Live data from Hacker News

Someone Is Learning How to Take Down the Internet

lawfareblog.com

91–100 of 143 posts

Re: Someone Is Learning How to Take Down the Internet

#91
post #8

Earlier quoted context omitted.

The start of every US war in the ME has featured attacks on communication and infrastructure, starting with hacking in to the telephone exchanges weeks or months before the hot war starts, and culminating with the takedown of critical physical infrastructure, like power, water, etc. as the first thing to go when the shooting starts.

Can you clarify this? I remember seeing some articles about this tactic in maybe 2010, but nothing before then. I recall the Gulf War and OIF/OEF infrastructure damage being primarily from aerial bombing, but it's possible I missed the articles about the hacking element. I'm not doing the snarky "citations pls" thing; I don't dispute it happened. I just want to know more.

I can't find the article I read at the time. The gist of it was that a sysadmin was bribed to gain access to the telephone exchanges and once the Iraqi government realized they were compromised they ran expedient unburied fiber links to communicate with commanders.

Re: Someone Is Learning How to Take Down the Internet

#92

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Schneier is undoubtably a world-class expert in cryptanalysis and cryptography, but he has decided to leave that field and become a tech journalist and pundit.

That's a pity, but I guess it makes sense for him if he wants to exert influence.

Unfortunately too many laypeople take everything he's writing as gospel. Remember when he clearly misunderstood the "xkcd scheme", was called out by pretty much everyone and couldn't even admit that and post a correction? You can be sure that lots and lots of people will dismiss everything looking like it (Diceware!), simply because Schneier erroneously piled heaps of ridicule on it.

Re: Someone Is Learning How to Take Down the Internet

#93
post #53
post #31

Earlier quoted context omitted.

That post is publicly visible to me. It also seems to be the first post for the account, and is fairly substantive. Moreover, I don't think it's even possible to reply to posts made from shadowbanned accounts.

Okay then. I didn't look at the poster's history, I just saw a constructive-looking comment that seemed to be modded to oblivion, and jumped to conclusions. I had to vouch for the post before HN would let me reply, which seems consistent with how shadowbanned accounts are handled here.

Sounds like someone flagged it for whatever reason and it was flag-killed.

Re: Someone Is Learning How to Take Down the Internet

#94

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…

> Just learn to deal with ambiguity; the world at large is quite different from the rigid boolean-logic computer systems you're interacting with on a daily basis.

You're shitting me, right?

Computer engineers are the last people who think in rigid, boolean-logic ways. It's the general population that does that. If you do any serious thinking in any STEM field, you quickly learn that the world is probabilistic in nature, and ambiguity is what you eat for breakfast. What the technical fields do to manage with it is learn to quantify the exact nature of ambiguity. When you do that, by means of probability theory, you learn that ambiguity doesn't mean "anything goes", there are rules it follows.

Like, backchannel intel may be vague, and this also implies it's likely to not be true (unless you can pull out additional evidence in its favour, like e.g. good track record of the person delivering this backchannel intel; that point is discussed in parallel threads). In a sea of noise, the "signal" you see is most likely a coincidence. Not comprehending this (aka. "seeing patterns everywhere") is one of the biggest sources of irrationality in people.

Re: Someone Is Learning How to Take Down the Internet

#95
post #72

Earlier quoted context omitted.

KG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would…

There's also the issue of the dubious legality of using encryption over eg HAMNET. Modern internet without encryption simply isn't modern internet.

The legality of encryption on ham isn't dubious, it's explicitly not allowed.

I don't know if there's any legal precedent or official policy regarding digital signatures; I would guess that they're probably okay because they don't obscure the meaning of the communication and anyone can verify them against the sender's public key (assuming that the public keys are published somewhere).

Communication with no privacy but with cryptographically secure signatures might be acceptable for emergency situations. It's unfortunate that ham rules are sufficiently restrictive that most of the tools we use on a day-to-day basis wouldn't be legal to use without substantial modification. But then again, we wouldn't want people trying to log into Facebook/Youtube/Reddit etc.. when the network runs at like 1200 baud (if it's packet radio on the 2 meter or 70 cm bands) or maybe in the low mbps (if it's over some kind of 802.11 b/g/whatever mesh network operating under part 97 rules).

Fortunately, while part 15 rules are pretty restrictive about power, they're less strict about antenna gain, so it's at least theoretically possible to make multi-mile connections without having to operate under ham rules. Building a large network out of point-to-point links with directional antennas, though, would be pretty difficult and laborious even in a non-disaster situation, so realistically I think the best local disaster communications option at the moment is to just use APRS and analog voice over 2 meters and accept that 1980's technology that sort of works is better than a modern internet experience that requires a lot of infrastructure that isn't working or available.

Re: Someone Is Learning How to Take Down the Internet

#96
post #7
post #3

Can anyone elaborate on what he means when he says that Verisign can 'go down' and take down most of the internet with it? How would a registrar going down affect anything to do with actual hosts?

Poor wording. Verisign operates .com for the US government. So if Verisign's .com servers were to go down, then .com would go down with them. The author shouldn't have used the word "registrar" which makes people think of the creation of new domain names, à la GANDI (good) or GoDaddy (bad).

What does it mean "operates .com" and ".com would go down"? Does it mean that "google.com" would suddenly stop resolving? If so, how is that possible given the way DNS works? If not, what exactly is the panic about?

Re: Someone Is Learning How to Take Down the Internet

#97
This is (one of) the reason(s) I moved my website to the decentralized web-hosting platform ZeroNet. It is still accessible to regular web users (through the use of proxies) but is ultimately secure against DDOS attacks and the like as there is no single server to attack (it could still be done, but it would take much more effort as you would have to attack each user of ZeroNet individually).

As applicable with all areas of life, association is a security risk. By depending upon any centralized authority (such as a server or domain name registrar) you are open to being censored (either by them or an attacker).

At this point however, decentralized web-hosting solutions still rely upon clearnet centralized port checkers, which is (ofcourse) an issue. The best the community can do is help to raise awareness of decentralized web hosting in the hopes more people will adopt it leading to a higher likelihood that the problems will be solved.

Re: Someone Is Learning How to Take Down the Internet

#98
The Internet is suppose to be decentralized. Yet we have these centralized groups, proving backbone, DNS, certs. Well duh, it's no surprise. Why can't I connect to my neighbor who lives next door without the packet doing a 200 mile trip? The Internet is really only devices that can route packets through at least 2 different gateways. If you only have one route. You are not part of the vision of the Internet.

Re: Someone Is Learning How to Take Down the Internet

#99

Although Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security , I don't think credible sec…

Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information. Yes, I agree the article is vague, and I'd like to learn more. But this is typical for this kind of backchannel intel. From some sources, through some channels, for some kinds of info - this is all you get. This is business as usual. Take it in for what it's worth. It's a signal from a sea of noise, nothing more. M…

> Sometimes it feels as if computer engineers have a unique inability to deal with ambiguous information.

This is a limitation of computers, not the engineers. The engineers are happy to deal with ambiguous information as long as you don't mind ambiguous results.

Re: Someone Is Learning How to Take Down the Internet

#100

The Internet is suppose to be decentralized. Yet we have these centralized groups, proving backbone, DNS, certs. Well duh, it's no surprise. Why can't I connect to my neighbor who lives next door without the packet doing a 200 mile trip? The Internet is really only devices that can route packets through at least 2 different gateways. If you only have one route. You are not part of the vision of the Internet.

[deleted]
Post reply on HN