This is both unsurprising, and worrying. Unsurprising because it's the job of any nation's military and espionage arms to consider and form plans to cripple or destroy their potential enemy's infrastructure, information included. Worrying, because as far as I can tell most people remain deeply ignorant and/or unconcerned (present company excluded both from that remark, and realistically the descriptor "most people")…
'the author' (Bruce Schneier) is right a lot.
Someone Is Learning How to Take Down the Internet
11–20 of 143 posts
Re: Someone Is Learning How to Take Down the Internet
#12Can anyone elaborate on what he means when he says that Verisign can 'go down' and take down most of the internet with it? How would a registrar going down affect anything to do with actual hosts?
Poor wording. Verisign operates .com for the US government. So if Verisign's .com servers were to go down, then .com would go down with them. The author shouldn't have used the word "registrar" which makes people think of the creation of new domain names, à la GANDI (good) or GoDaddy (bad).
Re: Someone Is Learning How to Take Down the Internet
#13Makes me wonder if we'll ever see a "hot" war that starts off as a "cyber" war.
If you see a hot war, under current circumstances it will almost certainly be preceded (if only for a few minutes) by a full-on cyber attack.
Re: Someone Is Learning How to Take Down the Internet
#14This is both unsurprising, and worrying. Unsurprising because it's the job of any nation's military and espionage arms to consider and form plans to cripple or destroy their potential enemy's infrastructure, information included. Worrying, because as far as I can tell most people remain deeply ignorant and/or unconcerned (present company excluded both from that remark, and realistically the descriptor "most people")…
'the author' (Bruce Schneier) is right a lot.
Re: Someone Is Learning How to Take Down the Internet
#15All of the tech exists in some form or another, but if it were well packaged, it's not hard to see there being a sufficient distribution of members to get people connected easily.
Re: Someone Is Learning How to Take Down the Internet
#16Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious attack. One of the reasons why the root servers are not centralized is to avoid the kind of disaster that Schneier predicts.
Also what if I maintain a list of IP addresses of the websites I visit most and update that list daily. When the "big attack" strikes, I put that list in /etc/hosts. Would I still be able to do my holiday shopping from Amazon? Would I still be able to read the logs on my VPS by ssh'ing to its IP? How long would such an attack sustain before BGP modifications start blackholing the sources? Long enough to let the average TTL cache expire?
Would an attack on the root servers really take down the internet? Or in case Schneier isn't talking about that, what kind of attack on the decentralized internet is actually able to take it all down? I'm not saying he is wrong, but I have a hard time thinking about how we should prepare and protect our infrastructure if he doesn't want to share the intel he knows instead of some generic warnings.
Re: Someone Is Learning How to Take Down the Internet
#17Earlier quoted context omitted.
'the author' (Bruce Schneier) is right a lot.
He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.
Re: Someone Is Learning How to Take Down the Internet
#18Earlier quoted context omitted.
'the author' (Bruce Schneier) is right a lot.
He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.
That said, Schneier obviously has more information than he's currently sharing.
Re: Someone Is Learning How to Take Down the Internet
#19Earlier quoted context omitted.
'the author' (Bruce Schneier) is right a lot.
He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.
Remember the U.S. government has plans to effectively destroy the world with nuclear strikes as a contingency in war. Do you think they would hesitate to prepare plans to take down a data network? It's immoral? Unthinkable?
I'm not criticizing such plans. War is death and destruction, and the U.S. must be prepared.
The U.S., and all nations and citizens, also should do everything to prevent situations where war is the best remaining option. This requires sober, expert foresight in foreign policy and politics, anticipating 2nd-, 3rd-, and n-order effects, not emotional, knee-jerk ideology and amateur foreign policy.
Re: Someone Is Learning How to Take Down the Internet
#20Earlier quoted context omitted.
'the author' (Bruce Schneier) is right a lot.
He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.
1) The US has nothing to gain by taking down the internet infrastructure via malicious means.
or
2) The US has better access to these systems to take them out directly rather than forcing them down via DDOS attacks.