Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

141–150 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#141

Earlier quoted context omitted.

While technically accurate to describe them as such, the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators. Where these devices are being attacked inside, ostensibly, professional organizations (companies, schools, government buildings), I agree. But there you have, again ostensibly, an actual network administrator capable of dealing with th…

"the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators." that's true, but the vast majority of internet service subscribers aren't their own network administrators. If you're using an ISP-supplied modem/router combo, i'd say that your ISP is your network administrator. If my ISP wants that kind of access into my local network (and they don't…

Under this concept, they'd be able to specify precisely what kinds of computers and IoT devices you'd be allowed to use on your home network. This would be a net-negative for the world.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#142
The failing here as in many cases such as a number of security breaches was a lack of investment. As someone with an engineering degree that worked as a VLSI design engineer, good engineering requires * backup systems *. This costs money that people don't want to spend. In some cases such as a startup they might be cash short, but many firms have the money but don't want to spend it ensuring that they have well engineered software that includes backups, up-to-date software and security upgrades, hiring (expensive) highly competent software engineers and consulting firms.

The mistake in this case was relying on one vendor for DNS. Amazon Route 53 would be a good alternate vendor for DNS, for example.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#143

Did any one else find the style of writing in this article really annoying? Things like using prefacing statements with "so-called" or putting terms in quotes to make them seem suspect. e.g.s: a so-called distributed denial-of-service (DDoS) attack York said Dyn was “actively” dealing with a “third wave” of the attack.

I tend to assume that the larger publications use it in the underlying sense of "..as it is so called".

Re: Possible Vendetta Behind the East Coast Web Slowdown

#144
post #104

Earlier quoted context omitted.

The real problem here, and this isn't going to be a popular position, is that you're relying on the internet for important things. The original engineering and architecture of the the internet (and the web) was not intended to create something you put all your eggs in. It was for sharing information, not building your mission critical business operations on. Right now, if you dumped your business into a cloud service…

Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.

ARPANET is nothing like the monstrosity we have today.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#145

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Exactly, I have tons of IOT devices. I put them on a separate subnet that does not have a gateway to the internet then I VPN into that network to access them. Perhaps a product that makes that a simple process will solve the problem?

I've been thinking about how you'd design a UI for that, that was easy to use. Maybe a separate wifi network that IOT devices go on to, and then a web app that knows devices with XYZ MAC are LIFX bulbs and shouldn't be able to talk to the smart TV, but that phones on the network should be able to jump the subnet and talk to the bulbs.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#146
post #104

Earlier quoted context omitted.

The real problem here, and this isn't going to be a popular position, is that you're relying on the internet for important things. The original engineering and architecture of the the internet (and the web) was not intended to create something you put all your eggs in. It was for sharing information, not building your mission critical business operations on. Right now, if you dumped your business into a cloud service…

Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.

No, it wasn't. That's a myth, disturbed in many sources, including [1]. Also in [2]:

Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Internet was invented. A project which began in the Pentagon that year, called Arpanet, gave birth to the Internet protocols sometime later (during the 1970's), but 1969 was not the Internet's beginnings. Surviving a nuclear attack was not Arpanet's motivation, nor was building a global communications network.

Bob Taylor, the Pentagon official who was in charge of the Pentagon's Advanced Research Projects Agency Network (or Arpanet) program, insists that the purpose was not military, but scientific. The nuclear attack theory was never part of the design. Nor was an Internet in the sense we know it part of the Pentagon's 1969 thinking. Larry Roberts, who was employed by Bob Taylor to build the Arpanet network, states that Arpanet was never intended to link people or be a communications and information facility.

[1] https://www.amazon.com/Where-Wizards-Stay-Up-Late/dp/0684832...

[2] http://www.nethistory.info/History%20of%20the%20Internet/beg...

Re: Possible Vendetta Behind the East Coast Web Slowdown

#147
post #104

Earlier quoted context omitted.

Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.

No, it wasn't. That's a myth, disturbed in many sources, including [1]. Also in [2]: Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Inte…

Where Wizards Stay Up Late is a fairly dry book, but it contains interesting kernels of information (like this). It's not a page turner, but it's worth a read if you are interested in things like, for example, the information in this comment's parent.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#148
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Ok, then they should be liable for any damage their lack of maintenance causes. The cost of properly maintaining your product is nothing compared to the lost business and repair costs caused by these DDOS attacks.

Being a small company doesn't mean you should be able to ship a defective product that is guaranteed to eventually become part of a botnet.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#149

Earlier quoted context omitted.

While technically accurate to describe them as such, the vast majority of consumers (and internet service subscribers) lack the actual technical expertise to be network administrators. Where these devices are being attacked inside, ostensibly, professional organizations (companies, schools, government buildings), I agree. But there you have, again ostensibly, an actual network administrator capable of dealing with th…

I think that's okay. We don't expect all homeowners to be, say, experts in electrical wiring, or gas supply, plumbing, drainage, or waste management. But all of these things—if they are poorly modified, managed, or maintained—can cause impacts on third parties. In the case of networked devices, the possible impact on third parties is even greater. We also enforce strong regulation on these systems – defining what may…

It's oscillation all over again:

http://airminded.org/2015/09/30/the-oscillation-of-r33/

Re: Possible Vendetta Behind the East Coast Web Slowdown

#150
post #59

Earlier quoted context omitted.

So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.

So grampa doesn't take care of his car, the brakes fail and he kills a family with four kids. Is he liable? Yes. He may not know the first thing about brakes or car repair but owns the car, and he took it out on the road without being sure it was in safe operating condition. But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have in…

I'm the "head fred" networking/infrastructure guy at an ISP. I want to avoid, as much as possible, peeking at my customer's traffic.

In my personal opinion, an ISP should be a dumb pipe. I'm providing you with the ability to send/receive "n" bits per second; I don't care whether you use it to participate in e-mail discussions with your church group or stream pornography and play online poker.

Are you certain you want ISPs to be responsible for monitoring all of your traffic and what you're doing online? Do you really want somebody else deciding -- at their own discretion -- what is "acceptable" for you to do online?

I'm very pro-privacy, pro-encryption, "pro-Internet freedom", etc., but the next guy may not be.

Post reply on HN