Live data from Hacker News

Possible Vendetta Behind the East Coast Web Slowdown

bloomberg.com

61–70 of 206 posts

Re: Possible Vendetta Behind the East Coast Web Slowdown

#61
post #53

I know the TTL is set really low for a lot of DNS entries but this recent outage got me wondering if it makes sense for servers further down the chain to hold onto it for longer than the TTL, honor it when they are able to get a new DNS entry within a reasonable amount of time, but fall back to the "expired" version if the authoritative server is not reachable. I'm wondering what would be the negative consequences of…

There was a good discussion on this in a sibling thread earlier today: https://news.ycombinator.com/item?id=12762110

Re: Possible Vendetta Behind the East Coast Web Slowdown

#62

Earlier quoted context omitted.

Just like with bridges. Getting certification by a professional engineer is just too much barrier to entry for small construction companies. Edit: forgot the /s

I'm not sure if you're being sarcastic, but isn't that a good thing?

[deleted]

Re: Possible Vendetta Behind the East Coast Web Slowdown

#64
post #37

Earlier quoted context omitted.

It's easy to fix; back in the day when a machine was infected; an ISP would just block outgoing traffic, contact line owner and re-enable when the issue is resolved.

Possibly stupid question: why is that no longer done?

Because today you can't call the customer anymore if you block their traffic.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#65

Earlier quoted context omitted.

Very young person so possibly impulsive; started college at age 12 so might not have developed enough emotional intelligence to avoid doing these things. I mean, Bloomberg is pointing fingers, I'm just trying to understand why an anti-DDoS firm would be DDoSing other firms.. EDIT: Also, "Marshal Webb, 18, whose Hamilton, Ohio home was raided this week by FBI agents as part of the LulzSec investigation". Maybe he did…

Per his LinkedIn[0] he started college at age 16. He's 23 now. The fact that he started college 2 years early, seven years ago, made him decide to DDoS a huge DNS provider? That's quite a leap... [0] - https://www.linkedin.com/in/webbmt

See my edit. You have fingers pointed at him, an unusual coincidence, and a background of being arrested by the FBI due to DDoS attacks he did when he was 16. Would you really be "surprised" if you find out he was the culprit, given these priors?

I'm not a judge nor a jury, I'm not stating he is guilty, just that that's more likely that a random guy attacking the firm

Re: Possible Vendetta Behind the East Coast Web Slowdown

#67
post #5

Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable

Firmware updating isn't exactly a "hard tech" problem, even if it is hard to do right. I suspect we'll see some generic firmware update frameworks/solutions emerge in the coming decade, and at that point adoption will pick up rapidly because being able to push updates is good for business.

Firmware updating isn't hard tech. Secure firmware update over public network is.

Re: Possible Vendetta Behind the East Coast Web Slowdown

#68

Here's a better article from Mr. Krebs: https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twit... Personally I think his case is pretty convincing.

Guess what, Krebs' site also receives a spanking at the moment. (Given that it's hosted by Google I find it highly unlikely to go down under normal traffic)

Re: Possible Vendetta Behind the East Coast Web Slowdown

#69

Earlier quoted context omitted.

Possibly stupid question: why is that no longer done?

Because it's hard to get an ISP to disable a service for one of their paying customers to help other people on the Internet who aren't paying them.

Why can't everyone else then block the customer? Get the big 5 tech companies to block IPs that are shown to do DDOS, for say a 24hr period, and you will see how quickly they unplug that IOT Toaster

Re: Possible Vendetta Behind the East Coast Web Slowdown

#70
post #59

Earlier quoted context omitted.

So grandpa goes to Home Depot, buys a fancy new thermostat and installs it at his home, the device gets hijacked by the archetypal 400 lb hacker, and is used to take down a major commercial site, and then grandpa is liable for the whole thing? I don't think so. You make a little gizmo with shitty security, you are liable. Full stop.

So grampa doesn't take care of his car, the brakes fail and he kills a family with four kids. Is he liable? Yes. He may not know the first thing about brakes or car repair but owns the car, and he took it out on the road without being sure it was in safe operating condition. But to steal an idea from another comment, make the ISPs liable also for routing the malicious traffic onto the internet. They will then have in…

And so grandpa needs to become a network security expert to avoid getting sued. Right, "makes sense". ;)

This is not like not doing maintenance on your car. This is like buying a car with faulty airbags. The manufacturer needs to issue a recall and fix the darn thing - or else face legal action.

Post reply on HN