Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

21–30 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#22
post #18
post #9

To be honest, I wouldn't be surprised at all if the BackConnect kid decided to launch the DDoS: https://www.crunchbase.com/person/marshal-webb Edit: Maybe this helps with the downvotes: http://www.cbsnews.com/news/lulzsec-takes-revenge-on-alleged... https://www.reddit.com/r/cincinnati/comments/ibwbz/fbi_hacki...

This is totally inappropriate.

Why inappropriate?

Re: Possible Vendetta Behind the East Coast Web Slowdown

#23
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

> Unfortunately, forced firmware updating is an area our governments should not be mandating.

It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulations, and lawsuits.

Lawsuits are infeasible in this case since we probably can't prove whose devices were involved in any given attack, so that leaves taxes and regulations - and the latter would be better so we don't have to go through the business of collecting taxes from manufacturers and then distributing them to the victims of attacks.

> That puts unnecessary strain on small companies

Clearly it isn't unnecessary, because I can't get to any friggin websites today. If small companies don't have the resources to update the devices, they shouldn't be building them in the first place.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#24
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

I don't think that's necessarily a bad thing. If a company doesn't have the resources to create secure products, then maybe it shouldn't be in that business in the first place.

[deleted]

Re: Possible Vendetta Behind the East Coast Web Slowdown

#25
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Just like with bridges. Getting certification by a professional engineer is just too much barrier to entry for small construction companies. Edit: forgot the /s

I'm not sure if you're being sarcastic, but isn't that a good thing?

Re: Possible Vendetta Behind the East Coast Web Slowdown

#26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads.

In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure.

If people start getting fines or sued over what their internet-connected devices are doing, they might stop connecting them to the internet, or shop more carefully for devices or providers that are secure.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#27
post #18
post #9

To be honest, I wouldn't be surprised at all if the BackConnect kid decided to launch the DDoS: https://www.crunchbase.com/person/marshal-webb Edit: Maybe this helps with the downvotes: http://www.cbsnews.com/news/lulzsec-takes-revenge-on-alleged... https://www.reddit.com/r/cincinnati/comments/ibwbz/fbi_hacki...

This is totally inappropriate.

Very young person so possibly impulsive; started college at age 12 so might not have developed enough emotional intelligence to avoid doing these things.

I mean, Bloomberg is pointing fingers, I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms..

EDIT: Also, "Marshal Webb, 18, whose Hamilton, Ohio home was raided this week by FBI agents as part of the LulzSec investigation". Maybe he did it or maybe not, but if he did, it wouldn't be the first time

http://www.thesmokinggun.com/documents/internet/hackers-who-...

Re: Possible Vendetta Behind the East Coast Web Slowdown

#28
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

Yep, and manufacturers have not much incentive to update firmware for a device which is not their latest greatest or update firmware while not adding more features to help them sell more. Security isn't a feature that the vast majority of consumers would pay extra for or know how to verify anyway. There was plenty of demand for that one "unhackable" android phone, but I'd be blown away if it wasn't 100% snake oil.

My prediction is that it'll get worse before it gets better and that these type of botnets will be around for at least 5 years. Look at what happened to unsecured-by-default routers, android phones, Windows PCs, cars...the way consumers will get more secure stuff is by manufacturers being publicly embarrassed / sued over problems until caring about security makes business sense, then they'll have it in their hands when their old insecure gadgets die.

My cynical side side thinks this will be a problem until all the old endpoints supporting these insecure things are shut down eventually in 5-10 years.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#29
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

In an age where security vulnerabilities can cause your thermostat to overheat your house and your smart lock to lock you out, maybe it'll be a good thing that companies that don't have good security practices and update mechanisms will be locked out of the IoT market.
Post reply on HN