Live data from Hacker News

Internet Attack Spreads, Disrupting Major Websites

nytimes.com

211–220 of 263 posts

Re: Internet Attack Spreads, Disrupting Major Websites

#211
post #176

Earlier quoted context omitted.

https://support.google.com/projectshield/answer/6358116?hl=e... > My website is on Blogger, Google Sites, or Google App Engine. Am I eligible? > As Google products, these sites already have similar DDoS protection to Project Shield. Your website would not need to be set up with Project Shield. Wonder if that answer includes Compute Engine. Doubt it.

It would be interesting to try using App Engine to simply proxy traffic. I don't know enough about it to even know if it's technically feasible. I imagine the downsides would be many but it could be useful as a temporary measure while you're getting attacked.

Some people already use App Engine as a free CDN (http://www.digitalistic.com/2008/06/09/10-easy-steps-to-use-...) , I imagine it would be totally possible to use it as a proxy.

Re: Internet Attack Spreads, Disrupting Major Websites

#212

Earlier quoted context omitted.

Can you third grade down your comment please? I find your language to be of high interest like you had a "dUH" moment - which I am ignorant to get myself. The Sons rays meat

DDOS usually occurs via a botnet of infected networked devices. Thus, the attacker is getting their resources for "free" since their host is unknowingly wasting CPU and bandwidth during the attack, while the defender is paying for theirs.

Until Google starts serving pages from our phones...

Re: Internet Attack Spreads, Disrupting Major Websites

#213
post #207

Earlier quoted context omitted.

God I fucking hope not. I'd much rather lose access to some services and focus on technical mitigations than literally start a war over it. I don't want me or my family to die just because services go down or businesses lose some income.

I am not sure you will think the same if someone in your family is at the local hospital and the electricity has been shut down

I think I must have missed some context here or misread since an attack on an electrical grid is substantially different from disrupting major web services.

Re: Internet Attack Spreads, Disrupting Major Websites

#214

Earlier quoted context omitted.

Based on what international laws? The source is likely in a country that doesn't play nice with our law enforcement and extradition requests. So what are you advocating?

Cut their internet access. Take down their power grid. If you're being attacked, I'm not sure what international law has to do with it. A country has the right to defend itself -- it doesn't require the UN to grant 'permission.' If you are in the midst of being attacked, waiting for the UN or some other disfunctional body to 'approve' would be like asking the teacher for permission to defend yourself while you're get…

Your Netflix stopped working. You're talking about going to war.

If you're being attacked, I'm not sure what international law has to do with it.

That's incredibly naive. Trumpian almost. Even in the midst of real war (you know, when people are dying, not sitting on the couch unable to place a Prime order), we follow international law. Because we want everyone else to as well.

Re: Internet Attack Spreads, Disrupting Major Websites

#215
post #167

Wikileaks tweeted: "Mr. Assange is still alive and WikiLeaks is still publishing. We ask supporters to stop taking down the US internet. You proved your point. " Link: https://twitter.com/wikileaks/status/789574436219449345 If their claim is true, does anyone think, it will turn many sympathizers against them? I don't think attacking normal bushiness is a good thing to do.

I think this tweet says more about Assange's vanity than anything else.

The motives of the attackers are much less interesting than the fact that such attacks are now possible.

Re: Internet Attack Spreads, Disrupting Major Websites

#216

We seem to be needing more concerted action on what is a consumer minimum standard for an internet connected device. Consumer devices have to be more secure because if the low user skill level - and interest. I am always reluctant to say "there should be a law against it" but frankly if we cannot mandate minimum standards of uogradbility and security for devices we will just keep handing over our devices to the first…

As noted below, you need FCC or similar licences for wifi radio, why not something similar for the packers emitted.

Downside is that radio leakage licensing is fairly simple scientifically. Proving something is unhackable is harder ...

Re: Internet Attack Spreads, Disrupting Major Websites

#217

Earlier quoted context omitted.

I feel like I hadn't thought of this as a market failure until reading your post calling it that. You're absolutely right about it. That's exactly what it is and the need for government involvement is quite obvious now. Suppliers are going to need to be held liable for the negative externalities their product offerings create, otherwise we're stuck at an equilibrium point where this situation does not improve.

You can call that "getting the government involved" but it's allowing suing for damages due to negligence, which is a fairly basic form of involvement, the sort of thing at the base of the market to begin with. That is to say, it's a bit strange to call this a market failure, because the market will (imo) take care of it once you can assign liability.

I'm not so sure suing would help here, as who is suing who?

The people who bought the IoT devices probably don't even know that their device has been hijacked in a lot of cases and therefore have no incentive to sue the manufacturers.

The people being hit by the DDoS have a tricky attribution problem to prove which manufacturers are to blame and then the manufacturers could, in many cases, shift the blame to users who didn't read instructions/change default passwords/apply available security patches.

Also you have the problem of complex supply chain. A lot of the people selling these devices are just white-labelling someone else's product, so who's to blame there, the vendor or the ODM?

Lastly you have shrink-wrap style licenses that disclaim liability for flaws the the software market has been relying on for many many years to avoid any liability when their products misbehave...

Personally I don't see the market sorting this, its a classic case of negative externality where government regulation is the most appropriate way to rectify the problem

Re: Internet Attack Spreads, Disrupting Major Websites

#218
post #209

Earlier quoted context omitted.

Availability is the % of times you try to access your data that you get it back. So 52.5 minutes of downtime a year is still within SLA. Durability is the % of your data that doesn't die. Eleven 9s means that if you store 1TB on AWS S3 you can expect to lose 10 bytes and still be within SLA.

No, it means that if you store your data there that there is a .000000001% chance that you will lose all of it.

Is that true? How can they possibly measure a probability event so small? If every human in the world was their customer, then .05 humans would lost heir data?

Re: Internet Attack Spreads, Disrupting Major Websites

#219
post #207

Earlier quoted context omitted.

I am not sure you will think the same if someone in your family is at the local hospital and the electricity has been shut down

I think I must have missed some context here or misread since an attack on an electrical grid is substantially different from disrupting major web services.

I'm not sure you've seen eighth graders who are unable to watch Netflix.
Post reply on HN