#92
post #37

Earlier quoted context omitted.

I looked up a video with an actual Dutch SWAT team and their uniform looks different. The one in the picture is pretty derpy, and they're carrying what looks like tiny medieval shields. I'm not convinced.

The picture is clearly Photoshopped. Light in the background is coming from the right, while light on the team is coming from the left. Edit: talking about this picture: http://cyberbunker.com/web/images/swat-bunker.jpg Edit2: I think it's more difficult to determine if it's real than I thought.

There are trees all around.

Light could be coming from the top (around midday) and be blocked in arbitrary parts by the trees, so one part of the place gets light from the right, while another gets it from the left.

Re: Global Internet slows after 'biggest attack in history'

#93
post #21

Earlier quoted context omitted.

According to a convenient nuclear effects calculator I found[1], 20MT at 5km and an optimal burst height will generate over 40psi of overpressure. The fireball itself will reach about 4km in radius. According to another site[2], 20psi is enough to severely damage or destroy heavily built concrete buildings, and the maximum wind speed at 40psi will be greater than the speed of sound. For comparison, 3psi is enough to…

Glad to know in the case of full scale nuclear war, the only survivors will be lunatics and data center admins.

relevant fiction:

http://craphound.com/overclocked/Cory_Doctorow_-_Overclocked...

Re: Global Internet slows after 'biggest attack in history'

#94
post #2

Funny story from the Hosting company[1]: "Before the break of dawn on a morning in April, a full SWAT team was sent to execute a search warrant on CyberBunker's property." "It must not have occurred to the officers that the blast doors were designed to withstand a 20 megaton nuclear explosion from close range. When the SWAT team realized that the door was not being opened for them, they throw flashbangs and take othe…

I looked up a video with an actual Dutch SWAT team and their uniform looks different. The one in the picture is pretty derpy, and they're carrying what looks like tiny medieval shields. I'm not convinced.

In the picture you see Riot Police, ‘Mobiele Eenheid’. A SWAT team is called ‘Arrestatieteam’ in Dutch http://www.svenvanbeek.nl/layout_imgs/632011/SVB_Arrestatiet...

I think they shopped the photo to illustrate their story -- they’re not claiming it’s genuine I imagine (after all, apparently it took place while they were asleep).

Re: Global Internet slows after 'biggest attack in history'

#95

Earlier quoted context omitted.

If she has Microsoft Security Essentials installed, doesn't run unknown software, and doesn't give out her password, what more could my mother, as a layman, reasonably be expected to do? I understand there are all sorts of complicated steps she could take if she had good intuition about sniffing out bad guys, but she doesn't. Isn't the problem with the crappy software, not her?

The fundamental problem is that bad guys can come up with new attack methods faster than we can educate or produce reliable user friendly software to counter their methods. Even a sophisticated user is just as vulnerable in many cases. If I give personal information to a third party site that I presume to be trustworthy (say a government site) there's no way I can know if someone is going to find SQLi vulnerabilities…

New attack methods are not the problem. If there is new technology there will always be a new attack method. Right now the existing attack methods are the problem. Specifically, that technology is being developed using the same lack of basic security standards and thus the same old attacks keep working.

SQLi should not be a thing. At all. It's the most trivial fucking thing in the world to validate data before you use it in an SQL query, and people get it wrong, every single day. Security isn't hard, it's just tedious.

Re: Global Internet slows after 'biggest attack in history'

#96
post #37

Earlier quoted context omitted.

I looked up a video with an actual Dutch SWAT team and their uniform looks different. The one in the picture is pretty derpy, and they're carrying what looks like tiny medieval shields. I'm not convinced.

The picture is clearly Photoshopped. Light in the background is coming from the right, while light on the team is coming from the left. Edit: talking about this picture: http://cyberbunker.com/web/images/swat-bunker.jpg Edit2: I think it's more difficult to determine if it's real than I thought.

Is there a mirror of the image? Ironically enough, that server is down for the count.

Re: Global Internet slows after 'biggest attack in history'

#97

Earlier quoted context omitted.

I looked up a video with an actual Dutch SWAT team and their uniform looks different. The one in the picture is pretty derpy, and they're carrying what looks like tiny medieval shields. I'm not convinced.

I think the uniforms in the picture are old, and the SWAT raid was supposedly many years ago, so it might be not be fake based on that.

they are uniforms of the Riot Police, not SWAT.

Re: Global Internet slows after 'biggest attack in history'

#98
post #37

Earlier quoted context omitted.

I looked up a video with an actual Dutch SWAT team and their uniform looks different. The one in the picture is pretty derpy, and they're carrying what looks like tiny medieval shields. I'm not convinced.

The picture is clearly Photoshopped. Light in the background is coming from the right, while light on the team is coming from the left. Edit: talking about this picture: http://cyberbunker.com/web/images/swat-bunker.jpg Edit2: I think it's more difficult to determine if it's real than I thought.

I don't think it's meant to be representative of their surveillance footage.

Re: Global Internet slows after 'biggest attack in history'

#100

Earlier quoted context omitted.

I agree, the problem however is that threats are constantly evolving and getting more complicated. Even most IT people don't understand the threats properly (I know I struggle). It used to be that could just tell people to install a security suite on their computer and they'd be mostly OK. I don't think that's really true any longer. You could also partly lay the blame at Microsoft's door in getting users to start co…

If she has Microsoft Security Essentials installed, doesn't run unknown software, and doesn't give out her password, what more could my mother, as a layman, reasonably be expected to do? I understand there are all sorts of complicated steps she could take if she had good intuition about sniffing out bad guys, but she doesn't. Isn't the problem with the crappy software, not her?

Reasonably? That's pretty much good. Add what another comment said about not giving out personal information, but having a good AV like MSSE, using automated Windows Updates, use an updated browser (even if it's just the latest version of IE), don't run untrusted software, and having strong passwords (using something like LastPass to remember them all but still retain convenience) is basically all you can reasonably ask an average user to do. And for the most part, that's good enough.

Sure, there's evolving threats, there's drive-bys that will slip around all of this, there's ways attackers could still get through. But as scary as it all is, anything beyond these steps gets into the territory of major inconvenience. The problem with that is, the more intrusive and inconvenient the security becomes, the less likely people are going to be to actually use and remember their security practices. If mom can't repeat it at her book club, it's not going to be effective. And to be honest, these types of attacks that bypass these restrictions are exceedingly rare when it comes to mom and grandma. The biggest threat there is phishing and malware. Corporate security has professionals enforcing a policy that meets the business's own requirements.

So to answer your question, yes, that's all you can reasonably do. In most cases, you'll be pretty well protected with just that, and those steps aren't too complicated to follow or remember.

Post reply on HN