Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

191–200 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#191
I love those comments about IoT and who should be responsible for error-proof products, or ISP monitoring traffic, or ...

Internet, in the beginning, was even more insecure. Including the computers and OSes. There were less abuse because few had resources and knowledge. Read some old software and you'll find all bad designs in it. Software didn't become worst, it's just targeted with more knowledge and intensity.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#192
post #93
post #80

Earlier quoted context omitted.

Neither the headline nor the bullet point "summary" actually delivers the promised information about a possible vendetta. The goal is obviously to bury the information as deep as possible in the article to increase the likelihood that readers will click on ads.

You're upset that the headline doesn't deliver info on what the headline tells you? That doesn't make any sense. And the bullets are providing context for the article, not trying to answer the headline.

In a news article, the lede (first 1-3 paragraphs) typically contains the who, what, where, why. The rest of the article is usually interesting background and speculation. This article doesn't even "bury the lede". It contains no who. If you read the whole article and you think about it deeply, you might come to the conclusion that someone is DDOS'ing the people who publicly connect the dots between security researchers and bad actors (on a theoretical level). This is a vendetta apparently, but the word "vendetta" doesn't appear in the story. In other words, the story doesn't deliver the headline.

We could write the lede differently to support the headline. "A major attack is underway targeting another company who publicly drew an association between hackers and security researchers. Dyn, a provider of DNS services, is experiencing a DDOS attack similar to the one experienced by Bruce Schneier.

"The attack occurred coincidentally with a suggestion by Dyn's security director that some hackers and security researchers may be the one and the same. Mr. Schneier also made similar connections before the attack on his servers."

Now, I know what might be going on.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#193
post #170

Earlier quoted context omitted.

Then we need to regulate the installation and maintenance of home networks like we do plumbing and electric. This is not a small requirement, and given the current ubiquity of home networks and networked devices it will be an incredible challenge to implement. Probably a startup idea or two would come out of that sort of regulation. Now that, to install that Nanny Cam, I have to hire a certified network administrator…

What sort of regulation are you referring to? I'm not a plumber or electrician but I replace broken faucets and light switches. No certification required.

I was more referring to requiring homes be up to code. You're right that individual projects don't really require anything special, more important when building new buildings.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#194

Earlier quoted context omitted.

> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…

Which business model works best: - planned obsolescence cranked to 11, you must replace everything in your house every month - monthly subscription fees for each lightbulb, refrigerator, and everything else - all products must refuse to operate unless they can connect to a central update server (which is being DDOSed by competing products made in a country without that government mandate, that are still working, whil…

Fun fact, we have working systems for peer-to-peer publish/subscribe systems that only need a known peer to bootstrap off of, and then are reasonably resilient to nodes disappearing etc. No need to have central update servers - just push a signed message into some random selection of machines and go!

Re: Possible Vendetta Behind the East Coast Web Slowdown

#195
post #104

Earlier quoted context omitted.

Actually, the original engineering and architecture of the internet was intended to provide reliable command & control in the event of a nuclear war. A network of last resort. I can't think of anything more mission critical than that.

No, it wasn't. That's a myth, disturbed in many sources, including [1]. Also in [2]: Many people have heard that the Internet began with some military computers in the Pentagon called Arpanet in 1969. The theory goes on to suggest that the network was designed to survive a nuclear attack. However, whichever definition of what the Internet is we use, neither the Pentagon nor 1969 hold up as the time and place the Inte…

A few oral history interviews with key actors also confirm this.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#196

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Exactly, I have tons of IOT devices. I put them on a separate subnet that does not have a gateway to the internet then I VPN into that network to access them. Perhaps a product that makes that a simple process will solve the problem?

The problem with any solution is getting it used widely enough to make a difference. We seem to have an unlimited predilection for making the same mistakes repeatedly, even though we could avoid them.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#197

Earlier quoted context omitted.

These attacks are mostly possible because of the complacency of operators at many sites and companies. This is not a new problem and many of RFC's talk about methods for preventing and mitigating them, but most people don't care and prefer to just outsource everything to a single provider, which becomes the weakest link. The Internet wasn't envisioned with a single email provider, single DNS provider, single app cont…

Seriously? It's OK if only one site/company gets taken offline at a time? There's no RFC that talks about methods for preventing or mitigating hundreds of thousands of machines all sending arbitrary traffic at you at the same time. The only way to protect yourself from that sort of attack is to buy filtering from someone who has a bigger pipe than the largest DDoS available, and have them filter the packets so that y…

> There's no RFC that talks about methods for preventing or mitigating hundreds of thousands of machines all sending arbitrary traffic at you at the same time.

The RFCs generally say that the problem is "you", i.e. the target. Of course those device makers could make their devices a little more secure, can't argue with that, it's another form of complacency. Still - the attackers are only able to do this because their targets are few.

If there were thousands of DNS providers such as Dyn each serving a small number of clients spread all over the world, it'd be impossible to attack them all.

To cause maximum damage you need to identify hosts that are common across many big companies. Someone did their homework and figured out that lots of companies are using Dyn for DNS, and for the East Coast of the US this is just a handful of servers. If the same DNS services were spread across 1000 servers, then the attackers would need proportionally more "power" to knock them out. DDos-ing 10 boxes is _so_ much easier than 1000 (approximately 100 times easier, to be precise).

Re: Possible Vendetta Behind the East Coast Web Slowdown

#198

Earlier quoted context omitted.

Hi! Thank you for the feedback and the suggestion. It is a good idea actually. I'm considering new features in the roadmap, because at the moment I don't even offer Internet access through my system, it's just a private LAN (I'm not competing with the myriad of privacy-minded browsing VPNs out there). Adding a manageable Internet Gateway could be a nice option. Developing and deploying a software+hardware piece would…

A flexible gateway would be a great add on, I also like a private DNS server while developing. If you offered a Postfix forwarder and static, clean IP addresses, you could attract home users who wish to host their own email but are behind dynamic residential connections (like me, I use a digital ocean droplet currently for that purpose).

Thank you again, you're feedback is great!

Re: Possible Vendetta Behind the East Coast Web Slowdown

#199
post #118

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Indeed. My mom got an internet connected "security camera" kit (for cheap from one of the big wholesalers, can't remember the manufacturer) and asked me to set it up. The hardware was nice, cameras did a reliable 1080p full color, but the whole reason my mom wanted it was so she could check in while she and my dad were traveling (and also sneak a peek at her bird feeders while she was away; avid birder, that one). So…

The problem here is there's nearly zero incentive to do it right. I mean, ok, let's say the worst - somebody breaks in the box. For a regular person, worst thing somebody would get access to their DVR. As long as it keeps working as DVR, they couldn't care less. Yes, this DVR would also serve as botnet bot, but the owner doesn't care. It doesn't hurt them - except when Twitter goes down but they don't make the link between them not configuring the DVR properly and Twitter going down. Until we find a way to make the incentives work in right direction, nothing really would change...

Re: Possible Vendetta Behind the East Coast Web Slowdown

#200
post #183

Earlier quoted context omitted.

> Admittedly, it did have some authentication for accessing the video streams, but I didn't trust that thing as far as I could throw it So...you wanted to have authentication and it has authentication...I must be missing something.

So...you wanted to have authentication and it has authentication...I must be missing something You missed that you could SSH into it with a default password that is easy to find on a web search.

So... don't use that default password?
Post reply on HN