Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

131–140 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#131
post #90

Earlier quoted context omitted.

You mean, like this guy? http://www.dailymail.co.uk/news/article-1386978/The-Japanese...

The man lived through a tsunami in the area, that was hardly a matter of exciting thoughts, but a desperate desire to prevent a predictable tragedy. By contrast people prepping for the end of days in whatever form, often nuclear, strike me as mad. If there's a nuclear war, I want to be in the hypocenter of the first detonation, because we're not climbing out of that hole as a species in any meaningful way. I suppose…

Serious question: what if you're enslaved by aliens before you can gun?

Re: Someone Is Learning How to Take Down the Internet

#132

Earlier quoted context omitted.

Link to the videos next time: https://www.youtube.com/watch?v=hWCX6IeBH7U They'll learn a lot more from them. ;)

Better still, link to both, as has happened here. People are often in situations where a wall of text is easier than a video, and vice versa.

Oh yeah, I agree. Correction accepted. I figured they'd like option to see it for themselves. :)

Re: Someone Is Learning How to Take Down the Internet

#133
post #111
post #107

I totally disagree that we can't do anything. With the existing TCP/IP protocol we can't do anything because it's possible to forge the origin IP address or modify the datagram content on its route to destination. A receiving end has no way to verify the validity of the datagram. An IP datagram authentication at the lowest level is required so that anyone on the route can detect forgery, error or tempering with the d…

> top priority change of the Internet See you in thirty years. Also, IP authentication doesn't help you. DDOS traffic often has real IP source addresses on. It tells you that the traffic is several hundred thousand home PCs. Now what?

Trying to cause serious mayhem with spoofed addresses is pointless. Most DDOS comes from bot nets, not from the attacker's personal resources. If you deployed a system that tried to spoof addresses all the needs to happen to eliminate 90% of your attack is for Comcast and co. to implement edge filtering such that traffic inbound from people's computers is dumped if it's not an address that can reasonably come from that origin.

And, since each additional node in the bot net has zero marginal cost, why bother trying to hide the device anyway?

Re: Someone Is Learning How to Take Down the Internet

#134
post #90

Earlier quoted context omitted.

The man lived through a tsunami in the area, that was hardly a matter of exciting thoughts, but a desperate desire to prevent a predictable tragedy. By contrast people prepping for the end of days in whatever form, often nuclear, strike me as mad. If there's a nuclear war, I want to be in the hypocenter of the first detonation, because we're not climbing out of that hole as a species in any meaningful way. I suppose…

Serious question: what if you're enslaved by aliens before you can gun?

Then... I'd be enslaved in your hypothetical, and by definition would have no choices I could make.

Re: Someone Is Learning How to Take Down the Internet

#135
post #95
post #72

Earlier quoted context omitted.

There's also the issue of the dubious legality of using encryption over eg HAMNET. Modern internet without encryption simply isn't modern internet.

The legality of encryption on ham isn't dubious, it's explicitly not allowed. I don't know if there's any legal precedent or official policy regarding digital signatures; I would guess that they're probably okay because they don't obscure the meaning of the communication and anyone can verify them against the sender's public key (assuming that the public keys are published somewhere). Communication with no privacy bu…

My understanding is that it's a little bit more grey than that. Modification of signals with an intent to obscure the content of the transmission is explicitly forbidden. But obfuscation for other reasons is not expressly forbidden. So there's a question of "is this incidentally encrypted, or intentionally encrypted", which is (again, from my understanding, which is very limited) why I'm calling it dubious and not simply "forbidden".

Re: Someone Is Learning How to Take Down the Internet

#136
post #111

Earlier quoted context omitted.

> top priority change of the Internet See you in thirty years. Also, IP authentication doesn't help you. DDOS traffic often has real IP source addresses on. It tells you that the traffic is several hundred thousand home PCs. Now what?

Trying to cause serious mayhem with spoofed addresses is pointless. Most DDOS comes from bot nets, not from the attacker's personal resources. If you deployed a system that tried to spoof addresses all the needs to happen to eliminate 90% of your attack is for Comcast and co. to implement edge filtering such that traffic inbound from people's computers is dumped if it's not an address that can reasonably come from th…

Bots use real address because nothing is done to track them and require the owner or OS provider to fix them. They currently have no incentive to fix the problem.

Collecting the source IP addresses of a DDOS attack is the first thing that could be done. Then progressive pressure should be put to enforce fixing the computers and get rid of the bots. OS with weak security would then feel the pain.

The day this is done, the next step will be to use forged source IP address. What would be the incentive for ISP to pay the price to filter packets ? As long as no one will be able to prove that the packet is forged, they won't do anything.

Re: Someone Is Learning How to Take Down the Internet

#137
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

Every once in a while I think of creating a little DNS cache that never expires entries, except when it runs out of storage, and run it on a Raspberry Pi, feeding it with DNS queries on my home network (but never using it to send replies to clients, just store queries and results). But I never do anything about it.

You can use dnstap with unbound or BIND 9.11 to do this kind of data collection really easily.

Re: Someone Is Learning How to Take Down the Internet

#138

This is why I worry about the centralization of all communications as we've done over the entirety of human history. Letting the Internet be centralized as it has been might be make economic sense but as for sustaining the world economy through a potentially global conflict it doesn't make any sense to put all our eggs in one basket here. It's like I mentioned on the "napalm girl" post that we've become too complacen…

The internet is decentralized, for the most part; it was designed to be that way from the start. Whole pieces of the internet can go offline that the rest of it will continue operating as normal, with packets routed around the damage. The TCP and IP protocols were designed for this. It's not the designers fault that so many people are dumb enough to happily give one company a near-monopoly over certain forms of commu…

You're confusing the issue by focusing on protocols versus actual physical implementations (data centers, trunk lines, etc). The physical installations for what we call the Internet are centralized. Companies like Level 3 might put some redundancy but at some point the cost of redundancy out weighs its benefits for them and other companies like them. This is especially true of consumer financial services like banking. If an attacker wanted to disrupt the United States they only have to do it to banking to cause a panic. They could easily ignore emergency services, hospitals, and even the government itself (outside of ACH) while doing this. And it would be such a mess that we couldn't resolve it immediately. The happiest outcome is the disruption is only for a few hours but the more likely outcome is possibly days or weeks of disruption where a large part of the banking system would be inoperable. It doesn't matter if you used TCP/IP or switch based communications the outcome is the same: the American economy shaken and possibly worse. So, we can take all day about Facebook and Diaspora but neither of those services do anything important for the average user like your bank which also uses the same centralized infrastructure. There is no Diaspora for banking and not one that's widely used or not using the current banking/financial transfer systems which are centralized.

Re: Someone Is Learning How to Take Down the Internet

#139
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

https://indico.dns-oarc.net/event/25/session/4/contribution/...

Could be an interesting, peripherally relevant talk...

Re: Someone Is Learning How to Take Down the Internet

#140

Earlier quoted context omitted.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

I was wondering the same thing. My assumption would be that either: 1) The US has nothing to gain by taking down the internet infrastructure via malicious means. or 2) The US has better access to these systems to take them out directly rather than forcing them down via DDOS attacks.

I think both. This sort of thing would be extremely disruptive to our economy.

I have no doubt, however, that we likely have developed plans around this sort of thing in a defensive or response capacity.

Post reply on HN