This seems to lack the full story, despite the headline.. Krebs' coverage is more in-depth (39 points) https://news.ycombinator.com/item?id=46976825
A Botnet Accidentally Destroyed I2P
51–60 of 101 posts
Re: A Botnet Accidentally Destroyed I2P
#52This seems to lack the full story, despite the headline.. Krebs' coverage is more in-depth (39 points) https://news.ycombinator.com/item?id=46976825
[flagged]
Re: A Botnet Accidentally Destroyed I2P
#53Re: A Botnet Accidentally Destroyed I2P
#54Earlier quoted context omitted.
No. They should not try to survive such attacks. The best defense to a temporary attack is often to pull the plug. Better than than potentially expose users. When there are 10x as many bad nodes as good, the base protection of any anonymity network is likely compromised. Shut down, survive, and return once the attacker has moved on.
This is why Tor is centralized, so that they can take action like cutting out malicious nodes if needed. It’s decentralized in the sense that anyone can participate by default.
How does that work?
Re: A Botnet Accidentally Destroyed I2P
#55Earlier quoted context omitted.
That's an interesting stress test for I2P. They should try to fix that, the protocol should be resilient to such an event. Even if there are 10x more bad nodes than good nodes (assuming they were noncompliant I2P actors based on that thread) the good nodes should still be able to find each other and continue working. To be fair spam will always be a thorny problem in completely decentralized protocols.
Finding good nodes is a thorny problem for human friendship, too!
Re: A Botnet Accidentally Destroyed I2P
#56This seems to be a better post about what happened, from the same site https://www.sambent.com/i2p-2-11-0-ships-post-quantum-crypto...
I'll save everyone else a click: AI slop text coupled with the strangest, most pointless visualizations I've ever seen.
I didn’t really understand the link between Alice and Bob until I saw a green floaty dot go through a pile of spaghetti with the word compromise beneath it.
Re: A Botnet Accidentally Destroyed I2P
#57Earlier quoted context omitted.
[flagged]
Could you elaborate a bit? It’s hard to take such a claim seriously without any evidence presented.
See the exploit.in thread for example https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B...
Krebs has access to these forums, he could’ve checked this story out in less than 3 minutes but did not.
Even if Krebs wasn’t a subject matter expert, it’s still inexcusable that he didn’t do the most basic work here. You don’t need to frequent underground runet forums to know that a journalist should be able to verify the stories he puts out.
I think it’s also particularly telling that he didn’t bother to source reasonable quality screenshots for the story, which he would have been able to do had he ever witnessed this phishing kit working.
Re: A Botnet Accidentally Destroyed I2P
#58Earlier quoted context omitted.
[flagged]
This is so odd. I tried to verify your claim and I give up. It might be but I really hate how information is becoming like this. There is other reporting out there on "Starkiller" (the phishing kit in kerbs most recent post) and I can find other articles on it, but sources seem to be circular. The source mentions Jinkusu forums, which do seem to be real, but any links I find aren't loading for me and still no conclus…
These forums are mostly private, but Krebs certainly has access to them. There can really be no excuse for how he handled this.
There are multiple posts by people in different places claiming to have bought this phishing kit, and then being delivered totally non-functional vibecoded garbage. The vibecoded garbage is not the advertised product though, as the author never managed to get the AI to finish his project.
Re: A Botnet Accidentally Destroyed I2P
#59Earlier quoted context omitted.
This is why Tor is centralized, so that they can take action like cutting out malicious nodes if needed. It’s decentralized in the sense that anyone can participate by default.
> so that they can take action like cutting out malicious nodes if needed How does that work?
Re: A Botnet Accidentally Destroyed I2P
#60Earlier quoted context omitted.
Could you elaborate a bit? It’s hard to take such a claim seriously without any evidence presented.
Every single person who has bought the phishing kit claims the seller is a scammer. Krebs’s article is based entirely on the sellers description of the (imaginary) product, rather than actual observation of the phishing kit in the wild. See the exploit.in thread for example https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B... Krebs has access to these forums, he could’ve checked this story out in less than…
"Maximum download limit reached" - it's gone. Also, not present in the archive.org :-(