Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

161–170 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#161

Earlier quoted context omitted.

Interesting, I have a few thoughts. Perhaps you could sell a preconfigured pfsense box (or make a raspberry pi image to start with) that when plugged into the customers router creates a reverse tunnel via your service as well as a WiFi hotspot. Then offer the user a very simple firewall control panel and they can choose what devices to allow to the open internet and what to keep private and accessible via some sort o…

Hi! Thank you for the feedback and the suggestion. It is a good idea actually. I'm considering new features in the roadmap, because at the moment I don't even offer Internet access through my system, it's just a private LAN (I'm not competing with the myriad of privacy-minded browsing VPNs out there). Adding a manageable Internet Gateway could be a nice option. Developing and deploying a software+hardware piece would…

A flexible gateway would be a great add on, I also like a private DNS server while developing. If you offered a Postfix forwarder and static, clean IP addresses, you could attract home users who wish to host their own email but are behind dynamic residential connections (like me, I use a digital ocean droplet currently for that purpose).

Re: Possible Vendetta Behind the East Coast Web Slowdown

#162

Earlier quoted context omitted.

> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…

Which business model works best: - planned obsolescence cranked to 11, you must replace everything in your house every month - monthly subscription fees for each lightbulb, refrigerator, and everything else - all products must refuse to operate unless they can connect to a central update server (which is being DDOSed by competing products made in a country without that government mandate, that are still working, whil…

This one: Companies offer products that meet a consumer need without creating an effective, easily accessed platform for criminal third parties to tax the rest of us. If they can't do that, then they don't fucking offer the product. "The only way we can sell this is to enable DDOSes by Russian hackers!" is a reason to say "then don't offer the product!"

Re: Possible Vendetta Behind the East Coast Web Slowdown

#163
post #158

Earlier quoted context omitted.

From the article: "Last month, a hacker by the name of Anna_Senpai released the source code for Mirai, a crime machine that enslaves IoT devices for use in large DDoS attacks. The 620 Gbps attack that hit my site last month was launched by a botnet built on Mirai, for example." I repeatedly hear people refer to IoT devices that are notoriously difficult to update...yet this Mirai code is technically able to access mi…

The problem is you're reading the situation wrong. Mirai isn't about an exploit, it's IoT devices that haven't had the default username/password changed. Now, you might say "why doesn't a good samritan just login to all of those devices and change the password to something random?" OK - ignoring the fact that THEY would be committing felonies in several countries... what happens when the device manufacturer wakes up…

I guess that's what I'm getting at though. If we were to scan for the affected devices, change the passwords and notify the manufacturer of the change and that it was made because their carelessness essentially endangered the internet it would make it possible for them to fix it.

You're plugging a leak and letting the owner know, hey this was leaking and I stopped it but you're going to need to address that.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#164
post #78

I always thought DNS had enough redundancy built-in that this sort of thing wouldn't really have much effect. But here I am unable to access websites, simply because name resolution isn't working. If my local DNS server were caching things longer there would largely be no issue.

Yeah, DNS entries are usually (or at least used to be) cached for what would seem like long enough, but I guess it doesn't really work the way it sounds. "a hierarchical decentralized naming system [that] provides distributed and fault tolerant service and was designed to avoid a single large central database" doesn't sound like it should be so fragile. Having single 'authoritative' servers for the sort of thing that should be inherently distributed sounds more like an Achilles heel.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#165

Earlier quoted context omitted.

Then we need to regulate the installation and maintenance of home networks like we do plumbing and electric. This is not a small requirement, and given the current ubiquity of home networks and networked devices it will be an incredible challenge to implement. Probably a startup idea or two would come out of that sort of regulation. Now that, to install that Nanny Cam, I have to hire a certified network administrator…

If the ISP were held responsible by contract, the ISP could either transfer that responsibility as described above or they could just filter their outbound a little harder. The latter solution seems more practical.

Or they could go the cheap route, and have a whitelist of devices you're allowed to use on your network.

Huh, weird, this whitelist seems to mostly consist of devices the ISP would be glad to rent out to you on a monthly basis...

Re: Possible Vendetta Behind the East Coast Web Slowdown

#166

Earlier quoted context omitted.

Why can't everyone else then block the customer? Get the big 5 tech companies to block IPs that are shown to do DDOS, for say a 24hr period, and you will see how quickly they unplug that IOT Toaster

Speaking as not-me, the average, non-technical homeowner who just installed his new internet connected washing machine at home. Great, now I can throw in a load and get a notice on my phone when it's done. This is awesome! (3 hours later) Wait, why can't I get to the internet? I call my ISP, they tell me that my connection is fine (it's tech support, they aren't security experts). But, I tell them, Google doesn't wor…

> Maybe they kick back a message as a 4xx (what would be appropriate?) that says my network has been hacked

429 seems appropriate.

Or maybe even 451.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#167
post #99

Earlier quoted context omitted.

FWIW, I would definitely be interested in paying for a service like this. I'm technical enough to care about this, but not technical enough to solve it myself. Similar to where I was before dropbox.

My comment here might be relevant to your interests: https://news.ycombinator.com/item?id=12765051 It could suit your needs or we can help with custom deployments. In any case I'd like to learn more about your needs and your expectations. Can I drop you an email?

totally, it's in my profile

Re: Possible Vendetta Behind the East Coast Web Slowdown

#168

Earlier quoted context omitted.

These attacks are mostly possible because of the complacency of operators at many sites and companies. This is not a new problem and many of RFC's talk about methods for preventing and mitigating them, but most people don't care and prefer to just outsource everything to a single provider, which becomes the weakest link. The Internet wasn't envisioned with a single email provider, single DNS provider, single app cont…

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

heh. move over user-centered design, user-centered malign is making a come-back :)

Re: Possible Vendetta Behind the East Coast Web Slowdown

#169
post #151

Earlier quoted context omitted.

No, it wasn't. That's a myth, disturbed in many sources, including [1]. Also in [2]: Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Inte…

> Arpanet was about time-sharing. Time sharing tried to make it possible for research institutions to use the processing power of other institutions computers when they had large calculations to do that required more power, or when someone else's facility might do the job better. Arpanet is distributed shared information for science. Nuclear technology is science. Surviving science is a war that requires nuclear insi…

As Aristotle might have said if he were here, you committed an error in syllogism number 56.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#170

Earlier quoted context omitted.

I think that's okay. We don't expect all homeowners to be, say, experts in electrical wiring, or gas supply, plumbing, drainage, or waste management. But all of these things—if they are poorly modified, managed, or maintained—can cause impacts on third parties. In the case of networked devices, the possible impact on third parties is even greater. We also enforce strong regulation on these systems – defining what may…

Then we need to regulate the installation and maintenance of home networks like we do plumbing and electric. This is not a small requirement, and given the current ubiquity of home networks and networked devices it will be an incredible challenge to implement. Probably a startup idea or two would come out of that sort of regulation. Now that, to install that Nanny Cam, I have to hire a certified network administrator…

What sort of regulation are you referring to? I'm not a plumber or electrician but I replace broken faucets and light switches. No certification required.
Post reply on HN