Live data from Hacker News

L0pht’s warnings about the Internet drew notice but little action

washingtonpost.com

31–40 of 69 posts

Re: L0pht’s warnings about the Internet drew notice but little action

#31
post #29
post #26

Earlier quoted context omitted.

It's painful that they combined XSS and SQLI, because progress on SQLI has been much better than progress on DOM corruption bugs.

Indeed, I'd love to see an expanded chart (as well as a more recent one). This one is focused on two categories, memory vs web vulns.

[deleted]

Re: L0pht’s warnings about the Internet drew notice but little action

#32
post #10

The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.

Well, it's somewhat exaggerated. But a bit of BGP hacking can take large areas offline for hours. Why not done more often? No lulz or money in it. Hackers want the net as a whole to stay up for the same reason as everyone else. It's specific sites that are targets for humiliation or extortion.

The problem is now more state actors than 'hackers'.

Re: L0pht’s warnings about the Internet drew notice but little action

#33

The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.

Peiter was talking about BGP. In 1998, you had to be somewhat diligent to get to a vantage point from which you could inject bogus BGP, and the Venn diagram between those people and "nihilistic assholes" is not that scary. In 2015, you can still technically fuck up BGP, but probably not for very long, and not without burning a lot of assets. Why would anyone bother?

The hunting and taxidermy of corrupted BGP advertisements is basically what got the NANOG crowd out of bed every morning; it's a pretty big chunk of the job. I always felt like the alarmism over BGP was a bit tone-deaf. Certainly, nothing Peiter said came as any surprise to anyone who'd ever managed default-free peering.

Re: L0pht’s warnings about the Internet drew notice but little action

#34
post #33

The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.

Peiter was talking about BGP. In 1998, you had to be somewhat diligent to get to a vantage point from which you could inject bogus BGP, and the Venn diagram between those people and "nihilistic assholes" is not that scary. In 2015, you can still technically fuck up BGP, but probably not for very long, and not without burning a lot of assets. Why would anyone bother? The hunting and taxidermy of corrupted BGP advertis…

Further, I recall several of the L0pht members were heavily interested in TEMPEST and van Eck phreaking at the time. Really played it up in an ominous tone.

Re: L0pht’s warnings about the Internet drew notice but little action

#35
post #21

Earlier quoted context omitted.

How many complete rewrites of Internet Explorer have we had since then? None? There's an ongoing one that was announced in January with a preview released in March. https://en.wikipedia.org/wiki/Microsoft_Edge

Spartan? https://twitter.com/dildog/status/612795030345007104 "It feels like 1996 again."

Microsoft Edge is Project Spartan.

"Microsoft Edge, initially developed under the codename Project Spartan..." (same Wikipedia link as above)

Re: L0pht’s warnings about the Internet drew notice but little action

#37

The Internet itself, he added, could be taken down "by any of the seven individuals seated before you" with 30 minutes of well-choreographed keystrokes. If this wasn't exaggeration, we should study the fortunate circumstances by which this calamity has been avoided for 17 years.

Maybe something about possible outcomes? If you're a bad guy with a super exploit, you could bring down the internet. You'll get a laugh for a few hours, but then the world will respond with enormous resources to find you and bring you to justice.

Or, alternatively, you could go after some smaller internet companies, demand extortion money, buy a nice car and treat your friends to drinks.

Re: L0pht’s warnings about the Internet drew notice but little action

#39
post #28
post #27

Earlier quoted context omitted.

With all due respect to you, everything would be different. I know even then it would've been a daunting thing to do but perhaps 1998 was the last year when it could've been done: tear it down and rebuild it securely. I am sure you know this too well but let me remind a few people here who were not even born when some of this happened: The early years were mostly of trust. As an example, I remember running around eve…

I understand that's what people think, but what I'm saying is that in 1998, we wouldn't have known how to rebuild everything securely. We'd have ended up with slightly better C standard libaries, S-BGP, IPSEC, and DNSSEC. Here, let me sum it up this way: I think it's possible that the L0pht testimony predates SQL injection .

I thought by then there was at least some awareness - old memories of people evangelizing prepared statements with placeholders – but this was the oldest reference I found, from December 1998:

http://phrack.org/issues/54/8.html

Re: L0pht’s warnings about the Internet drew notice but little action

#40
post #20

The more I think about this story, the dumber it seems to me. The narrative seems to be, L0pht testifies, world ignores them, chaos ensues. But Mudge's testimony coincides almost perfectly with a software security renaissance. The reality is more like: L0pht testifies, world ignores them, gigantic sea-change in security leads to 9-figure investment in securing Windows, the near eradication of SQL injection from popul…

> Most new software is no longer shipped in C/C++.

What language are the applications in? What makes them more secure than C/C++?

Post reply on HN