Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

61–70 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#61

Earlier quoted context omitted.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

I don't think we should rule out the US, as they conduct defense drills all of the time. In this case, they don't overtly control the assets under attack, but would still want to know how resilient our networks are "in the real world" -- not always as a "friendly" drill, a la Red Cell. https://en.wikipedia.org/wiki/Red_Cell

Link to the videos next time:

https://www.youtube.com/watch?v=hWCX6IeBH7U

They'll learn a lot more from them. ;)

Re: Someone Is Learning How to Take Down the Internet

#62
post #4

Earlier quoted context omitted.

'the author' (Bruce Schneier) is right a lot.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

> He suspects China or Russia as the likely culprit. What exactly rules out an American agent?

Well, a mere suspicion does not rule out properly anything. It's like a quantum wave function with a maximum of probability density on China, but non-zero values everywhere.

Re: Someone Is Learning How to Take Down the Internet

#63
post #46

Earlier quoted context omitted.

His writing about cryptography certainly should include citations.

It might sound blasphemous but I (as a non-expert in crypto) would be satisfied if either you or Bruce didn't cite their writing about crypto. Yes, appeal to authority and all that, but I don't have time to fully learn a field to find out if a cryptographer is mistaken. Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.

Ngah. No. You should definitely want references from me, too!

Re: Someone Is Learning How to Take Down the Internet

#64
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

Every once in a while I think of creating a little DNS cache that never expires entries, except when it runs out of storage, and run it on a Raspberry Pi, feeding it with DNS queries on my home network (but never using it to send replies to clients, just store queries and results).

But I never do anything about it.

Re: Someone Is Learning How to Take Down the Internet

#65

Blaming China or Russia is lazy writing. It could be just about anyone, including a rogue internal agency doing a spoof-attack to precisely cause the blame to go towards the obvious "state actors". Cyber-warfare is the 'new' war and just like any war, misinformation plays an important role.

Since he took the time to explain what a DDOS is, I think he felt the need to say "China or Russia" to help set the scale for people reading who aren't familiar with this kind of stuff.

Re: Someone Is Learning How to Take Down the Internet

#66
post #28

Earlier quoted context omitted.

The amateur radio community already has the technical know-how and disaster readiness to do most of that, and I'd be willing to bet there's enough overlap between them and the meshnet crowd to take care of the rest.

KG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would…

Wouldn't SDRs be a lot more useful for creating higher-bandwidth wireless networks in the sort of disaster where the FCC opens up other frequency ranges?

The amateur radio regulation regime and common ham radios work well for small numbers of small messages sent around in a well-regulated way, without the government initiating a frequency band jubilee. But beyond that, HAM radios are limited, even if they're modded, and the cheap SDRs are even cheaper than baofeng handhelds, so where does that leave amateur radio in a real frequency free-for-all? I think what would matter is, as mentioned above, availability of SDRs, and secondly, parties of people tracking down transmitters that are messing up the ad-hoc sdr wireless nets.

Re: Someone Is Learning How to Take Down the Internet

#67

Earlier quoted context omitted.

My point is that his honesty is actually not existent, as it has been tainted by his provably incorrect speculation from 2013-2016. I think it's absolutely valid for tptacek to demand citations from Schneier!

> My point is that his honesty is actually not existent, as it has been tainted by his provably incorrect speculation from 2013-2016. What are you referring to here? And, taking your statement at face value: If he speculated, and was clear that he was speculating, and was wrong, that doesn't destroy his honesty - merely his reputation as a speculator.

Indeed in my original comment I assert that he speculates without appropriately labeling it as such. Hence, why my viewpoint is controversial on HN. Most HNers believe Mr. Schneier is an authority on computer security. I believe he takes his genuine expertise in cryptography and mistakes it for understanding of computer security that he doesn't actually possess.

His shortcomings are especially apparent when applied to APT, memory corruption, and computer network intrusion/defense.

Re: Someone Is Learning How to Take Down the Internet

#68
post #63

Earlier quoted context omitted.

It might sound blasphemous but I (as a non-expert in crypto) would be satisfied if either you or Bruce didn't cite their writing about crypto. Yes, appeal to authority and all that, but I don't have time to fully learn a field to find out if a cryptographer is mistaken. Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.

Ngah. No. You should definitely want references from me, too!

On second thought, I do want references. I thoroughly enjoy watching you and other cryptographers arguing on HN. Especially when the topic of DNSSEC comes up.

Re: Someone Is Learning How to Take Down the Internet

#69

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Schneier cited the Verisign DDoS trends report and provided a link to it.

He also cites anonymous sources. These sources agreed with each other and with the public report from Verisign. He explained why he was keeping those sources anonymous.

That is just good journalism.

Re: Someone Is Learning How to Take Down the Internet

#70

Earlier quoted context omitted.

KG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would…

Wouldn't SDRs be a lot more useful for creating higher-bandwidth wireless networks in the sort of disaster where the FCC opens up other frequency ranges? The amateur radio regulation regime and common ham radios work well for small numbers of small messages sent around in a well-regulated way, without the government initiating a frequency band jubilee. But beyond that, HAM radios are limited, even if they're modded,…

Sure, but everything has to be ready, prepared and exercised before anything happens. Whatever plan you may conceive, you have to do plenty of test runs in advance. After it happens, it's chaos, it's too late to start new initiatives.

And there are caveats anyway.

For local connections, some kind of WiFi mesh might still be the best option.

For long distance, I don't think you can currently use anything but proper HAM equipment, and fairly large power at that. For a reliable connection, especially at good bandwidth, you need lots of power and a good antenna. But if you blow standards out of the water, and start pumping out huge bandwidths at huge powers, you run again into a tragedy of commons - you're taking up large chunks of spectrum over entire continents.

There is no free lunch.

Post reply on HN