Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

51–60 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#51

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

I don't think he can give citations or evidence. He gets told some stuff in confidence. He can violate the confidence, and not be told stuff in the future. Or he can say nothing. Or he can tell us as much as he feels he can, even though that's annoyingly vague and unspecific. As far as I can see, those are his only options.

On this topic, he chose the third option, because he felt that people needed to know, even though he couldn't give specifics. It sounds like you wanted him to pick the first option. If he did, though, it would be the last time he would be able to do so, because his information would dry up.

That's the pragmatic argument. There are also some of us who feel, when you tell someone that you aren't going to blab what they told you in confidence, that you should keep your word...

Re: Someone Is Learning How to Take Down the Internet

#52
post #46

Earlier quoted context omitted.

His writing about cryptography certainly should include citations.

It might sound blasphemous but I (as a non-expert in crypto) would be satisfied if either you or Bruce didn't cite their writing about crypto. Yes, appeal to authority and all that, but I don't have time to fully learn a field to find out if a cryptographer is mistaken. Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.

That works for you, but on the subject of security, tptacek is on a different level than most of the rest of us. It's perfectly valid for him to say that he wants to see Schneier's references, and for you to say that you will take it on trust from either of them.

> Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.

A totally valid point. Way too often, people smuggle credibility from an area where they have expertise (and therefore deserve the credibility) to areas where they don't. In this case, though, the real credibility is Schneier's honesty, not his expertise, since he's passing on (obscured) reports from others.

Re: Someone Is Learning How to Take Down the Internet

#53
post #31
post #22

Earlier quoted context omitted.

Just a little heads-up, your account appears to have been shadowbanned.

That post is publicly visible to me. It also seems to be the first post for the account, and is fairly substantive. Moreover, I don't think it's even possible to reply to posts made from shadowbanned accounts.

Okay then.

I didn't look at the poster's history, I just saw a constructive-looking comment that seemed to be modded to oblivion, and jumped to conclusions.

I had to vouch for the post before HN would let me reply, which seems consistent with how shadowbanned accounts are handled here.

Re: Someone Is Learning How to Take Down the Internet

#54
post #4

Earlier quoted context omitted.

'the author' (Bruce Schneier) is right a lot.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

Could the NSA do this? Almost certainly.

Could they make it look like China was at fault? Also almost certainly.

Would they? Well, they'd need a good reason. What would a good reason be? To hone their attack skills? Perhaps. (I would expect - though I have no proof - that many of the American pieces of internet-critical infrastructure are more hardened against attacks than many other countries' stuff, because the American stuff gets actual attacks more often. If the NSA can attack our stuff to the point of breaking, it can probably break other countries' stuff.)

Would the NSA do it to hone peoples' defensive capabilities? To show them what a real nation-state attack might look like? Also perhaps. (Or perhaps it could even have both goals.)

Would the NSA be in very deep trouble if they ever got caught at that game? Probably. Deep enough to get them to not do it? I don't know.

TL;DR: The NSA could be doing this. I'm unsure how probable I consider that option.

Re: Someone Is Learning How to Take Down the Internet

#55
post #49

Earlier quoted context omitted.

> Is it limited to state actors, or could we all play? Per the article, no, we can't all play. We don't have either the bandwidth or the expertise.

> Per the article Not quite, it says "If the attacker has a bigger fire hose of data than the defender has, the attacker wins" and "the size and scale of these probes—and especially their persistence—points to state actors" which is not quite the same as saying you need to own the bandwidth. For example, DNS amplification can be used "to turn initially small queries into much larger payloads, which are used to bring…

OK, perhaps I phrased it slightly wrong. I can't play, because I don't have the bandwidth or the expertise. I think that most of us on this board are in that category. (There's expertise here, but most of it isn't on the level of these attacks.)

Re: Someone Is Learning How to Take Down the Internet

#56

Earlier quoted context omitted.

It might sound blasphemous but I (as a non-expert in crypto) would be satisfied if either you or Bruce didn't cite their writing about crypto. Yes, appeal to authority and all that, but I don't have time to fully learn a field to find out if a cryptographer is mistaken. Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.

That works for you, but on the subject of security, tptacek is on a different level than most of the rest of us. It's perfectly valid for him to say that he wants to see Schneier's references, and for you to say that you will take it on trust from either of them. > Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in. A totally valid point…

My point is that his honesty is actually not existent, as it has been tainted by his provably incorrect speculation from 2013-2016.

I think it's absolutely valid for tptacek to demand citations from Schneier!

Re: Someone Is Learning How to Take Down the Internet

#57

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

I don't think he can give citations or evidence. He gets told some stuff in confidence. He can violate the confidence, and not be told stuff in the future. Or he can say nothing. Or he can tell us as much as he feels he can, even though that's annoyingly vague and unspecific. As far as I can see, those are his only options. On this topic, he chose the third option, because he felt that people needed to know, even tho…

I think you are mischaracterizing my statement. At no point did I suggest he should violate journalistic integrity by belying his sources' confidence.

I do say that it's inappropriate to expect implicit trust after all his previous integrity failures (conjecture as fact, etc). I want to believe this article. I do believe it. But I also can't rely on it, as his track record shows that given the topic of computer security, he will even present unfounded speculation to Congress as fact if given the opportunity.

Re: Someone Is Learning How to Take Down the Internet

#58
post #42
post #6

Earlier quoted context omitted.

If Verisign is running the nameservers for .com and .net, it will cause DNS problems across the board. We'd have to rely on DNS caches until new .net and .com nameservers come up. This would impact not only new domain registrations, but DR grade migrations, and DNSSEC. If coordinated with an attack against the root nameservers so we couldn't change the .com and .net nameservers, DNS would become a real disaster. If c…

Would there a use case for decentralizing DNS into blockchain, or for creating an alternative?

This is one of the goals of Namecoin, but I'm not sure how successful they've been so far.

Re: Someone Is Learning How to Take Down the Internet

#59
post #42
post #6

Earlier quoted context omitted.

If Verisign is running the nameservers for .com and .net, it will cause DNS problems across the board. We'd have to rely on DNS caches until new .net and .com nameservers come up. This would impact not only new domain registrations, but DR grade migrations, and DNSSEC. If coordinated with an attack against the root nameservers so we couldn't change the .com and .net nameservers, DNS would become a real disaster. If c…

Would there a use case for decentralizing DNS into blockchain, or for creating an alternative?

[deleted]

Re: Someone Is Learning How to Take Down the Internet

#60

Earlier quoted context omitted.

That works for you, but on the subject of security, tptacek is on a different level than most of the rest of us. It's perfectly valid for him to say that he wants to see Schneier's references, and for you to say that you will take it on trust from either of them. > Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in. A totally valid point…

My point is that his honesty is actually not existent, as it has been tainted by his provably incorrect speculation from 2013-2016. I think it's absolutely valid for tptacek to demand citations from Schneier!

> My point is that his honesty is actually not existent, as it has been tainted by his provably incorrect speculation from 2013-2016.

What are you referring to here?

And, taking your statement at face value: If he speculated, and was clear that he was speculating, and was wrong, that doesn't destroy his honesty - merely his reputation as a speculator.

Post reply on HN