Live data from Hacker News

TP240PhoneHome Reflection/Amplification DDoS Attack Vector

akamai.com

51–60 of 90 posts

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#51
post #36

Earlier quoted context omitted.

A failure to defend yourself is not aiding the enemy. That is insane. The government provides for the common security. That's one of it's most fundamental jobs. Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…

> Let's say you are the leader of a border post

Let's not say that. Suggesting that civilians have defence duties on par with members of the military is ridiculous.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#52
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

In principle, that's what the NSA would be doing. When DES was developed and standardized in 1976, the NSA had input in selecting some of the constants that were chosen for it [0]. It wasn't until the late 80s when independent development of differential cryptanalysis [1] came out, and people realized that the DES constants were deliberately chosen to be resistant to this attack.

The NSA has since turned away from this responsibility, and has done the exact opposite. When Dual_EC_DRBG was developed [2], there was a similar choice of constants, with the final values having been chosen by the NSA. In this case, rather than protecting against a attack method known only by the NSA, the constants were chosen to allow an attack method known only by the NSA.

[0] https://en.wikipedia.org/wiki/Data_Encryption_Standard

[1] https://en.wikipedia.org/wiki/Differential_cryptanalysis

[2] https://en.wikipedia.org/wiki/Dual_EC_DRBG

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#53

Earlier quoted context omitted.

because that value is a physical limit

How so? If I find a vector that triggers the remote system to `cat /dev/random | netcat $target` then there's no limit for how much traffic my refelection generates, no?

I assume by limit OP means the remote system's bandwidth.

at 4 billion to 1, there's in practice very little difference between CVE-2022-26143 and what you describe. Both will be capped at the same number by the bandwidth available to the offending system.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#54
post #36

Earlier quoted context omitted.

A failure to defend yourself is not aiding the enemy. That is insane. The government provides for the common security. That's one of it's most fundamental jobs. Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…

> Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable.

Yes! Because if you are a member of the state operated defense force, then defense is your responsibility. The state is responsible for defense.

If on the other hand, you are a civilian who just happens to own property near a border, you have absolutely zero obligation to defend the border yourself. The same is true for businesses near a border.

> We are at war with Russia and China on a nation-state level and on top of that we also have cybercrime gangs.

Man, if only society had a way to form some sort of governance body which could provide defense against other nations and provide some sort of justice system to protect against and punish crimes. Oh well, I guess its every man for themselves ¯\_(ツ)_/¯

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#55
post #20

Earlier quoted context omitted.

I think the question is about foreign government operations. If North Korean agents threw up some graffiti on a Wal-Mart and stole some soda, the private security would not be expected to handle the situation on their own. Even if the stakes seem low, that's an international incident.

That's... a very weird, reaching argument to make. And also not an international incident, since it's just some graffiti, not espionage or assassination or whatever. I'm not sure what point you're trying to make here.

It doesn't seem that far reaching. There's a difference between "foreign citizen action" and "foreign government action". If another government comes to your territory, to break your laws and deprive one of your businesses of their property or rights, that's a big deal. But because it happens online, it's given a pass and pushed on to private individuals to deal with.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#56
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Many private businesses already are expected to protect themselves from state (and similar capability) physical interference and attacks, especially if they are in the supply chain of critical infrastructure. It's one of the things you have to do effectively to earn profits in that sector.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#57
post #30
post #7

Earlier quoted context omitted.

Limit would end up being when you send 1 byte of traffic to a box and that box amplifies it to whatever its own max outbound bandwidth rate is. This seems like it would exceed that in many cases, since 1 byte in => 4.2 gigabytes out. Which is roughly 33.6 gbps. Not sure many of these vulnerable boxes actually have that amount of outbound bandwidth to utilize. (Please feel free to correct my quick math if I messed it…

Why do you want to send everything in one second?

This is a good point, but then you need more boxes to perform the DDOS as the reason they are effective is overwhelming the packets per second or bandwidth per second of the receiving networks. So it definitely does allow for a sustained attack by a single box with limited outbound bandwidth, but that blunts the usual reasoning for why the amplification is so dangerous.

Another interesting impact of this is that the higher the amplification, the more likely it is noticeable by the server that is being abused. I mean if you clog the outbound network for a company they will notice and try to resolve immediately. Versus some milder amplification where it can go under the radar, or at least the business impact urgency radar of a company much longer.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#58
post #45
post #13

Earlier quoted context omitted.

It could be easily solved by the operator, but that doesn't mean it's easy for the victims to get the operators to fix their stuff. These amplifiers are already run by people who ignored the software manufacturer's directions. What are the odds they will actually install the new version that's harder to abuse?

Usually[0] contacting the operator's ISP and informing them of the situation will get said ISP to contact said operator. All that outbound traffic does represent a cost to the ISP, after all. A call from your ISP usually gets a bit more respect than a call from some random person. [0]- In the US; I don't know about anywhere else

In the past what usually happens is the ISP disconnects you until you prove you've fixed whatever it was (sometimes they're nice and block just part of the connection, or give you a warning).

Surprisingly enough, the ISP often has no real way of contacting anyone; the easiest is to cut the connection and wait for a complaint.

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#59
post #36

Earlier quoted context omitted.

A failure to defend yourself is not aiding the enemy. That is insane. The government provides for the common security. That's one of it's most fundamental jobs. Imagine if your house was destroyed by a Russian drone and you were thrown in jail for not having enough "defense in depth" against drone strikes.

> A failure to defend yourself is not aiding the enemy. That is insane. Let's say you are the leader of a border post, and you leave your post unmanned allowing the enemy in - of course you will be held accountable. Exposing stuff to the Internet despite the manufacturer warning against it is at least grossly negligent and should be punished. We are at war with Russia and China on a nation-state level and on top of t…

Likewise, if I sell... garden fencing, and the military decides to buy it as just another customer, how liable should I be if it's easily bypassed?

Re: TP240PhoneHome Reflection/Amplification DDoS Attack Vector

#60
post #8

Is it just me, or does it seem crazy that we all just accept that private businesses are obligated to protect themselves from state-sponsored hacking? Imagine if Wal-Mart had to fund a private air force and patrol over their stores in order to combat foreign bombers coming in and everyone was like, "Yeah, that's just how it goes." Isn't a primary responsibility of government to protect its citizens and businesses fro…

Yes, it's walmart responsibility to protect their customers. It's their responsibility that their supply chain is not hacked to say distribute poison, it's their responsibility that the cameras they use in store are theirs and only they have access, it's their responsibility that the card I use in their terminal is safe. The example you gave won't be hurting the people, otherwise yes if they want to gain trust in dangerous land they have to ensure safety of people.
Post reply on HN