Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

41–50 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#43

No luck with Google DNS for me, but Yandex seems to work: 77.88.8.8 77.88.8.1 https://dns.yandex.ru

Probably, but I would definitely avoid giving all my DNS resolutions to a *.ru domain.

The reputation of the government - shutting down access to websites that hurt them is kind-a no-go for me.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#45
post #39
post #37

Earlier quoted context omitted.

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

If the "machine" in question is my ADSL router as supplied by my ISP, I will be deeply unimpressed if they block me due to their own negligence in updating it!

Similarly, a single bad device on my network would block the whole of my network from the internet. It's another sort of denial of service attack.

We need IPv6 and have devices either access the internet with their own IP address or not access it at all. This solution, then, would only impact bad actor devices, not your other (non-compromised) devices. Still, not easy.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#46

Earlier quoted context omitted.

I don't think that's necessarily a bad thing. If a company doesn't have the resources to create secure products, then maybe it shouldn't be in that business in the first place.

The problem is not whether they can create a secure product, but whether they can afford to certify their products as secure. From my experience in the aviation software world, we spend a great deal more on demonstrating reliability than in producing it. This forces a huge amount of overhead on our projects. This isn't a bad thing, mind you, but it is a thing to consider. It is hard for a couple engineers to start a…

> From my experience in the aviation software world, we spend a great deal more on demonstrating reliability than in producing it.

The same is true in organic produce. I hear of a lot of farms that follow all the rules to raise organic goods but can't label them "certified USDA organic" because the certification process is too expensive.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#47
post #37
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

"Fix" is a relative term, especially if IoT devices are in play – yes, turning off the internet to customers stops the attack, but then (at least?) thousands of people lose internet connectivity because of a vulnerability that they could very well be powerless to fix. I'm not saying it's ok with me that an army of smart refrigerators could be taking out big chunks of the web, but it's a lot easier to tell someone, "Hey, either get the infection off your computer or re-format" than it is to make someone buy new lightbulbs and appliances.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#48
post #26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

This makes a case for data caps or charging internet by usage which frankly nobody really likes. Maybe outbound caps for home users (if thats where a lot of the DDOS are coming from). The risk of getting shut off or a higher bill if your transmitting to much data might make people start noticing and securing their devices.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#49
post #26
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

> Like with cars

That's not the same thing at all. For a car to hurt somebody, the owner has to be actively using it, and doing so in a reckless or negligent manner; and furthermore, note that reckless operation of a car can hurt somebody even if the manufacturer built it perfectly. (if your car somehow did hurt somebody when nobody was using it, then the liability probably would belong to the manufacturer).

IoT devices are the exact opposite: they can cause harm when the owner has done nothing wrong, and they can only cause harm if the manufacturer screwed up and did not secure it propertly.

All the liability belongs to the producer.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#50
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…

If you are a chemical company you have regulation on the stuff you put out and the environmental hazard of you product and waste products.

Something similar could work for IT.

Post reply on HN