Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

201–206 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#201
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…

The consumer takes on some of the cost. But the only reason you are so for this legislation is because you don't understand the full-scale logistics involved in mandating such a feat as well implementing them as a tech company. If you want to mandate security to include well-established, cost-appropriate solutions, that's cool, but requiring future updates to these IoT devices is not the correct solution. It brings into question free speech issues for one, requiring companies to support the life of products they no longer wish to support. And the only companies who will not feel the full brunt of this would be the elite.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#202
post #18

Earlier quoted context omitted.

This is totally inappropriate.

Very young person so possibly impulsive; started college at age 12 so might not have developed enough emotional intelligence to avoid doing these things. I mean, Bloomberg is pointing fingers, I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms.. EDIT: Also, "Marshal Webb, 18, whose Hamilton, Ohio home was raided this week by FBI agents as part of the LulzSec investigation". Maybe he did…

>I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms

It's basic 'eliminate the competitors' behavior.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#203
post #118

Earlier quoted context omitted.

The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.

Indeed. My mom got an internet connected "security camera" kit (for cheap from one of the big wholesalers, can't remember the manufacturer) and asked me to set it up. The hardware was nice, cameras did a reliable 1080p full color, but the whole reason my mom wanted it was so she could check in while she and my dad were traveling (and also sneak a peek at her bird feeders while she was away; avid birder, that one). So…

why not generate a cert based off mac address and allow customer to use that

Re: Possible Vendetta Behind the East Coast Web Slowdown

#204

I am a non-programmer who reads HN and keeps up with tech news in general. And every time I read about the IoT botnet, my immediate response is to look around my apartment at my Internet-connected lights, and wonder if they're part of it. How can I find this out? Is anyone making a tool that a non-technical user can run to squint at their network and look for evidence of Mirai, or anything else trying to take advanta…

Dowse is trying to help you out http://dowse.eu/#sec-2-2 Dowse is a transparent proxy facilitating the awareness of ingoing and outgoing connections, from, to, and within a local area network. ... Dowse communicates with users in various ways: via a web interface, but also pushing messages via audio (synthesized speech), Bonjour and simple apps interfacing with personal mobile devices. You can even hook up Dowse to y…

Oooh. I think I may have finally found a use for the Raspberry Pi sitting around my apartment.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#205

Earlier quoted context omitted.

> Admittedly, it did have some authentication for accessing the video streams, but I didn't trust that thing as far as I could throw it So...you wanted to have authentication and it has authentication...I must be missing something.

It may not have been over HTTP, so possible to be sniffed. Or, even if it did have HTTPS, it might not generate keys in a secure way (or might use the same certificate as other devices). And you don't know if there are hidden backdoor accounts that might be found eventually... So, yeah, it makes sense to block it - personally I block IOT devices from the Internet entirely (and don't let them initiate requests to my l…

Late response, but yes - there was no https support whatsoever on this thing. Authentication was some custom shit and intended to be passed over the internet in clear text.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#206

Earlier quoted context omitted.

Looking over all the replies this comment received, I think my plan for seeing if my apartment's Internet Things are on any botnet is going to be "bribe that security researcher I flirt with sometimes to visit my place and run some tests". Which is not really a solution that scales, either for that friend, or for people who don't happen to run in the kinds of circles where that's someone they could conceivably trade…

> bribe that security researcher I flirt with sometimes to visit my place and run some tests...[w]hich is not really a solution that scales... Assuming the flirting displayed is sincere, that security researcher may prove much more scalable than you'd imagine.

There's not really enough of a size difference between us to make "scaling" come into play.
Post reply on HN