Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

101–110 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#101
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

Here's one way:

* Find a couple of remote security holes in Windows and Android, maybe iOS and Macs as well (Linux would be good too, as lots of servers run Linux and have big bandwidth).

* Write a self-propagating worm which uses your holes to infect a large chunk of machines currently attached to the internet.

* Set your worm so, after an hour or so it starts hammering the root servers.

That mess would be almost impossible to sort out, particularly if you were clever about the traffic you created do it was hard to filter.

The only reason I can think no-one would do this is it's MAD -- no-one's internet would work, why would Russia or China or the US want to take down everyone's internet?

Re: Someone Is Learning How to Take Down the Internet

#102

The Internet is suppose to be decentralized. Yet we have these centralized groups, proving backbone, DNS, certs. Well duh, it's no surprise. Why can't I connect to my neighbor who lives next door without the packet doing a 200 mile trip? The Internet is really only devices that can route packets through at least 2 different gateways. If you only have one route. You are not part of the vision of the Internet.

You can make such a connection and establish a mesh network, most people are just too lazy or technically unsophisticated to pull it off apparently. Centralization is a consequence of that fact that people do not actually want to maintain their own infrastructure, they just want it to work while they get back to the rest of their life.

Re: Someone Is Learning How to Take Down the Internet

#103
post #33

Earlier quoted context omitted.

My guess would be that the American government has less reason to test what would take down some of these services. And not for benevolent reasons, but because they could more easily send in armed agents and simply unplug those services.

We've already shown that we can pretty effective destroy a country's infrastructure from the air as well, not just with explosives and incendiaries, but other clever tricks as well.

Such as...

Re: Someone Is Learning How to Take Down the Internet

#104
post #15

Since there are lots of hobbies that sometimes overlap with community service I'd love to see a club that focuses on being prepared to reestablish intra-community communication in case the Internet goes down. Yes, it'd be great if everyone was self hosting, using distributed services and involved in a mesh network now, but without motivation it won't happen. So this club could focus on developing the resources that a…

This guy in Spain created his own internet infrastructure: https://backchannel.com/forget-comcast-heres-the-diy-approac... It's been running successfully for years and has grown quite a bit.

Re: Someone Is Learning How to Take Down the Internet

#105
post #28

Earlier quoted context omitted.

The amateur radio community already has the technical know-how and disaster readiness to do most of that, and I'd be willing to bet there's enough overlap between them and the meshnet crowd to take care of the rest.

The amateur radio community can't use encryption and, for the most part, is happy about this restriction. A zero-privacy internet might be better than nothing, but I'm not 100% sure of that.

but its only relevant in the disaster-recovery situation anyhow; should be quite decent for that use. And otherwise, you have regular Internet access, and its hardly realistic a small hacker community can do anything to replace it.

Re: Someone Is Learning How to Take Down the Internet

#106
post #90

Earlier quoted context omitted.

You mean, like this guy? http://www.dailymail.co.uk/news/article-1386978/The-Japanese...

The man lived through a tsunami in the area, that was hardly a matter of exciting thoughts, but a desperate desire to prevent a predictable tragedy. By contrast people prepping for the end of days in whatever form, often nuclear, strike me as mad. If there's a nuclear war, I want to be in the hypocenter of the first detonation, because we're not climbing out of that hole as a species in any meaningful way. I suppose…

Agreed, if civilization does come tumbling down. However, as far as I could read, for it to survive a nuclear exchange is quite possible, even probable.

Blasts themselves seem relatively harmless, beyond the hundereds of millions they just outright kill that is, radiation we're just characteristically paranoid about, but can actually deal with at least in many remaining areas, and the main issue at debate is whether a nuclear winter of substantial duration would be formed or not. Which depends on the scope of the fires, so flammability of urban environments and the like. We can't pretend to know a real answer, but its certainly possible.

And then there's the issue of whether the south hemisphere could avoid that fate even in such a case, due to weather patterns, provided there's no detonations there (as there are no weapons there).

Now that doesn't seem substantially different from any large-scale warfare civilization easily survived previously, like world war II; urban devastation and millions of dead. Hardly a civilization-ending event.

Re: Someone Is Learning How to Take Down the Internet

#107
I totally disagree that we can't do anything. With the existing TCP/IP protocol we can't do anything because it's possible to forge the origin IP address or modify the datagram content on its route to destination. A receiving end has no way to verify the validity of the datagram.

An IP datagram authentication at the lowest level is required so that anyone on the route can detect forgery, error or tempering with the data. This would allow tracking the real sources of DDOS attack, diagnose the cause and fix it.

What's the point of keeping digging deeper trenches ?

This should be a top priority change of the Internet. There was no incentive to move to IPv6. Now there is one to move to a more secure Internet.

Re: Someone Is Learning How to Take Down the Internet

#108
post #86

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

My $0.02, as a latecomer to this tech industry (really only been in it for 6-8 years) I don't understand the reverance around Schneier. I first saw him give a talk in 2009, and it was an 'insert town name here' speech about stuff that was blazingly obvious to people who should already know (topic: social engineering and passwords). Yet people were fawning over the talk. It really struck me as a guy who was once great…

He wrote a book in the 90's that defined crypto for a lot of people. It was the first time that I know of that this info was all collected, curated and available to the "average reasonably technical developer", without reading a ton of academic papers.

In retrospect we've learned a lot since them and no one (including the author) would recommend developers read that book first or even at all. Now we've come to the understanding that folks are much better served by opinionated cryptosystem design ("no sharp edges") and texts like "cryptography engineering" that have a better focus on failure modes.

Anyway, he's not the be all, end all expert but he has been thinking about this stuff for a long time and often has perspectives that are worth thinking about. Some of them, like his views on airline security etc are now so mainstream that you wouldn't realise he was a big part of why they are now widely held.

But mainly it's that he has a lot of pretty high level gov and industry connections that I would at least entertain his conjecture here.

Re: Someone Is Learning How to Take Down the Internet

#109
post #4

Earlier quoted context omitted.

'the author' (Bruce Schneier) is right a lot.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

Yes, as you say, the possible motivation is very different.

In a cyberconflict escalation if it would come up to a possibility of disrupting core Internet infrastructure to (temporarily) disable most of Internet, it would be most likely for China or Russia to want this result and for USA/NATO to actually want the opposite.

Re: Someone Is Learning How to Take Down the Internet

#110
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

It doesn't really imply harming the DNS, but rather the actual core infrastructure - network connections.

If they disable/crack/overwhelm the major routers connecting different ISPs (e.g. zero-days or backdoors for router OSes, BGP attacks with cooperation or cracked credentials from some major ISP insiders), then the internet is not going to work for you because your ISP will be simply unable to route your data to where you want.

Are there any good reasons to believe that all major router models don't have backdoors inserted by state actors, either by bribing an insider engineer ten years ago, or even having a manufacturer of some secondary on-board chip (that has direct memory access) insert a hardware backdoor ? We've detected such attempts before, there's all reason to expect that there are some of them active and undetected right now.

Post reply on HN