Live data from Hacker News

Internet Attack Spreads, Disrupting Major Websites

nytimes.com

251–260 of 263 posts

Re: Internet Attack Spreads, Disrupting Major Websites

#251

Earlier quoted context omitted.

I feel like I hadn't thought of this as a market failure until reading your post calling it that. You're absolutely right about it. That's exactly what it is and the need for government involvement is quite obvious now. Suppliers are going to need to be held liable for the negative externalities their product offerings create, otherwise we're stuck at an equilibrium point where this situation does not improve.

If ISPs were treated like a utility and charged per bit, customers would have an incentive to ensure that their devices weren't dumping traffic onto the internet. It's rare that you can see a dashboard showing your usage, even rarer to see a dashboard showing your usage, broken down by device.

That's why I got an Asus RT-AC5300 router. It's got a beautiful traffic analyzer.

I could've built something but honestly I don't have time for that anymore.

Re: Internet Attack Spreads, Disrupting Major Websites

#254
post #183

Earlier quoted context omitted.

Could the market failure be addressed through private class action suits against manufacturers of insecure IoT devices?

And what about software developers? Should we be suing the kernel developers for leaving that privilege escalation bug in for 9 years?

Don't open source license all include disclaimers?

Re: Internet Attack Spreads, Disrupting Major Websites

#255

Why? Let them invade another country, let them hack our infrastructure next such as our water supply? You think letting it go or doing nothing is the answer? This guy Putin is no different than Hitler, let him do this sort of thing and you will have much bigger problems in a couple of years.

We detached this subthread from https://news.ycombinator.com/item?id=12765946 and marked it off-topic.

Re: Internet Attack Spreads, Disrupting Major Websites

#256
Are there any downloadable DNS lookup tables which could be used as hosts.txt or /etc/hosts in case of emergency?

I know that DNS is organized in root zones with hierarchical subqueries. A global hosts file which contains the whole IP space is sort of unfeasible because domain names change within seconds.

However, in face of the current attacks the DNS maintainers should seriously consider to offer downloadable hosts files so that we could use them temporarily to circumvent DNS queries in cases of further attacks.

Re: Internet Attack Spreads, Disrupting Major Websites

#258
post #209

Earlier quoted context omitted.

Availability is the % of times you try to access your data that you get it back. So 52.5 minutes of downtime a year is still within SLA. Durability is the % of your data that doesn't die. Eleven 9s means that if you store 1TB on AWS S3 you can expect to lose 10 bytes and still be within SLA.

No, it means that if you store your data there that there is a .000000001% chance that you will lose all of it.

It doesn't mean that either. It's just an SLA. Could have been a number pulled out of the air. Likely loss in real life would be granular at the object level.

Re: Internet Attack Spreads, Disrupting Major Websites

#259
post #142
post #121

Earlier quoted context omitted.

> Enable private consultants and companies to provide this as a service. If I am an AWS customer I expect AWS to handle/prevent DDoS, same way as they do with S3 to achieve 11 9's availability (the files are saved in multiple AZs in the same region - Glacier IIRC copy files on different regions to avoid data loss in case of physical disaster). One of the reason for choosing AWS is because AMZ has deep pockets and has…

"achieve 11 9's availability" is this sarcasm?

It all depends how you measure it

Re: Internet Attack Spreads, Disrupting Major Websites

#260
post #183

Is it confirmed yet that so-called IoT devices were the bots? Bruce was on point if so, arguing a couple weeks ago that accountability needs to happen on the manufacturers: "What was new about the Krebs attack was both the massive scale and the particular devices the attackers recruited. Instead of using traditional computers for their botnet, they used CCTV cameras, digital video recorders, home routers, and other e…

Could the market failure be addressed through private class action suits against manufacturers of insecure IoT devices?

That's probably too distributed a set. You'd have to hit the device manufacturers (say, ARM or Intel), or vendors (Amazon). Hold them liable for problems.

Hit the distribution channel and I suspect you'll see a rapid increase in accountability and security measures.

Post reply on HN