Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable
> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…
Possible Vendetta Behind the East Coast Web Slowdown
201–206 of 206 posts
Re: Possible Vendetta Behind the East Coast Web Slowdown
#202Earlier quoted context omitted.
This is totally inappropriate.
Very young person so possibly impulsive; started college at age 12 so might not have developed enough emotional intelligence to avoid doing these things. I mean, Bloomberg is pointing fingers, I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms.. EDIT: Also, "Marshal Webb, 18, whose Hamilton, Ohio home was raided this week by FBI agents as part of the LulzSec investigation". Maybe he did…
It's basic 'eliminate the competitors' behavior.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#203Earlier quoted context omitted.
The problem with these devices in particular is the weak point is the user. As is the case in most attacks. Your average user says "Sure I can setup cameras" then sees "remote access" in the menu, sets it up, maybe it has some UPNP to the router and BOOM. Magic remote login without any type of mitigation.
Indeed. My mom got an internet connected "security camera" kit (for cheap from one of the big wholesalers, can't remember the manufacturer) and asked me to set it up. The hardware was nice, cameras did a reliable 1080p full color, but the whole reason my mom wanted it was so she could check in while she and my dad were traveling (and also sneak a peek at her bird feeders while she was away; avid birder, that one). So…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#204I am a non-programmer who reads HN and keeps up with tech news in general. And every time I read about the IoT botnet, my immediate response is to look around my apartment at my Internet-connected lights, and wonder if they're part of it. How can I find this out? Is anyone making a tool that a non-technical user can run to squint at their network and look for evidence of Mirai, or anything else trying to take advanta…
Dowse is trying to help you out http://dowse.eu/#sec-2-2 Dowse is a transparent proxy facilitating the awareness of ingoing and outgoing connections, from, to, and within a local area network. ... Dowse communicates with users in various ways: via a web interface, but also pushing messages via audio (synthesized speech), Bonjour and simple apps interfacing with personal mobile devices. You can even hook up Dowse to y…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#205Earlier quoted context omitted.
> Admittedly, it did have some authentication for accessing the video streams, but I didn't trust that thing as far as I could throw it So...you wanted to have authentication and it has authentication...I must be missing something.
It may not have been over HTTP, so possible to be sniffed. Or, even if it did have HTTPS, it might not generate keys in a secure way (or might use the same certificate as other devices). And you don't know if there are hidden backdoor accounts that might be found eventually... So, yeah, it makes sense to block it - personally I block IOT devices from the Internet entirely (and don't let them initiate requests to my l…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#206Earlier quoted context omitted.
Looking over all the replies this comment received, I think my plan for seeing if my apartment's Internet Things are on any botnet is going to be "bribe that security researcher I flirt with sometimes to visit my place and run some tests". Which is not really a solution that scales, either for that friend, or for people who don't happen to run in the kinds of circles where that's someone they could conceivably trade…
> bribe that security researcher I flirt with sometimes to visit my place and run some tests...[w]hich is not really a solution that scales... Assuming the flirting displayed is sincere, that security researcher may prove much more scalable than you'd imagine.