Live data from Hacker News

Internet Attack Spreads, Disrupting Major Websites

nytimes.com

191–200 of 263 posts

Re: Internet Attack Spreads, Disrupting Major Websites

#191
post #90

We seem to be needing more concerted action on what is a consumer minimum standard for an internet connected device. Consumer devices have to be more secure because if the low user skill level - and interest. I am always reluctant to say "there should be a law against it" but frankly if we cannot mandate minimum standards of uogradbility and security for devices we will just keep handing over our devices to the first…

Or you need to make it easier for the 'black hole' solution to be pushed further and further back to the sources of the bad traffic. A remote site shouldn't be able to get you banned from the Internet (by it's self); but it MUST be able to say, "This host is being abusive, restrain them from sending me data". ISPs SHOULD use that information to evaluate if a host from their network might be compromised or otherwise a…

So, as your ISP, I'm going to be held responsible for the actions of you, my customer/user?

Okay, if I'm going to be liable, financially or otherwise, well, then we're gonna have to make some changes around here.

First off, I'm going to have to heavily filter and restrict what traffic you can send out to the Internet. What isn't filtered or restricted is going to have to be inspected, logged, and retained for a period of time.

Next, because I can't be certain that you're RFC3514 compliant and that at least some of the bits you're sending aren't malicious, I'm going to have to prevent you from sending out any encrypted traffic. Instead of allowing you to use any DNS servers you want, you're going to have to use mine (DNS is heavily abused for DDoS attacks). Outgoing e-mail will be automatically redirected to my internal smart host (STARTTLS will be blocked, by the way) and I'm gonna have to log, read, and retain it all. HTTP traffic will be transparently proxied and all requests and responses will be logged and retained.

That's just the beginning. Are you sure this is what you prefer as your "solution"?

As a network operator, I believe that your ISP should be nothing more than a dumb pipe and allow the bits that you send to pass through freely. As an ISP customer, that's how I want my ISP to act. (If something gets reported or I "notice" you for some reason then, sure, I'll look into it. Otherwise, I try to fuck with my customer's traffic as little as possible.)

I'll agree that there is certainly a problem, but it is not because of ISPs.

Re: Internet Attack Spreads, Disrupting Major Websites

#192

Earlier quoted context omitted.

I think what the OP is implying is that these static admin passwords were put as a deniable backdoor. If it was a Chinese gov scheme it is quite clever as a real backdoor would have been obvious, while this just looks like total incompetence.

This makes no sense. Everyone knows what the default passwords are. And all sorts of products not made in China have default passwords. And, some of the products implicated in these attacks aren't Chinese. I think the OP is grasping at straws.

It actually would be pretty clever given that once hacked you can close the door and keep out other hackers. Step 1. Make a device with a wide open door. Step 2. Hack all these devices and close the door. You get easy deniability and a massive botnet.

Having said this I suspect that this is not what has happened and it is most likely just a case of complete incompetence.

Re: Internet Attack Spreads, Disrupting Major Websites

#193

Earlier quoted context omitted.

It's harder, but you can distribute your web resources across multiple cloud providers

If GitHub and Twitter are struggling with this, what chance do the rest of us have?

Well one upside of not being a Unicorn is that doubling the infrastructure/hosting costs for a project that's at a "cup of coffee a day" or a "diner and a movie a month" budget isn't a showstopper. Doubling Twitter's infrastructure costs would not be good...

Re: Internet Attack Spreads, Disrupting Major Websites

#194
post #45

Irony alert: > "But technology providers in the United States could suffer blowback. As Dyn fell under recurring attacks on Friday, Mr. York, the chief strategist, said such assaults were the reason so many companies are pushing at least parts of their infrastructure to cloud computing networks, to decentralize their systems and make them harder to attack." Pushing your infrastructure to cloud computing is not decent…

AWS was affected at one point.

I fully agree with you about the paradox of how, in the intent to de-centralize we centralize into cloud VPSes and managed services.

The real reason for the move is that same showtune that we keep hearing in our heads and wish we could tune it out: it's cheaper to move from physical infrastructure to the cloud. It's cheaper to skimp on security by not updating IoT devices. It's cheaper to skimp on security because features need to come first. It's cheaper to outsource operational management to parties with less expertise in places that pay less. To spend less time securing infrastructure perimeters because it costs money.

We feel almost as if we feel comfort hiding behind heavyweights like Google and Amazon will protect us from the bad elements of the world, where we hear about major breaches every few weeks (eg., Yahoo being the most recent). Will this strategy pan out long-term?

With this DDOS, articles about machine learning picking up better password-cracking/guessing algorithms by having previously analyzed large volumes of passwords, major breaches in the financial world, talk of state-sponsored attacks (a la DNC emails) it certainly FEELS like the Internet has gotten a little bit more wild.

Re: Internet Attack Spreads, Disrupting Major Websites

#195
Would longer, say, week long TTL along with some redundancy have prevented this problem? Can it be done now to prepare for next attack? That is, TTL shortened when making updates, etc., but then set to a week the rest of the time. Here's an article that I think could be useful: https://medium.com/@brianarmstrong/youre-probably-doing-dns-...

Re: Internet Attack Spreads, Disrupting Major Websites

#196

Earlier quoted context omitted.

so it will be eventually Cloud VS DDoS eh, both can scale indefinitely so the limit is money, which makes the DDoS guys wins, they practically stole CPU/RAM/NET where cloud providers need to buy hardware as usual Unless we can somehow secure every net-connected devices, ha (I don't know whether to cry or laugh right now)

Can you third grade down your comment please? I find your language to be of high interest like you had a "dUH" moment - which I am ignorant to get myself. The Sons rays meat

DDOS usually occurs via a botnet of infected networked devices. Thus, the attacker is getting their resources for "free" since their host is unknowingly wasting CPU and bandwidth during the attack, while the defender is paying for theirs.

Re: Internet Attack Spreads, Disrupting Major Websites

#197

I think the main problem is that the Internet is decentralized. As it has no single owner nobody is responsible for mitigating the attacks and noone wants to pay for developing and implementing new protocols, installing new hardware.

More the opposite, because it's too centralized, an attack can take out the few 'authority' servers and knock off everything downstream.

Re: Internet Attack Spreads, Disrupting Major Websites

#198
post #176
post #106

Earlier quoted context omitted.

afaik Shield is for select journalists only, not for typical web infrastructure.

https://support.google.com/projectshield/answer/6358116?hl=e... > My website is on Blogger, Google Sites, or Google App Engine. Am I eligible? > As Google products, these sites already have similar DDoS protection to Project Shield. Your website would not need to be set up with Project Shield. Wonder if that answer includes Compute Engine. Doubt it.

It would be interesting to try using App Engine to simply proxy traffic. I don't know enough about it to even know if it's technically feasible. I imagine the downsides would be many but it could be useful as a temporary measure while you're getting attacked.

Re: Internet Attack Spreads, Disrupting Major Websites

#199
post #121

Earlier quoted context omitted.

If Azure and Google would like to gain a competitive advantage over AWS, then I would suggest this: Build out a suite of tools for fighting DDOS. Enable private consultants and companies to provide this as a service. Do this in such a way, that cloud customers save money and have to worry about less. Hell, let companies jump in structured as insurance companies! Also bring in cooperation with law enforcement and use…

> Enable private consultants and companies to provide this as a service. If I am an AWS customer I expect AWS to handle/prevent DDoS, same way as they do with S3 to achieve 11 9's availability (the files are saved in multiple AZs in the same region - Glacier IIRC copy files on different regions to avoid data loss in case of physical disaster). One of the reason for choosing AWS is because AMZ has deep pockets and has…

When you are DDOSed they will keep supplying the resources for you to consume and pay them extra. Cloud is commodity so don't expect to be treated like a special snowflake. Your distress is their opportunity to make extra money.

Offtopic but relevant. One of my customer moved their email to O365 without understanding the differences from being ON-Prem. Now they are struggling to adopt their business processes to then limitations MS imposes.

Re: Internet Attack Spreads, Disrupting Major Websites

#200

Earlier quoted context omitted.

No, not irony. Our infrastructure is under attack. Why not fight back?

Based on what international laws? The source is likely in a country that doesn't play nice with our law enforcement and extradition requests. So what are you advocating?

Cut their internet access. Take down their power grid.

If you're being attacked, I'm not sure what international law has to do with it. A country has the right to defend itself -- it doesn't require the UN to grant 'permission.' If you are in the midst of being attacked, waiting for the UN or some other disfunctional body to 'approve' would be like asking the teacher for permission to defend yourself while you're getting your face pounded in. Countries are sovereign. They shouldn't need permission to defend themselves when they are under an immediate threat.

Post reply on HN