Earlier quoted context omitted.
Junk IoT manufacturers need to feel fear. We've reached the point where any clueless business type who pooh-poohs and wishes away security concerns needs to get the idiot bit flipped on them. Today's networked computing environment has reached the point, where this stuff is toxic. It might have been okay for a few isolated frontier weirdos to play with mercury to extract gold, but then when that became a full blown i…
capitalism just isn't ready for prime time
Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
41–50 of 50 posts
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#42Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#43Earlier quoted context omitted.
That the scale of DDoS's has increased is the entire thesis of the OP.
They've been increasing steadily for decades . Today almost certainly isn't some new record-setting attack orders of magnitude beyond what's been seen before - it isn't the herald of a new age of attacks and the "beginning of a bleak future". Claiming such is just sensationalist garbage that belies a lack of understanding of the way the internet works and the history of DDOSes in general. Spamhaus was historic in 201…
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#44Earlier quoted context omitted.
Have they been increasing steadily , though? The 2013 attack was http://www.cisco.com/c/en/us/solutions/collateral/service-pr... ) Most predictions suggest that IoT attacks will grow faster than what we've already seen, and a rough estimate suggests that DDoS capacity is growing faster than legitimate capacity. None of that means today was orders of magnitude higher - the shock factor was that it exposed a structural…
I certainly expect it to become an increasingly-significant problem, as well. I don't mean to downplay the significance of the attack. But the lesson here isn't "welp, the bad guys have won, the internet is dead", it's "don't use one DNS provider, go redundant on it just like you do on every other piece of the stack". Yeah, it's annoying, but it's not an unsolvable problem. The reporting on this has really annoyed me…
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#45Earlier quoted context omitted.
Have they been increasing steadily , though? The 2013 attack was http://www.cisco.com/c/en/us/solutions/collateral/service-pr... ) Most predictions suggest that IoT attacks will grow faster than what we've already seen, and a rough estimate suggests that DDoS capacity is growing faster than legitimate capacity. None of that means today was orders of magnitude higher - the shock factor was that it exposed a structural…
I certainly expect it to become an increasingly-significant problem, as well. I don't mean to downplay the significance of the attack. But the lesson here isn't "welp, the bad guys have won, the internet is dead", it's "don't use one DNS provider, go redundant on it just like you do on every other piece of the stack". Yeah, it's annoying, but it's not an unsolvable problem. The reporting on this has really annoyed me…
I've been really selective with the reporting I checked, and so most everything I've seen has been either BBC-bloodless ("these sites are inaccessible, because a DDoS attack happened"), or TheRegister-sophisticated (assumes the reader knows what DNS is). A quick look at what other people have been running explains your general sentiment. This isn't the end of the world, and running stories saying "IoT WILL KILL US ALL" isn't making anything better.
So fair enough: I think this is a serious issue, and today's events revealed that people haven't been properly prepared. But pitching it as something totally unpredictable is downright dishonest.
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#46It seems like some eyeball and distribution networks should get together and run a private subset of the Internet, with good filtering (BCP38 style), etc. internally. You could get pretty good coverage with just ~10 eyeball networks in the US, a few cloud providers, and maybe some key infrastructure. Operate normally most of the time, but when under attack, be able to fall back to just vetted networks, transports, an…
So, these DDOS attacks take advantage of IoT devices so how would you tell the difference using vetting when they are on the same networks as regular users?
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#47Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#48Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…
can you imagine the cost of doing and having everything nX times ??
Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
#49Earlier quoted context omitted.
I would just ban the ips for 24hrs if I detect an IP that is part of a ddos. After that people will wise up and unplug their nanycam/toaster/iotwhatever
You're assuming that people will know or be able to guess what is compromised. Assuming multiple IOT devices the average user won't have any clue, and will think they just need to run antivirus on their Windows box.