Live data from Hacker News

Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

dynstatus.com

61–70 of 94 posts

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#61

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

Even if you assume an overwhelming court victory (by settlement or judgment), there will still inevitably be tens of millions of vulnerable devices out there. I'm betting most of these products don't have anything in the way of automated remote patching.

And if these bot herders are smart, they're changing the vulnerable configurations or adding rudimentary ACLs so that they can keep the bots to themselves. White hat IoT-fixing scripts may not be too effective.

But yes, court action is probably necessary to prevent the problem from getting much worse than it already is.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#62

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

Am I the only one who finds the notion that "the free market will solve this problem" by using the court system (an entity of the state operating on laws passed by the government) at odds?

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#63
post #60

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance.

Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#64

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

That's a common, if naive, misconception. How exactly is a plaintiff going to enforce a judgment against a manufacturer overseas, or against an Internet-enabled thermostat?

The US legal system, at least, was designed for quite a few things, but enforcing Econ 101 was not one of them.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#65
post #60

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

On top of that, that isn't generally how liability works. If you make a crappy garage door that anyone can open, the people who bought one might be able to require you to fix it, or possibly make claims for losses if things are stolen. But when some vandals steal spray paint and sledge hammers and smash up the neighborhood, the vandals are the ones responsible for smashing up the neighborhood.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#66
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance. Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

More likely the marketplace itself moves overseas. People use Amazon because they sell the stuff they want. If they stop selling it, the buyers go somewhere else. Amazon is a website. It could as easily be a website hosted out of China.

Also, it sounds like you don't mind if the effect of your proposal is to destroy things like Etsy. And eBay.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#67

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

Hey, can one sue manufacturer of a stolen car that was used to rob and kill people (and returned to the owner afterwards of you wish)? Does it matter if that car model was easier or harder to hijack?

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#68
post #37
post #15

Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…

Getting good, consistent, well routed, fast and secure DNS Is harder than you'd think. Dyn typically sing speed as the main selling point for their DNS product, they do this through a large distribution of domain name servers geographically and anycast. Many hosts (like say, DigitalOcean) run their own DNS but use something like CloudFlare Virtual DNS on top. Personally I was surprised so many large sites trusted Dyn…

Route 53 aint all that. We approached them about handling our customer's domains, and they said no way. They didn't have the capacity. Granted, this was 2 years ago, but Dyn has a much better reputation (still) than Route 53.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#69
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

Don't forget that DDoS is a market too, and not the smallest one.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#70
post #39
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

vodafone is building a lowband/narrowband WAN that could/should be used for helping fix an impending Botpocalypse type of thing IF It's implemented with such a goal in mind: http://www.theregister.co.uk/2016/10/20/vodafone_nb_iot_roll...

It's not Vodafone specific, it's really a generic property of cellular IoT.

Any 3GPP technology (for IoT, primarily 2G and LTE) can provide private PDN connectivity, where the device is not put on the Internet but on a private LAN. In this case, the device will only talk to friendly server and will not be directly accessible from random hacker. Now it's not a mandatory features either, so some devices can be put on the Internet and become reachable. Even in this case the situation is less dire: the devices are attached to a subscription, and it's in theory possible to insert some filtering. Also, operators now often require that devices support over-the-air (OTA) software updates, which allows fixing vulnerabilities.

Now with 2G it's possible to have rogue base stations to hack devices. But this is a local attack, so not usable for this kind of massive DDoS. And this hole is closed in LTE, where there is mutual authentication (device authenticates the network too).

So yes, I believe cellular IoT should be safer. The private PDN feature is very simple and very effective. Now, will have to see the prices for the new lower cost IoT LTE categories: CatM1 and NB1.

CatM1 will be the first to appear in the US. It's rather versatile, and can handle low throughput data and will handle VoLTE in a second step. NB1 will appear first in Europe. It's more streamlined but it's really for message based application (sending a message now and then) and data only.

Post reply on HN