Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

51–60 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#51
post #9

To be honest, I wouldn't be surprised at all if the BackConnect kid decided to launch the DDoS: https://www.crunchbase.com/person/marshal-webb Edit: Maybe this helps with the downvotes: http://www.cbsnews.com/news/lulzsec-takes-revenge-on-alleged... https://www.reddit.com/r/cincinnati/comments/ibwbz/fbi_hacki...

More likely to be that sergio correia guy. I heard bad things about him.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#53
I know the TTL is set really low for a lot of DNS entries but this recent outage got me wondering if it makes sense for servers further down the chain to hold onto it for longer than the TTL, honor it when they are able to get a new DNS entry within a reasonable amount of time, but fall back to the "expired" version if the authoritative server is not reachable.

I'm wondering what would be the negative consequences of this and if they outweigh the benefit of being more resilient to these types of attacks.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#54
post #37

Earlier quoted context omitted.

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

Possibly stupid question: why is that no longer done?

Because it's hard to get an ISP to disable a service for one of their paying customers to help other people on the Internet who aren't paying them.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#55
post #37

Earlier quoted context omitted.

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

"Fix" is a relative term, especially if IoT devices are in play – yes, turning off the internet to customers stops the attack, but then (at least?) thousands of people lose internet connectivity because of a vulnerability that they could very well be powerless to fix. I'm not saying it's ok with me that an army of smart refrigerators could be taking out big chunks of the web, but it's a lot easier to tell someone, "H…

I would hope things like smart refrigerators and lightbulbs actually still operate normally when the internet is out, right? By "normally" I mean similar to "dumb" versions of the same product. So a customer could fix the issue by kicking the device off the network (disconnect the smart fridge from the ethernet / wifi, unplug the hub for your light bulbs, etc) without actually having to immediately replace them.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#56
post #4

For a long time, I've wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I've seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop.…

These attacks are mostly possible because of the complacency of operators at many sites and companies. This is not a new problem and many of RFC's talk about methods for preventing and mitigating them, but most people don't care and prefer to just outsource everything to a single provider, which becomes the weakest link.

The Internet wasn't envisioned with a single email provider, single DNS provider, single app container provider. (Ok, for most of these you have two, sometimes three choices, but still, that is too few). The centralization makes everything very vulnerable - imagine what would happen when Gmail is knocked out for a day.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#57

Earlier quoted context omitted.

> Unfortunately, forced firmware updating is an area our governments should not be mandating. It absolutely is an area that governments should be mandating, because the problem is an externality. These attacks are a cost imposed on neither the producer nor the consumer of the device itself, and (apart from some highly speculative libertarian conjectures) the only things that can fix externalities are taxes, regulatio…

If you are a chemical company you have regulation on the stuff you put out and the environmental hazard of you product and waste products. Something similar could work for IT.

Yeah, this seems, to me, the most apt existing analog. We have regulation for environmental pollution, this would be digital pollution (of a sort). Insecure devices create a harm to the digital environment.

But this is incredibly hard, due to ease of manufacture and distribution, to regulate in the case of IoT devices and software.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#58
I'm suggesting this just so someone more knowledgeable can debunk it. Suppose FBI or someone up there had a meeting and said "in three weeks, there could be millions of armed Americans who believe that democracy was just stolen from them by some evil dictator in a massive globalist conspiracy. These people love twitter. Is there a way to make twitter go down without making it look like we're suddenly pulling the plug?" The answer was yes, we'll do a test run Friday.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#59
post #26

Earlier quoted context omitted.

Liability should be on the people who connect these things to the public internet. The owners of the devices. Like with cars, you have certain responsibilities and liabilities when you operate a potential dangerous machine on the public roads. In the case of ISPs providing cable modems and routers and DVRs and other boxes to their customers, they should be responsible for keeping those secure. If people start getting…

So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.

So grampa doesn't take care of his car, the brakes fail and he kills a family with four kids. Is he liable? Yes. He may not know the first thing about brakes or car repair but owns the car, and he took it out on the road without being sure it was in safe operating condition.

But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have incentive to monitor their networks and they can take homes offline until their customers fix or disconnect their hacked devices.

Post reply on HN