Live data from Hacker News

A Botnet Accidentally Destroyed I2P

sambent.com

61–70 of 101 posts

Re: A Botnet Accidentally Destroyed I2P

#61
Is there a shittier summary anywhere, please? Or did the author reached the peak of enshittification?

Honestly, did the bot implementation have bugs or was it a proper implementation that crashed the network due to sheer numbers?

Also, how does changing the encryption standard affect anything if the bots tried to integrate correctly with the network?

Is the problem "fixed" or is it not? Elsewhere I found large number if botnet devs got pissed off with this botnet operator and 600k nodes went offline. Might this have much more to do with the situation getting better than simply changing encryption?

Also, was there any suggestion a quantum breaking attack was attempted? No. So why put the emphasis on "post quantum" in this article?

Bad. Very bad.

Re: A Botnet Accidentally Destroyed I2P

#62
post #59

Earlier quoted context omitted.

> so that they can take action like cutting out malicious nodes if needed How does that work?

While anyone can run a Tor node and register it as available, the tags that Tor relays get assigned and the list of relays is controlled by 9 consensus servers[1] that are run by different members the Tor project (in different countries). They can thus easily block nodes. [1]: https://consensus-health.torproject.org/

It's 10, not 9. And there are severe problems with having a total of 10 DA be the essential source of truth for whole network. It would be trivial to DDoS the DAs and bring down the Tor network or at the very least, disrupt it: https://arxiv.org/abs/2509.10755.

It's the only complaint I have of the current state of Tor. Anyone should be able to run directory authority, regardless if you trust the operator or not (same as normal relays).

Re: A Botnet Accidentally Destroyed I2P

#63

Earlier quoted context omitted.

Could you elaborate a bit? It’s hard to take such a claim seriously without any evidence presented.

Every single person who has bought the phishing kit claims the seller is a scammer. Krebs’s article is based entirely on the sellers description of the (imaginary) product, rather than actual observation of the phishing kit in the wild. See the exploit.in thread for example https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B... Krebs has access to these forums, he could’ve checked this story out in less than…

> Krebs’s article is based entirely on the sellers description of the (imaginary) product, rather than actual observation

I noticed. While researching I had a feeling of "is this just makeup on a pig?". Anyone can make pretty graphics or make claims. I tried reading a few selling points and I was weary.

One claimed to handle a MFA token handover and then somehow got access to the token and they could proxy it for you? The user types in the MFA token, they get the token. I cant figure out how they would bypass all browser protections to pass on the highly-secured token via a proxy. I've been online for 25 years, I understand on a deep level on the internet works and the web and what is happening in this situation, as I'm sure most here are.

Without a 0day, this just doesn't make sense. But this is pretty technical, and unless you hang out here then the above sounds perfectly reasonable but to us sounds like bullshit.

> he didn’t bother to source reasonable quality screenshots for the story

Also noted. Quickly found better quality versions myself with a quick search.

Re: A Botnet Accidentally Destroyed I2P

#64
post #60

Earlier quoted context omitted.

Every single person who has bought the phishing kit claims the seller is a scammer. Krebs’s article is based entirely on the sellers description of the (imaginary) product, rather than actual observation of the phishing kit in the wild. See the exploit.in thread for example https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B... Krebs has access to these forums, he could’ve checked this story out in less than…

>See the exploit.in thread for example https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B ... "Maximum download limit reached" - it's gone. Also, not present in the archive.org :-(

https://files.catbox.moe/fod8rc.pdf

https://web.archive.org/web/20260222094129/https://files.cat...

Re: A Botnet Accidentally Destroyed I2P

#65
post #52

Earlier quoted context omitted.

This is so odd. I tried to verify your claim and I give up. It might be but I really hate how information is becoming like this. There is other reporting out there on "Starkiller" (the phishing kit in kerbs most recent post) and I can find other articles on it, but sources seem to be circular. The source mentions Jinkusu forums, which do seem to be real, but any links I find aren't loading for me and still no conclus…

https://temp.sh/XOWUP/STARKILLER_V6.0.1___ULTIMATE_WEAPON__B... These forums are mostly private, but Krebs certainly has access to them. There can really be no excuse for how he handled this. There are multiple posts by people in different places claiming to have bought this phishing kit, and then being delivered totally non-functional vibecoded garbage. The vibecoded garbage is not the advertised product though, as…

I figured the forums were real, just was blocked for some reason so thanks.

I do not doubt this story for a second. Its crazy Kerb's is basically freely advertising this blackhat slop.

Re: A Botnet Accidentally Destroyed I2P

#66

Earlier quoted context omitted.

No. They should not try to survive such attacks. The best defense to a temporary attack is often to pull the plug. Better than than potentially expose users. When there are 10x as many bad nodes as good, the base protection of any anonymity network is likely compromised. Shut down, survive, and return once the attacker has moved on.

Why would an attacker move on if it can maintain a successful DoS attack forever?

The mentioned botnet didn't intentionally take down I2P. It's run by bunch of kids who don't know what they're doing.

Re: A Botnet Accidentally Destroyed I2P

#67
post #5

Earlier quoted context omitted.

Many state bodies involved in adversarial action have dedicated budgets for offensive cyber-warfare, credential thefts, supply chain compromises and disinformation. If they haven't used all of their budget by the end of the budget period, they'll be allocated a smaller budget for the next budget period.

Oh ffs. Whenever I think my opinion on the state of the world can’t get any lower, things somehow manage to get dumber.

State sponsored cyber attacks are news to you? It's been a thing since more than 2 decades now.

Re: A Botnet Accidentally Destroyed I2P

#68
post #52

Earlier quoted context omitted.

[flagged]

This is so odd. I tried to verify your claim and I give up. It might be but I really hate how information is becoming like this. There is other reporting out there on "Starkiller" (the phishing kit in kerbs most recent post) and I can find other articles on it, but sources seem to be circular. The source mentions Jinkusu forums, which do seem to be real, but any links I find aren't loading for me and still no conclus…

Krebs lack any sort of real credibility. He's pushing out slop with a govern-mentalist propaganda. Tech journalists are the worst form to gather any actual information.

Re: A Botnet Accidentally Destroyed I2P

#69
post #21

Isn't I2P java? The botnet uses java? I thought python or C is preferred for that kinda stuff

Computers are so fast it doesn’t matter

"Since the abstraction layers have quadrupled, let's not just care about the actual performance anymore!"

Re: A Botnet Accidentally Destroyed I2P

#70
post #55

Earlier quoted context omitted.

Finding good nodes is a thorny problem for human friendship, too!

That's why the Web of Trust, or classic GNUPG key signing parties are a forgotten/ignored must have. Anyone can change and go rouge of course, but it's statistically less likely.

If I understand gp correctly, the web of trust comes after finding these human nodes, and will not help you in the process.
Post reply on HN