Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

31–40 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#31
post #26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

True, but then botnet owners would be using foreign IPs to do US attacks and viceversa. So you need punishments that you can actually enforce.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#32
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

I don't think that's necessarily a bad thing. If a company doesn't have the resources to create secure products, then maybe it shouldn't be in that business in the first place.

The problem is not whether they can create a secure product, but whether they can afford to certify their products as secure.

From my experience in the aviation software world, we spend a great deal more on demonstrating reliability than in producing it. This forces a huge amount of overhead on our projects. This isn't a bad thing, mind you, but it is a thing to consider.

It is hard for a couple engineers to start a new company making these sorts of systems. The only practical way is to have a truly good and demonstrably better solution, or be inside a large corporation with already deep pockets.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#34
post #26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing?

I don't think so.

You make a little gizmo with shitty security, you are liable. Full stop.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#35
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

There'd be something ironic about a manufacturer's website being made unavailable because of a DDoS caused by their own poorly secured devices.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#36
post #18

Earlier quoted context omitted.

This is totally inappropriate.

Very young person so possibly impulsive; started college at age 12 so might not have developed enough emotional intelligence to avoid doing these things. I mean, Bloomberg is pointing fingers, I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms.. EDIT: Also, "Marshal Webb, 18, whose Hamilton, Ohio home was raided this week by FBI agents as part of the LulzSec investigation". Maybe he did…

Per his LinkedIn[0] he started college at age 16. He's 23 now. The fact that he started college 2 years early, seven years ago, made him decide to DDoS a huge DNS provider? That's quite a leap...

[0] - https://www.linkedin.com/in/webbmt

Re: Possible Vendetta Behind the East Coast Web Slowdown

#37
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#38

Here's a better article from Mr. Krebs: https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twit... Personally I think his case is pretty convincing.

krebs is loading reaaaaal slow for me...i wonder if its related? or just a lot of people linking to it today.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#39
post #37
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

If the "machine" in question is my ADSL router as supplied by my ISP, I will be deeply unimpressed if they block me due to their own negligence in updating it!

Re: Possible Vendetta Behind the East Coast Web Slowdown

#40
post #37
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

Possibly stupid question: why is that no longer done?
Post reply on HN