Live data from Hacker News

A Botnet Accidentally Destroyed I2P

sambent.com

41–50 of 101 posts

Re: A Botnet Accidentally Destroyed I2P

#42

Why does Discord allow a server for a botnet owner?

Why wouldn't they? There are Discord servers about anything you can imagine and also what you can't or don't want to image. As long as they don't start disrupting their infra Discord couldn't care less.

Also, how would you even go about classifying them as botnet operators?

Re: A Botnet Accidentally Destroyed I2P

#43
post #20

Earlier quoted context omitted.

Ever tried to ban a botnet owner from a service they want to use? It’s basically impossible. They have money, IPs, identities, anything you could possibly want to evade.

It would be pretty funny if the age verification stuff blocked some of these folks.

Discord age verification is only for content filters, adult-themed servers, and a few other features.

They aren’t requiring age verification for everyone to join servers and chat. The headlines and panic really got away from the actual story.

Re: A Botnet Accidentally Destroyed I2P

#44

Why does Discord allow a server for a botnet owner?

Discord has a lot of terrible servers. This is one of the reasons they were not trusted when they came out and wanted to do identity verification. They already have a lot of information yet fail to do meaningful enforcement at scale.

Only a couple years ago the outrage was that Discord was too eagerly banning servers and users.

I know several people whose Discord accounts were banned because they participated in a server that later had some talk of illegal activities in one of the channels. There are similar stories all over Reddit.

Re: A Botnet Accidentally Destroyed I2P

#45

Earlier quoted context omitted.

> Why does i2p (per the article) expect state sponsored attacks every February? Because The Invisible Internet Project (I2P) allows government dissidents to communicate without the government oversight. Censorship-resistant, peer-to-peer communication > Where are those forming from, what does the regularity achieve? At least PR China, Iran, Oman, Qatar, and Kuwait. censor communication between dissidents. > How come…

Sure, but why February and not the other 11 months?

Likely it's just a coincidence — there were other Sybil attacks that are not in February too, so the chance that you'd get 3 in Feb isn't all that low.

Re: A Botnet Accidentally Destroyed I2P

#47
post #5

Man, I feel so out of depth with cybersecurity news. Why does i2p (per the article) expect state sponsored attacks every February? Where are those forming from, what does the regularity achieve? How come the operators of giant (I’m assuming illegal) botnets are available to voice their train of thought in discord?

Many state bodies involved in adversarial action have dedicated budgets for offensive cyber-warfare, credential thefts, supply chain compromises and disinformation. If they haven't used all of their budget by the end of the budget period, they'll be allocated a smaller budget for the next budget period.

Cool theory but that should result in other attacks that peak in February too, can you give examples?

Re: A Botnet Accidentally Destroyed I2P

#48
> The I2P development team responded by shipping version 2.11.0 just six days after the attack began.

Not wanting to be overly critical, but any net-infrastructure project kind of has to keep bot-attacks in mind and other attack vectors, in the initial design stage already. Any state-actor (and other actors, though I would assume it is often a state financing the bot network behind-the-scene) can become potentially hostile.

Re: A Botnet Accidentally Destroyed I2P

#49
post #4

From the main article, I2P has 55,000 computers, the botnet tried to add 700,000 infected routers to I2P to use it as a backup command-and-control system. https://news.ycombinator.com/item?id=46976825 This, predictably, broke I2P.

I guess "predictably" is valid but what actually went wrong? After going through multiple sources I can't tell if the botnet nodes were breaking the protocol on purpose, breaking the protocol on accident, or correct implementations that nevertheless overwhelmed something.

Re: A Botnet Accidentally Destroyed I2P

#50
This article (with high slop vibes) and another article on their site (linked in the comments) seem to suggest that post quantum encryption mitigated the Sybil attack, without explanation. I fail to understand how the two are even related.
Post reply on HN