To be honest, I wouldn't be surprised at all if the BackConnect kid decided to launch the DDoS: https://www.crunchbase.com/person/marshal-webb Edit: Maybe this helps with the downvotes: http://www.cbsnews.com/news/lulzsec-takes-revenge-on-alleged... https://www.reddit.com/r/cincinnati/comments/ibwbz/fbi_hacki...
Possible Vendetta Behind the East Coast Web Slowdown
51–60 of 206 posts
Re: Possible Vendetta Behind the East Coast Web Slowdown
#52We need protocols and systems that are designed to be distributed from the outset.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#53I'm wondering what would be the negative consequences of this and if they outweigh the benefit of being more resilient to these types of attacks.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#54Earlier quoted context omitted.
It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.
Possibly stupid question: why is that no longer done?
Re: Possible Vendetta Behind the East Coast Web Slowdown
#55Earlier quoted context omitted.
It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.
"Fix" is a relative term, especially if IoT devices are in play – yes, turning off the internet to customers stops the attack, but then (at least?) thousands of people lose internet connectivity because of a vulnerability that they could very well be powerless to fix. I'm not saying it's ok with me that an army of smart refrigerators could be taking out big chunks of the web, but it's a lot easier to tell someone, "H…
Re: Possible Vendetta Behind the East Coast Web Slowdown
#56For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…
The Internet wasn't envisioned with a single email provider, single DNS provider, single app container provider. (Ok, for most of these you have two, sometimes three choices, but still, that is too few). The centralization makes everything very vulnerable - imagine what would happen when Gmail is knocked out for a day.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#57Earlier quoted context omitted.
> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…
If you are a chemical company you have regulation on the stuff you put out and the environmental hazard of you product and waste products. Something similar could work for IT.
But this is incredibly hard, due to ease of manufacture and distribution, to regulate in the case of IoT devices and software.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#58Re: Possible Vendetta Behind the East Coast Web Slowdown
#59Earlier quoted context omitted.
Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…
So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.
But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have incentive to monitor their networks and they can take homes offline until their customers fix or disconnect their hacked devices.
Re: Possible Vendetta Behind the East Coast Web Slowdown
#60No luck with Google DNS for me, but Yandex seems to work: 77.88.8.8 77.88.8.1 https://dns.yandex.ru