Earlier quoted context omitted.
While technically accurate to describe them as such, the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators. Where these devices are being attacked inside, ostensibly, professional organizations (companies, schools, government buildings), I agree. But there you have, again ostensibly, an actual network administrator capable of dealing with th…
"the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators." that's true, but the vast majority of internet service subscribers aren't their own network administrators. If you're using an ISP-supplied modem/router combo, i'd say that your ISP is your network administrator. If my ISP wants that kind of access into my local network (and they don't…
Possible Vendetta Behind the East Coast Web Slowdown
141–150 of 206 posts
Re: Possible Vendetta Behind the East Coast Web Slowdown
#142The mistake in this case was relying on one vendor for DNS. Amazon Route 53 would be a good alternate vendor for DNS, for example.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#143Did any one else find the style of writing in this article really annoying? Things like using prefacing statements with "so-called" or putting terms in quotes to make them seem suspect. e.g.s: a so-called distributed denial-of-service (DDoS) attack York said Dyn was “actively” dealing with a “third wave” of the attack.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#144Earlier quoted context omitted.
The real problem here, and this isn't going to be a popular position, is that you're relying on the internet for important things. The original engineering and architecture of the the internet (and the web) was not intended to create something you put all your eggs in. It was for sharing information, not building your mission critical business operations on. Right now, if you dumped your business into a cloud service…
Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#145Earlier quoted context omitted.
The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.
Exactly, I have tons of IOT devices. I put them on a separate subnet that does not have a gateway to the internet then I VPN into that network to access them. Perhaps a product that makes that a simple process will solve the problem?
Re: Possible Vendetta Behind the East Coast Web Slowdown
#146Earlier quoted context omitted.
The real problem here, and this isn't going to be a popular position, is that you're relying on the internet for important things. The original engineering and architecture of the the internet (and the web) was not intended to create something you put all your eggs in. It was for sharing information, not building your mission critical business operations on. Right now, if you dumped your business into a cloud service…
Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.
Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Internet was invented. A project which began in the Pentagon that year, called Arpanet, gave birth to the Internet protocols sometime later (during the 1970's), but 1969 was not the Internet's beginnings. Surviving a nuclear attack was not Arpanet's motivation, nor was building a global communications network.
Bob Taylor, the Pentagon official who was in charge of the Pentagon's Advanced Research Projects Agency Network (or Arpanet) program, insists that the purpose was not military, but scientific. The nuclear attack theory was never part of the design. Nor was an Internet in the sense we know it part of the Pentagon's 1969 thinking. Larry Roberts, who was employed by Bob Taylor to build the Arpanet network, states that Arpanet was never intended to link people or be a communications and information facility.
[1] https://www.amazon.com/Where-Wizards-Stay-Up-Late/dp/0684832...
[2] http://www.nethistory.info/History%20of%20the%20Internet/beg...
Re: Possible Vendetta Behind the East Coast Web Slowdown
#147Earlier quoted context omitted.
Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.
No, it wasn't. That's a myth, disturbed in many sources, including [1]. Also in [2]: Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Inte…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#148Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable
Being a small company doesn't mean you should be able to ship a defective product that is guaranteed to eventually become part of a botnet.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#149Earlier quoted context omitted.
While technically accurate to describe them as such, the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators. Where these devices are being attacked inside, ostensibly, professional organizations (companies, schools, government buildings), I agree. But there you have, again ostensibly, an actual network administrator capable of dealing with th…
I think that's okay. We don't expect all homeowners to be, say, experts in electrical wiring, or gas supply, plumbing, drainage, or waste management. But all of these things—if they are poorly modified, managed, or maintained—can cause impacts on third parties. In the case of networked devices, the possible impact on third parties is even greater. We also enforce strong regulation on these systems – defining what may…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#150Earlier quoted context omitted.
So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.
So grampa doesn't take care of his car, the brakes fail and he kills a family with four kids. Is he liable? Yes. He may not know the first thing about brakes or car repair but owns the car, and he took it out on the road without being sure it was in safe operating condition. But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have in…
In my personal opinion, an ISP should be a dumb pipe. I'm providing you with the ability to send/receive "n" bits per second; I don't care whether you use it to participate in e-mail discussions with your church group or stream pornography and play online poker.
Are you certain you want ISPs to be responsible for monitoring all of your traffic and what you're doing online? Do you really want somebody else deciding -- at their own discretion -- what is "acceptable" for you to do online?
I'm very pro-privacy, pro-encryption, "pro-Internet freedom", etc., but the next guy may not be.