Live data from Hacker News

Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

dynstatus.com

71–80 of 94 posts

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#71

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

That's a common, if naive, misconception. How exactly is a plaintiff going to enforce a judgment against a manufacturer overseas, or against an Internet-enabled thermostat? The US legal system, at least, was designed for quite a few things, but enforcing Econ 101 was not one of them.

The lawsuit will work because US distributors and retailers (hi Amazon) have joint and several liability for damage caused by defective products they sell.

You don't have to chase small anonymous overseas manufacturers. Distributors, acting in their own self-interest, choose to not sell the offending products.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#72
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

On top of that, that isn't generally how liability works. If you make a crappy garage door that anyone can open, the people who bought one might be able to require you to fix it, or possibly make claims for losses if things are stolen. But when some vandals steal spray paint and sledge hammers and smash up the neighborhood, the vandals are the ones responsible for smashing up the neighborhood.

If it is foreseeable that your defective product would be used to harm another person, you can be held liable. Yes, the intervening actor is behaving illegally. That doesn't matter. You still bear your fair share of responsibility.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#73
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

On top of that, that isn't generally how liability works. If you make a crappy garage door that anyone can open, the people who bought one might be able to require you to fix it, or possibly make claims for losses if things are stolen. But when some vandals steal spray paint and sledge hammers and smash up the neighborhood, the vandals are the ones responsible for smashing up the neighborhood.

[deleted]

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#74

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

Hey, can one sue manufacturer of a stolen car that was used to rob and kill people (and returned to the owner afterwards of you wish)? Does it matter if that car model was easier or harder to hijack?

I sell a defective telephone pole. A vandal comes along and pushes it. The pole falls on your house. I am liable for damages to your house. The vandal is, too.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#75

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

Hey, can one sue manufacturer of a stolen car that was used to rob and kill people (and returned to the owner afterwards of you wish)? Does it matter if that car model was easier or harder to hijack?

[deleted]

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#76

Earlier quoted context omitted.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance. Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

More likely the marketplace itself moves overseas. People use Amazon because they sell the stuff they want. If they stop selling it, the buyers go somewhere else. Amazon is a website. It could as easily be a website hosted out of China. Also, it sounds like you don't mind if the effect of your proposal is to destroy things like Etsy. And eBay.

The legal system is less brain-dead than you imagine. :-) This is not the first time in history that a plague of imported items causes a problem.

Etsy and eBay will survive. Ford survived the Exploding Pinto. Firestone survived its tire debacle. And we are all the safer for it.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#77
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance. Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

Um, AliExpress, heard of it?

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#78
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

Fuses (circuit breakers actually) are required by code.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#79
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance. Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

[deleted]

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#80
post #60

Earlier quoted context omitted.

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.

This is why tort lawyers sue distributors and retailers in the USA. They are here and they have insurance. Once there is a court decision, a rational seller (oh, Amazon hypothetically) will understand that selling fly-by-night small manufacturer items is fraught with peril. The offending items disappear from the marketplace.

Your response is still completely ignoring the problem of identifying the offending devices. When all you have to go on is a spoof-able possibly dynamic IP address, and the device is probably behind NAT anyway, good luck tracking it down or knowing what it is, in enough cases to prevent you from making more than a small dent in the problem. Then even once you know what it is, that doesn't tell you who the owner is. Then even if you find the owner, that doesn't tell you the retailer or the distributor. By the time you find the distributor, the device will be obsolete anyway and replaced by the next generation of bad devices.

Your way may have worked in the past when the harm was felt directly by the consumer who knew who the retailer was. But now, the harm is inflicted on remote parties who have no inkling about the source of the harmful devices. So your argument has a huge hole in it.

Post reply on HN