Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

121–130 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#121
post #30

Earlier quoted context omitted.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

It depends on exactly what services Schneier is talking about here, but an awful lot of the infrastructure of the internet is hosted in countries that the US armed forces have easy physical access to. Even if a cyber attack were the "plan a" for quickly and untraceably taking those systems out, the US has an easy enough "plan b" that testing "plan a" isn't going to be a major concern. Add that to the fact that the US…

> Add that to the fact that the US has a lot more to lose if it gets caught attacking internet infrastructure than China and friends do (even just tests like this) and I would be surprised (honestly not shocked, but definitely surprised) if the USA is behind these shenanigans.

So can you give me the address of the rock you've been living under for the past 3 years?

Re: Someone Is Learning How to Take Down the Internet

#122
>The NSA, which has more surveillance in the Internet backbone than everyone else combined, probably has a better idea, but unless the U.S. decides to make an international incident over this, we won't see any attribution.

Or unless it's the US itself. Not the most likely possibility I think, but still a possibility.

Re: Someone Is Learning How to Take Down the Internet

#123
post #42
post #6

Earlier quoted context omitted.

If Verisign is running the nameservers for .com and .net, it will cause DNS problems across the board. We'd have to rely on DNS caches until new .net and .com nameservers come up. This would impact not only new domain registrations, but DR grade migrations, and DNSSEC. If coordinated with an attack against the root nameservers so we couldn't change the .com and .net nameservers, DNS would become a real disaster. If c…

Would there a use case for decentralizing DNS into blockchain, or for creating an alternative?

I think the problem with the blockchain is that it is relatively immutable, while the internet is anything but. Also, the cost for making a Namecoin change is inexpensive now, but if it were to take over full operations for even one TLD, that would not remain the case.

Re: Someone Is Learning How to Take Down the Internet

#124
post #90

Earlier quoted context omitted.

The man lived through a tsunami in the area, that was hardly a matter of exciting thoughts, but a desperate desire to prevent a predictable tragedy. By contrast people prepping for the end of days in whatever form, often nuclear, strike me as mad. If there's a nuclear war, I want to be in the hypocenter of the first detonation, because we're not climbing out of that hole as a species in any meaningful way. I suppose…

Agreed, if civilization does come tumbling down. However, as far as I could read, for it to survive a nuclear exchange is quite possible, even probable. Blasts themselves seem relatively harmless, beyond the hundereds of millions they just outright kill that is, radiation we're just characteristically paranoid about, but can actually deal with at least in many remaining areas, and the main issue at debate is whether…

It depends on if we're talking about Pakistan and India dusting each other, or the US and Russia pulling the trigger. In the former case it's as uncertain as you said, but in the latter to be honest, we're done. Huge areas will be utterly toxic, and there will be infrastructure or meaningful leadership to let anyone know where those are.

So I grant you that something a bit less hopeful and dramatic than 'Mad Max' is more than possible, but only as part of a long slide into the end of our species.

While "Humans" would almost certainly survive (for a while), the odds of any given human (i.e. you or me) surviving are pretty poor. At best you'd be looking at generations of struggle and misery, and then what? Our way of life came to pass by a number of factors including the ready availability of coal. That's... not coming back either. Resources that don't' require extreme mining are generally depleted already, from fossil fuels to various metals.

The various steps that brought us up from mud huts don't necessarily work for another round.

Re: Someone Is Learning How to Take Down the Internet

#125
post #33

Earlier quoted context omitted.

We've already shown that we can pretty effective destroy a country's infrastructure from the air as well, not just with explosives and incendiaries, but other clever tricks as well.

Such as...

Such as, for one example that's been used to great effect: https://en.wikipedia.org/wiki/Graphite_bomb

Re: Someone Is Learning How to Take Down the Internet

#126

This is why I worry about the centralization of all communications as we've done over the entirety of human history. Letting the Internet be centralized as it has been might be make economic sense but as for sustaining the world economy through a potentially global conflict it doesn't make any sense to put all our eggs in one basket here. It's like I mentioned on the "napalm girl" post that we've become too complacen…

The internet is decentralized, for the most part; it was designed to be that way from the start. Whole pieces of the internet can go offline that the rest of it will continue operating as normal, with packets routed around the damage. The TCP and IP protocols were designed for this.

It's not the designers fault that so many people are dumb enough to happily give one company a near-monopoly over certain forms of communication.

It's very simple: stop using Facebook for everything. Use different sites/services, or switch to a decentralized service like Diaspora. Otherwise, stick with Facebook for everything and stop complaining when it bites you in the butt, and suffer the consequences when disaster strikes.

Re: Someone Is Learning How to Take Down the Internet

#127

Earlier quoted context omitted.

I don't think we should rule out the US, as they conduct defense drills all of the time. In this case, they don't overtly control the assets under attack, but would still want to know how resilient our networks are "in the real world" -- not always as a "friendly" drill, a la Red Cell. https://en.wikipedia.org/wiki/Red_Cell

Link to the videos next time: https://www.youtube.com/watch?v=hWCX6IeBH7U They'll learn a lot more from them. ;)

Better still, link to both, as has happened here. People are often in situations where a wall of text is easier than a video, and vice versa.

Re: Someone Is Learning How to Take Down the Internet

#128
post #111

Earlier quoted context omitted.

> top priority change of the Internet See you in thirty years. Also, IP authentication doesn't help you. DDOS traffic often has real IP source addresses on. It tells you that the traffic is several hundred thousand home PCs. Now what?

If you knew for sure that an IP src address involved in a DDoS attack was not spoofed, we could easily design a control protocol that allowed a recipient to contact the origin ISP and enable a block on that particular {src,dst} pair. Unless you know for sure that the src address isn't spoofed though, such a mechanism would itself be abused to deny service. Having the ability to validate a source address would be the…

> Unless you know for sure that the src address isn't spoofed though, such a mechanism would itself be abused to deny service.

Unfortunately, even if you know that the source address isn't spoofed, such a mechanism would itself be abused to deny service

Re: Someone Is Learning How to Take Down the Internet

#129
post #124

Earlier quoted context omitted.

Agreed, if civilization does come tumbling down. However, as far as I could read, for it to survive a nuclear exchange is quite possible, even probable. Blasts themselves seem relatively harmless, beyond the hundereds of millions they just outright kill that is, radiation we're just characteristically paranoid about, but can actually deal with at least in many remaining areas, and the main issue at debate is whether…

It depends on if we're talking about Pakistan and India dusting each other, or the US and Russia pulling the trigger. In the former case it's as uncertain as you said, but in the latter to be honest, we're done. Huge areas will be utterly toxic, and there will be infrastructure or meaningful leadership to let anyone know where those are. So I grant you that something a bit less hopeful and dramatic than 'Mad Max' is…

hah, mostly very good points

IDK, for one I'm not even sure a major exchange is as deadly as here supposed (much depends on who else joins the party I guess); sure lots of land on some continents at least is badly irradiated, but a majority is not quite as bad, and most of radiation degrades quickly, some simple measures help, and besides not everyone needs to survive every year After Launch anyhow, and non-extreme radiation doses kill only statistically. Much depends on - as you say, on how much of state command structure is able to survive and organize the remains, and that could easily vary from state to state on the planet.

I lived through a minor war in my youth, with the frontline maybe 2km at its closest approach and regular shelling for IDK couple of years. It was a remarkably well-ordered affair, considering. Fact half the GDP evaporated and rest was put under direct government command for war and other logistical purposes didn't really constitute a panic collapse of societal order or anything like that, and return to some kind of (low budget) normality quite quick. Kinda remarkable in retrospect, in how badly we react to small upsets, like a high-single digit GDP loss in a recession, yet tolerate such major disasters...

If the number of people directly killed is on the order of a few hundered million, thats not a substantial part of the humankind, so it may not be too different -- to people living in places too boring to have been hit by a nuke and not too close downwind from something interesting, ofc.

Guess it becomes worse if all the players hit all the other players, and no further advances in reducing nuclear inventories are made before it hits etc.

But again, yeah, a societal collapse is certainly a kill-myself kind of event for me too, because as you say - we're never gonna rebuild if we fall to that point. I'm just more sanguine about nukes being lobbed about not necessarily causing this I guess.

Re: Someone Is Learning How to Take Down the Internet

#130
post #7

Earlier quoted context omitted.

Poor wording. Verisign operates .com for the US government. So if Verisign's .com servers were to go down, then .com would go down with them. The author shouldn't have used the word "registrar" which makes people think of the creation of new domain names, à la GANDI (good) or GoDaddy (bad).

What does it mean "operates .com" and ".com would go down"? Does it mean that "google.com" would suddenly stop resolving? If so, how is that possible given the way DNS works? If not, what exactly is the panic about?

Most DNS resolvers come with a 'root zone hints file', which includes a list of the root nameservers and static IPs for each one.

When you look up google.com, these root nameservers are queried for com, and they return the results (name and IP) for the nameservers for .com

These nameservers for com are then queried for google.com, which then return the results for the nameservers for google.com.

Google's nameservers are then queried for google.com, and an IP is returned.

So yes, given how DNS works, all .com and .net domains would stop resolving if the Verisign nameservers for .com and .net were to go down. Most people go through caching nameservers, which would retain the values for google.com, and continue to return them, up until the time to live on those records expired, at which point they too would stop returning any values if the upstream servers hadn't returned before then.

Post reply on HN