Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

181–190 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#181
post #93
post #80

Earlier quoted context omitted.

Neither the headline nor the bullet point "summary" actually delivers the promised information about a possible vendetta. The goal is obviously to bury the information as deep as possible in the article to increase the likelihood that readers will click on ads.

You're upset that the headline doesn't deliver info on what the headline tells you? That doesn't make any sense. And the bullets are providing context for the article, not trying to answer the headline.

Upon reading TFA three times, it is still unclear to me who is waging a vendetta against whom. I vote clickbait as well.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#182
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

Yep, and manufacturers have not much incentive to update firmware for a device which is not their latest greatest or update firmware while not adding more features to help them sell more. Security isn't a feature that the vast majority of consumers would pay extra for or know how to verify anyway. There was plenty of demand for that one "unhackable" android phone, but I'd be blown away if it wasn't 100% snake oil. My…

This isn't just small manufacturers either. I bought a new Samsung tablet for my kid two weeks ago. It is running a three year old version of Android with no updates available. Pretty shocking.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#183
post #118

Earlier quoted context omitted.

Indeed. My mom got an internet connected "security camera" kit (for cheap from one of the big wholesalers, can't remember the manufacturer) and asked me to set it up. The hardware was nice, cameras did a reliable 1080p full color, but the whole reason my mom wanted it was so she could check in while she and my dad were traveling (and also sneak a peek at her bird feeders while she was away; avid birder, that one). So…

> Admittedly, it did have some authentication for accessing the video streams, but I didn't trust that thing as far as I could throw it So...you wanted to have authentication and it has authentication...I must be missing something.

So...you wanted to have authentication and it has authentication...I must be missing something

You missed that you could SSH into it with a default password that is easy to find on a web search.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#184
post #118

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Indeed. My mom got an internet connected "security camera" kit (for cheap from one of the big wholesalers, can't remember the manufacturer) and asked me to set it up. The hardware was nice, cameras did a reliable 1080p full color, but the whole reason my mom wanted it was so she could check in while she and my dad were traveling (and also sneak a peek at her bird feeders while she was away; avid birder, that one). So…

I will be interested if you take time to write this up.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#185
post #136
post #121

Earlier quoted context omitted.

For non-technical users, I'd suggest the following: Turn off the devices you don't want to check; leave only those up you want to investigate. Visit your router on the web interface and see if there are any graphs are possible to check for things like requests/second or packets/second. If it's really high while you're not actively doing anything, that's a clue. Visit the UPnP settings on the router. If there are port…

> For non-technical users, ... routers ... packets ... UPnP ... SSH ... tcpdump ... wireshark ... protocol ... telnet ... IRC ... plain text commands ... I think you unintentionally helped to cement GP's point. There is a huge opportunity for some kind of little box - vetted/certified or even insured - that non-technical users can plug in, click Next > Next > Finish, and be notified when any device on their home netw…

I'm so tired of this.We live in a higly technical world and people should learn the basics. One of the reasons we are having this situation is because people don't understand their things.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#186
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

These attacks are mostly possible because of the complacency of operators at many sites and companies. This is not a new problem and many of RFC's talk about methods for preventing and mitigating them, but most people don't care and prefer to just outsource everything to a single provider, which becomes the weakest link. The Internet wasn't envisioned with a single email provider, single DNS provider, single app cont…

Seriously? It's OK if only one site/company gets taken offline at a time?

There's no RFC that talks about methods for preventing or mitigating hundreds of thousands of machines all sending arbitrary traffic at you at the same time.

The only way to protect yourself from that sort of attack is to buy filtering from someone who has a bigger pipe than the largest DDoS available, and have them filter the packets so that you only get clean traffic. Unless you know of an alternative that nobody else has heard of yet.

So you wind up buying transit / scrubbing from one of a few big providers, because that's the only way to avoid being sniped by DDoSers.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#187

I am a non-programmer who reads HN and keeps up with tech news in general. And every time I read about the IoT botnet, my immediate response is to look around my apartment at my Internet-connected lights, and wonder if they're part of it. How can I find this out? Is anyone making a tool that a non-technical user can run to squint at their network and look for evidence of Mirai, or anything else trying to take advanta…

Looking over all the replies this comment received, I think my plan for seeing if my apartment's Internet Things are on any botnet is going to be "bribe that security researcher I flirt with sometimes to visit my place and run some tests". Which is not really a solution that scales, either for that friend, or for people who don't happen to run in the kinds of circles where that's someone they could conceivably trade…

> bribe that security researcher I flirt with sometimes to visit my place and run some tests...[w]hich is not really a solution that scales...

Assuming the flirting displayed is sincere, that security researcher may prove much more scalable than you'd imagine.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#188
post #136

Earlier quoted context omitted.

> For non-technical users, ... routers ... packets ... UPnP ... SSH ... tcpdump ... wireshark ... protocol ... telnet ... IRC ... plain text commands ... I think you unintentionally helped to cement GP's point. There is a huge opportunity for some kind of little box - vetted/certified or even insured - that non-technical users can plug in, click Next > Next > Finish, and be notified when any device on their home netw…

Precisely. Users need something as simple as Malwarebytes where they just need to click the big 'Scan' button and after a few minutes it will say "Your living room ceiling fan is running a potentially unwanted program (bitcoinminer), your freezer is infected with a virus, your garage door opener is participating in a botnet, and your fitbit has a rootkit. Click here to quarantine and disinfect everything. Click here…

Well, you wouldn't necessarily need to determine what software is running on any device to quarantine it. However, what would be helpful would be some kind of central registry of botnet traffic signatures so that the scanner could use something more than just traffic volume.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#189

Earlier quoted context omitted.

Speaking as not-me, the average, non-technical homeowner who just installed his new internet connected washing machine at home. Great, now I can throw in a load and get a notice on my phone when it's done. This is awesome! (3 hours later) Wait, why can't I get to the internet? I call my ISP, they tell me that my connection is fine (it's tech support, they aren't security experts). But, I tell them, Google doesn't wor…

From my point of view as someone who is no longer ddos'd, I don't have a problem with this.

Wait, isn't this whole plan a massively worse DDoS than what we experienced today?

By exploiting a toaster, the attacker could shut off the domestic internet service entirely, rather than just disrupting Netflix.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#190
post #59

Earlier quoted context omitted.

So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.

So grampa doesn't take care of his car, the brakes fail and he kills a family with four kids. Is he liable? Yes. He may not know the first thing about brakes or car repair but owns the car, and he took it out on the road without being sure it was in safe operating condition. But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have in…

And here we go with what is malicious traffic.

Leaked news put the government in shame?

Copyrighted materail transmission?

Code to raise the temperature of some heater?

Post reply on HN