Live data from Hacker News

Internet Attack Spreads, Disrupting Major Websites

nytimes.com

221–230 of 263 posts

Re: Internet Attack Spreads, Disrupting Major Websites

#221
post #183

Is it confirmed yet that so-called IoT devices were the bots? Bruce was on point if so, arguing a couple weeks ago that accountability needs to happen on the manufacturers: "What was new about the Krebs attack was both the massive scale and the particular devices the attackers recruited. Instead of using traditional computers for their botnet, they used CCTV cameras, digital video recorders, home routers, and other e…

Could the market failure be addressed through private class action suits against manufacturers of insecure IoT devices?

Nope. Many of these compromised routers and webcams are not based on U.S. soil, so they're outside of U.S. jurisdiction. But even if some enterprising lawyer could attach a legal claim to them, most of these guys are tiny, and while you could easily sue some individual companies out of existence, it would not have much impact on the broader problem.

Re: Internet Attack Spreads, Disrupting Major Websites

#222

Earlier quoted context omitted.

If they're absent T ballots, they're not counted until several weeks later (unless the total amount of absent T ballots is larger than the margin between any candidate to ballot measure).

What does the T stand for?

Hillary. Oh no, voter fraud!

Re: Internet Attack Spreads, Disrupting Major Websites

#223

Is this the end of the Internet that news.com predicted back in 1995?

Are you talking about this Newsweek article? http://www.newsweek.com/clifford-stoll-why-web-wont-be-nirva...

I just remember seeing this article on news.com cira 1995 that predicted the imminent demise of the Internet due to the commercialization of it. It worried that the net just couldn't handle all the traffic from all those 56k dialup hitting and getting email all at once.

So my comment was a bit on the ironic / goofy side.

Re: Internet Attack Spreads, Disrupting Major Websites

#225
post #33

Earlier quoted context omitted.

Also what amazed me is that he would casually threaten to strike Russia. It seems that no one considers these attacks as an act of war. But that's what they are.

God I fucking hope not. I'd much rather lose access to some services and focus on technical mitigations than literally start a war over it. I don't want me or my family to die just because services go down or businesses lose some income.

Like it or not, that's happening and next year when Clinton comes in the office, that will be the among the first things it comes to. Mark this comment.

Why ? Because business.

Re: Internet Attack Spreads, Disrupting Major Websites

#226
post #33

Earlier quoted context omitted.

Also what amazed me is that he would casually threaten to strike Russia. It seems that no one considers these attacks as an act of war. But that's what they are.

There is a strange push in America to go to war with Russia. Of course no one comes right out and says this, because it would be counterproductive. But every time something bad happens to democrats, it gets blamed on Russia. Lots of non-sequitur bellicose talk about Putin all the time. It reminds me of the run up to the Iraq war. Seems bad.

But they had WMDs ! /s

Re: Internet Attack Spreads, Disrupting Major Websites

#227
post #209

Earlier quoted context omitted.

Availability is the % of times you try to access your data that you get it back. So 52.5 minutes of downtime a year is still within SLA. Durability is the % of your data that doesn't die. Eleven 9s means that if you store 1TB on AWS S3 you can expect to lose 10 bytes and still be within SLA.

No, it means that if you store your data there that there is a .000000001% chance that you will lose all of it.

For those wondering .000000001% per what? The answer apparently is per object year.

i.e. you could expect to lose 10 bytes of your 1TB every year if your stored it as a trillion one byte objects, but if you stored it as a single object you could expect to lose the whole thing once every hundred billion years, but none of it the rest of the time.

Re: Internet Attack Spreads, Disrupting Major Websites

#228
I wonder why companies affected by these IoT-enabled DDoS attacks don't sue the companies building those devices, as they currently often choose security over convenience when it comes to securing them. If you can forensically prove that a large fraction of the attack was carried out using a given type of device it should be possible to hold the manufacturer liable for the damage, at least if no reasonable measures were taken to secure it (using blank or default passwords on the device could count as gross negligence).

I even kind of wish that somebody would do this, as it would finally provide a strong incentive for the manufacturers to think about security.

Re: Internet Attack Spreads, Disrupting Major Websites

#229

I wonder why companies affected by these IoT-enabled DDoS attacks don't sue the companies building those devices, as they currently often choose security over convenience when it comes to securing them. If you can forensically prove that a large fraction of the attack was carried out using a given type of device it should be possible to hold the manufacturer liable for the damage, at least if no reasonable measures w…

Poul-Henning Kamp had this proposal on the subject back in 2011: http://queue.acm.org/detail.cfm?id=2030258

I think it's a good idea.

Re: Internet Attack Spreads, Disrupting Major Websites

#230
post #54

We seem to be needing more concerted action on what is a consumer minimum standard for an internet connected device. Consumer devices have to be more secure because if the low user skill level - and interest. I am always reluctant to say "there should be a law against it" but frankly if we cannot mandate minimum standards of uogradbility and security for devices we will just keep handing over our devices to the first…

It's controversial, but I kind of agree. You need FCC approval to broadcast a radio signal due to the risk of interfering with other traffic, and you should have FCC approval that your IOT device meets minimum security standards before being sold.

It may be controversial, but I think there ought to be a law. Some ideas: http://www.dwheeler.com/essays/law-security.html
Post reply on HN