Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

71–80 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#71
post #46
post #39

Earlier quoted context omitted.

DOS is a kind of protest, like a picket line. Protest != terrorism.

A protest becomes terrorism when it prevents access to vital services (eg "picketing" a hospital and not allowing ambulances in/out)

So if a bunch of hospital workers were protesting their pay and formed a picket line around a hospital, their purpose would be to 'instill terror?' Somehow this comes across as adding to the dilution of the word 'terrorism.'

Do you really think that picketing a hospital is comparable to using guerilla tactics against a civilian population?

I'm not agreeing that people should be allowed to prevent access to a hospital, but the idea that 'terrorism' is the best label for this sort of action seems ill-advised. Maybe I'm being naive, but I don't think that anyone would have called such actions 'terrorism' back in the 90's, why is it all of the sudden terrorism now?

Seems like any deliberate action by a small group of people against a larger group of people that will have any sort of adverse affect on the larger group is being crammed into the 'terrorism' bucket these days...

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#72
post #43

And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...

TFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).

TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).

TOR itself filters it:

    Also, remember that many of their more subtle communication mechanisms
    (like spoofed UDP packets) can't be used over Tor, because it only transports
    correctly-formed TCP connections. 
My guess is that they're just clueless.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#73
post #38
post #6

I'm pretty sure every hacker group has gotten this idea at one point or another. Has anyone even come close to taking down all the root DNS servers at once?

Given the built-in resiliency of the DNS system, wouldn't creating an alternative system[1] be more effective in disrupting the status quo? [1] http://en.wikipedia.org/wiki/AlterNIC

Creating one is easy compared to getting people to use it.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#74
post #48

Earlier quoted context omitted.

So could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?

* Verisign, because they inherited MCI and thus UUNet. * USC, one of the headquarters of academic network research. * Cogent (no idea why, but they're a sort-of tier 1 NSP).† * UMD, another headquarters of academic network research. * NASA, because space. * ISC, because they organized the authorship of BIND. * DISA, because of DARPA. * Army Research Lab, because of .MIL. * Whoever owns NORDU.NET, which was is a conso…

wow thanks for the list. So mostly US organizations.

Could the design be better if we had to rewrite it today? Any plans to include other countries (China etc.)?

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#75
post #37
post #33

Earlier quoted context omitted.

No; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.

The problem is that, in the DNS spoof attack, the DNS reflectors have to have some data to send "back" to the spoofed IP. If the root servers are down, the reflectors won't have any data to send back, so the flood will stop as the reflectors' caches expire.

As far as I know, they should still send a SERVFAIL response if they are unable to contact the authoritative servers.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#77
post #23
post #10

Let's assume they succeed. They take down the Internet at noon EDT (9AM PDT). What's the worst that could happen?

Well that all depends. First most requests don't go to the root servers -- they are far too important, second there is caching on the isps servers. To have any effect other than to make sys admins dehydrate anon have to keep the attack up long enough to have the caches empty (if they are indeed configured to flush even if they cannot connect to the root. They may not) and there are several layer deep caching (your is…

Bittorrent will still work, though ;) Well, at least if using DHT. The trackers use a domain, of course.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#78
Why do people always take these so seriously?

It's far more likely that a bored teenager somewhere wrote this.

Also, if we were to assume that Anonymous does actually exist in some semblance, they would never ship a notice like this with gramatical errors. They're small, but obvious.

I'll eat my foot if they actually manage to make a noticeable affect on the DNS servers anyway.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#79
post #42

I don't know if they're just simplifying things or are just clueless, but none of the 13 DNS roots are single servers. Most or all of them aren't even in a single physical site. There's somewhere around 240 root server sites each consisting of multiple physical servers, just served up on 13 IP's. Given that many of these sites are colocated at interchanges and with providers with tons of multi gigabit links, they hav…

We have no proof that this is even Anonymous. We have nothing that says that the author of this is even a hacker or knows hackers. Any person following the Anonymous attacks and statements could have easily written this file.

Why is this on hacker news? This is not news, this is a poorly (tech wise) written short story.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#80
The bottom line is simple: they can't do it, they won't be able to do it, and it makes the issue moot. Someone is desperate for attention.

You would need to have complete control over the infrastructure of something equivalent to an Amazon, Microsoft, or Google to take down the whole DNS system - and it would require a permanently sustained and constantly evolving attack.

I'm always amazed at the vast under-estimation of what would be faced in a real attempt of that sort. First, let's assume they made some progress and actually started harming the stability of the global Internet. 1) the number of interested parties (from hackers to corporations) that would immediately respond to the counter, in numerous ways, would resolve the issue in an extraordinarily short amount of time and 2) watch you don't have the US special forces black bagging you within 24 hours if you're involved, no matter where you're at on earth. The corporate money interest in the Internet being up is at least a hundred billion dollars per day. They will kill you over that, or at the least put you in an off grid terrorist prison.

Post reply on HN