Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

71–80 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#71
post #4

Earlier quoted context omitted.

'the author' (Bruce Schneier) is right a lot.

He suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.

> What exactly rules out an American agent?

What exactly rules out America? NSA wants to see how an attack might unfold, or wants to see how to actually shut things down in case of insurrection, a coup, or pitchforks. Does some hard probing. Things get bad, and companies call in ... the NSA, who then get to do unfettered battle damage assessment.

Re: Someone Is Learning How to Take Down the Internet

#72
post #28

Earlier quoted context omitted.

The amateur radio community already has the technical know-how and disaster readiness to do most of that, and I'd be willing to bet there's enough overlap between them and the meshnet crowd to take care of the rest.

KG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would…

There's also the issue of the dubious legality of using encryption over eg HAMNET. Modern internet without encryption simply isn't modern internet.

Re: Someone Is Learning How to Take Down the Internet

#73

Earlier quoted context omitted.

If you see a hot war, under current circumstances it will almost certainly be preceded (if only for a few minutes) by a full-on cyber attack.

It's an interesting arrangement. Launching a cyber war for its own sake might or might not escalate to a hot conflict, but a hot conflict would almost certainly be backed by the cyber version.

So in addition to debating launch on warning, we now have to think about launch on DDoS.

Re: Someone Is Learning How to Take Down the Internet

#74

Earlier quoted context omitted.

I don't think he can give citations or evidence. He gets told some stuff in confidence. He can violate the confidence, and not be told stuff in the future. Or he can say nothing. Or he can tell us as much as he feels he can, even though that's annoyingly vague and unspecific. As far as I can see, those are his only options. On this topic, he chose the third option, because he felt that people needed to know, even tho…

I think you are mischaracterizing my statement. At no point did I suggest he should violate journalistic integrity by belying his sources' confidence. I do say that it's inappropriate to expect implicit trust after all his previous integrity failures (conjecture as fact, etc). I want to believe this article. I do believe it. But I also can't rely on it, as his track record shows that given the topic of computer secur…

Can you please do as you say, and provide specific citations and examples of his conjectures framed as fact?

Re: Someone Is Learning How to Take Down the Internet

#75

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information.

Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual.

Take it in for what it's worth. It's a signal from a sea of noise, nothing more. Maybe it's actionable, but perhaps it's not. Just learn to deal with ambiguity; the world at large is quite different from the rigid boolean-logic computer systems you're interacting with on a daily basis.

Re: Someone Is Learning How to Take Down the Internet

#76
post #41
post #15

Since there are lots of hobbies that sometimes overlap with community service I'd love to see a club that focuses on being prepared to reestablish intra-community communication in case the Internet goes down. Yes, it'd be great if everyone was self hosting, using distributed services and involved in a mesh network now, but without motivation it won't happen. So this club could focus on developing the resources that a…

things along those lines are already happening in oakland and a number of other cities across the country. https://sudoroom.org/wiki/Mesh

Seconded. Definitely look into meshnets. There's one in Red Hook (brooklyn) that's been up and running for a long time.

Re: Someone Is Learning How to Take Down the Internet

#77

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…

> the world at large is quite different from the rigid boolean-logic computer systems you're interacting with on a daily basis.

This rhetoric is patronizing and doesn't contribute to the conversation.

Re: Someone Is Learning How to Take Down the Internet

#78

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…

Taken out of context, your statement is true. In context, your relativist position isn't applicable. In this case, this is a renowned cryptologist making some assertions. My complaint was that this article is good, but given the author's track record, I want more evidence. I don't think that's unreasonable.

Re: Someone Is Learning How to Take Down the Internet

#79

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Schneier cited the Verisign DDoS trends report and provided a link to it. He also cites anonymous sources. These sources agreed with each other and with the public report from Verisign. He explained why he was keeping those sources anonymous. That is just good journalism.

I agree with everything you said.

My comment was juxtaposing it with the accuracy of Schneier's blog and his public statements on computer security.

Re: Someone Is Learning How to Take Down the Internet

#80
post #16

So how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious atta…

Just to clarify, there are 13 "logical" root server but each one can be implemented by multiple servers. For example, L is implemented by 157 spread across the globe (see http://l.root-servers.org/ ). Many of the others are similarly redundant and distributed.
Post reply on HN