Earlier quoted context omitted.
The start of every US war in the ME has featured attacks on communication and infrastructure, starting with hacking in to the telephone exchanges weeks or months before the hot war starts, and culminating with the takedown of critical physical infrastructure, like power, water, etc. as the first thing to go when the shooting starts.
Can you clarify this? I remember seeing some articles about this tactic in maybe 2010, but nothing before then. I recall the Gulf War and OIF/OEF infrastructure damage being primarily from aerial bombing, but it's possible I missed the articles about the hacking element. I'm not doing the snarky "citations pls" thing; I don't dispute it happened. I just want to know more.
Someone Is Learning How to Take Down the Internet
91–100 of 143 posts
Re: Someone Is Learning How to Take Down the Internet
#92Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…
That's a pity, but I guess it makes sense for him if he wants to exert influence.
Unfortunately too many laypeople take everything he's writing as gospel. Remember when he clearly misunderstood the "xkcd scheme", was called out by pretty much everyone and couldn't even admit that and post a correction? You can be sure that lots and lots of people will dismiss everything looking like it (Diceware!), simply because Schneier erroneously piled heaps of ridicule on it.
Re: Someone Is Learning How to Take Down the Internet
#93Earlier quoted context omitted.
That post is publicly visible to me. It also seems to be the first post for the account, and is fairly substantive. Moreover, I don't think it's even possible to reply to posts made from shadowbanned accounts.
Okay then. I didn't look at the poster's history, I just saw a constructive-looking comment that seemed to be modded to oblivion, and jumped to conclusions. I had to vouch for the post before HN would let me reply, which seems consistent with how shadowbanned accounts are handled here.
Re: Someone Is Learning How to Take Down the Internet
#94Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…
Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…
You're shitting me, right?
Computer engineers are the last people who think in rigid, boolean-logic ways. It's the general population that does that. If you do any serious thinking in any STEM field, you quickly learn that the world is probabilistic in nature, and ambiguity is what you eat for breakfast. What the technical fields do to manage with it is learn to quantify the exact nature of ambiguity. When you do that, by means of probability theory, you learn that ambiguity doesn't mean "anything goes", there are rules it follows.
Like, backchannel intel may be vague, and this also implies it's likely to not be true (unless you can pull out additional evidence in its favour, like e.g. good track record of the person delivering this backchannel intel; that point is discussed in parallel threads). In a sea of noise, the "signal" you see is most likely a coincidence. Not comprehending this (aka. "seeing patterns everywhere") is one of the biggest sources of irrationality in people.
Re: Someone Is Learning How to Take Down the Internet
#95Earlier quoted context omitted.
KG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would…
There's also the issue of the dubious legality of using encryption over eg HAMNET. Modern internet without encryption simply isn't modern internet.
I don't know if there's any legal precedent or official policy regarding digital signatures; I would guess that they're probably okay because they don't obscure the meaning of the communication and anyone can verify them against the sender's public key (assuming that the public keys are published somewhere).
Communication with no privacy but with cryptographically secure signatures might be acceptable for emergency situations. It's unfortunate that ham rules are sufficiently restrictive that most of the tools we use on a day-to-day basis wouldn't be legal to use without substantial modification. But then again, we wouldn't want people trying to log into Facebook/Youtube/Reddit etc.. when the network runs at like 1200 baud (if it's packet radio on the 2 meter or 70 cm bands) or maybe in the low mbps (if it's over some kind of 802.11 b/g/whatever mesh network operating under part 97 rules).
Fortunately, while part 15 rules are pretty restrictive about power, they're less strict about antenna gain, so it's at least theoretically possible to make multi-mile connections without having to operate under ham rules. Building a large network out of point-to-point links with directional antennas, though, would be pretty difficult and laborious even in a non-disaster situation, so realistically I think the best local disaster communications option at the moment is to just use APRS and analog voice over 2 meters and accept that 1980's technology that sort of works is better than a modern internet experience that requires a lot of infrastructure that isn't working or available.
Re: Someone Is Learning How to Take Down the Internet
#96Can anyone elaborate on what he means when he says that Verisign can 'go down' and take down most of the internet with it? How would a registrar going down affect anything to do with actual hosts?
Poor wording. Verisign operates .com for the US government. So if Verisign's .com servers were to go down, then .com would go down with them. The author shouldn't have used the word "registrar" which makes people think of the creation of new domain names, à la GANDI (good) or GoDaddy (bad).
Re: Someone Is Learning How to Take Down the Internet
#97As applicable with all areas of life, association is a security risk. By depending upon any centralized authority (such as a server or domain name registrar) you are open to being censored (either by them or an attacker).
At this point however, decentralized web-hosting solutions still rely upon clearnet centralized port checkers, which is (ofcourse) an issue. The best the community can do is help to raise awareness of decentralized web hosting in the hopes more people will adopt it leading to a higher likelihood that the problems will be solved.
Re: Someone Is Learning How to Take Down the Internet
#98Re: Someone Is Learning How to Take Down the Internet
#99Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…
Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…
This is a limitation of computers, not the engineers. The engineers are happy to deal with ambiguous information as long as you don't mind ambiguous results.
Re: Someone Is Learning How to Take Down the Internet
#100The Internet is suppose to be decentralized. Yet we have these centralized groups, proving backbone, DNS, certs. Well duh, it's no surprise. Why can't I connect to my neighbor who lives next door without the packet doing a 200 mile trip? The Internet is really only devices that can route packets through at least 2 different gateways. If you only have one route. You are not part of the vision of the Internet.