Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

101–110 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#101
post #51
post #9

To be honest, I wouldn't be surprised at all if the BackConnect kid decided to launch the DDoS: https://www.crunchbase.com/person/marshal-webb Edit: Maybe this helps with the downvotes: http://www.cbsnews.com/news/lulzsec-takes-revenge-on-alleged... https://www.reddit.com/r/cincinnati/comments/ibwbz/fbi_hacki...

More likely to be that sergio correia guy. I heard bad things about him.

Ok, I'll take the bait:

I see a Bloomberg article attacking the company as the cause for the DDoS. I go to their Crunchbase and see that the founder is very young, entered college at age 12 (although that contradicts his linkedin), etc. and point that I wouldn't be surprised if that is the link.

Then you say that should not be enough evidence, which made me google him, and surprise, I find out he was part of LulzSec, raided by the FBI, etc. So as "inappropriate" as my prior was, it seemed to be pretty good at spotting this possibility no?

Re: Possible Vendetta Behind the East Coast Web Slowdown

#102
post #6

If you are unable to connect because of DNS problems, switch your DNS server to 8.8.8.8 (Google). Edit: sorry there, this worked for me but apparently it's not guaranteed.

I switched temporarily from those to Open DNS's 208.67.222.222 and things are working for now. But, just to be clear, it's not Google's fault: 8.8.8.8 are not the authoritative name servers for the sites that are down. Rather, Dyn, the provider of the NS is down, and I presume Google (8.8.8.8) is correctly not returning any IP address because the underlying authoritative name server is not. Presumably Open DNS is wor…

Yes, the call it "SmartCache": https://www.opendns.com/about/press-releases/opendns-introdu...

Re: Possible Vendetta Behind the East Coast Web Slowdown

#103
post #26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

Car owners are not liable if the car is designed to be dangerous and they don't know it.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#104

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

The real problem here, and this isn't going to be a popular position, is that you're relying on the internet for important things. The original engineering and architecture of the the internet (and the web) was not intended to create something you put all your eggs in. It was for sharing information, not building your mission critical business operations on. Right now, if you dumped your business into a cloud service…

Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#105
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Firmware updating isn't exactly a "hard tech" problem, even if it is hard to do right. I suspect we'll see some generic firmware update frameworks/solutions emerge in the coming decade, and at that point adoption will pick up rapidly because being able to push updates is good for business.

Google's IoT solution offers this. But no one seems to want to use it.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#106

Here's a better article from Mr. Krebs: https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twit... Personally I think his case is pretty convincing.

From the article:

"Last month, a hacker by the name of Anna_Senpai released the source code for Mirai, a crime machine that enslaves IoT devices for use in large DDoS attacks. The 620 Gbps attack that hit my site last month was launched by a botnet built on Mirai, for example."

I repeatedly hear people refer to IoT devices that are notoriously difficult to update...yet this Mirai code is technically able to access millions of devices and bend them to its will.

So what I'm wondering is just, what prevents the good guys from using Mirai to slurp down every available device to patch the vulnerability that allowed Mirai to work in the first place?

It seems like if vulnerabilities in these devices can destabilize the entire internet that it should be perfectly viable as a response to actively look for those vulnerabilities, patch/minimize them and notify their creators of the issue.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#107

Earlier quoted context omitted.

I think that's okay. We don't expect all homeowners to be, say, experts in electrical wiring, or gas supply, plumbing, drainage, or waste management. But all of these things—if they are poorly modified, managed, or maintained—can cause impacts on third parties. In the case of networked devices, the possible impact on third parties is even greater. We also enforce strong regulation on these systems – defining what may…

Then we need to regulate the installation and maintenance of home networks like we do plumbing and electric. This is not a small requirement, and given the current ubiquity of home networks and networked devices it will be an incredible challenge to implement. Probably a startup idea or two would come out of that sort of regulation. Now that, to install that Nanny Cam, I have to hire a certified network administrator…

If the ISP were held responsible by contract, the ISP could either transfer that responsibility as described above or they could just filter their outbound a little harder. The latter solution seems more practical.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#108

I'm suggesting this just so someone more knowledgeable can debunk it. Suppose FBI or someone up there had a meeting and said "in three weeks, there could be millions of armed Americans who believe that democracy was just stolen from them by some evil dictator in a massive globalist conspiracy. These people love twitter. Is there a way to make twitter go down without making it look like we're suddenly pulling the plug…

I'll bite. It would take a lot longer than a couple of hours of twitter being down for that to have a useful effect. For something as major as the presidential election result, it would probably take minimum a week before people got bored and moved on to a different topic. So this kind of attack that only takes something out for a few hours would have no useful effect for an actor that wants to prevent people from di…

Sure it wouldnt work for an extended time. I'm just thinking that in an unpredictable situation, a few hours might be all you need to diffuse it. For example suppose someone claims they have evidence of some crazy shit happening at the polling places, and the only thing that can be done is to for Patriots to seize the equipment at the polling places before the globalists can cover their tracks.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#109

I'm suggesting this just so someone more knowledgeable can debunk it. Suppose FBI or someone up there had a meeting and said "in three weeks, there could be millions of armed Americans who believe that democracy was just stolen from them by some evil dictator in a massive globalist conspiracy. These people love twitter. Is there a way to make twitter go down without making it look like we're suddenly pulling the plug…

I'll bite. It would take a lot longer than a couple of hours of twitter being down for that to have a useful effect. For something as major as the presidential election result, it would probably take minimum a week before people got bored and moved on to a different topic. So this kind of attack that only takes something out for a few hours would have no useful effect for an actor that wants to prevent people from di…

[deleted]

Re: Possible Vendetta Behind the East Coast Web Slowdown

#110

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Exactly, I have tons of IOT devices. I put them on a separate subnet that does not have a gateway to the internet then I VPN into that network to access them. Perhaps a product that makes that a simple process will solve the problem?

We partly do that at Wormhole. I say partly because you still have to be able to access one of our addresses. Port of last resort is 443/TCP, so it works on lots of tricky networks out there.

The idea is that all your IOT stuff establishes a connection to this server, creating an encrypted network between them. You then add your control servers to that network and job done. You devices don't need any inbound access to talk to each other. All the connections are outbound, so no ports to open on your firewall and no risk.

You could do this by yourself, but we take that hassle out of your hands. Happy to help with custom deployments too outside our main service; it's a great way of learning our customers' needs.

It's hard though to have your exact setup as a service, it implies incoming VPN connections to the site where you deploy your IOT and a VPN server of sorts.

Our main focus was remote teams and devs having to use remote servers, however IOT might be a killer use here.

https://wormhole.network

Post reply on HN