TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Possible Vendetta Behind the East Coast Web Slowdown

187 pointsby whiskypetersover 8 years ago

21 comments

jerfover 8 years ago
For a long time, I&#x27;ve wondered what would finally be the Securitypocalypse, the thing that finally caused our industry as a whole to take security seriously. These IoT DDoS attacks are as good a candidate as any I&#x27;ve seen in a long time. They are fundamentally very difficult to fix in light of the non-updateability of many of these devices, and this is only the beginning, because the IoT has hardly begun to develop. And in the short-term, I&#x27;m not sure I see any hope, because the forces that make people throw out cheap devices with broken firmwares with no update capability aren&#x27;t going away.<p>If we could somehow mandate that these devices were supported with firmware updates for the indefinite future, that would simply destroy the entire market. And you can&#x27;t do that, because even the devices created by an entity that no longer exists and didn&#x27;t sell its IP to anybody else will eventually be enough to do these DDoSes, if they aren&#x27;t already.
评论 #12764356 未加载
评论 #12764246 未加载
评论 #12764123 未加载
评论 #12764232 未加载
评论 #12765054 未加载
评论 #12764635 未加载
egypturnashover 8 years ago
I am a non-programmer who reads HN and keeps up with tech news in general.<p>And every time I read about the IoT botnet, my immediate response is to look around my apartment at my Internet-connected lights, and wonder if they&#x27;re part of it.<p>How can I find this out?<p>Is anyone making a tool that a non-technical user can run to squint at their network and look for evidence of Mirai, or anything else trying to take advantage of this niche?<p>There are plenty of tools with a reasonably simple interface that will tell me if my laptop&#x2F;desktop computer is infected with something. But what can I use to diagnose the health of all of the <i>other</i> computers proliferating around my house?<p>How can a non-technical user easily monitor the overall health of their connected household? Is this a project anyone is building? Because I think it&#x27;s definitely something that needs to exist now.
评论 #12766752 未加载
评论 #12767602 未加载
评论 #12767388 未加载
评论 #12765185 未加载
评论 #12765305 未加载
评论 #12765196 未加载
评论 #12765271 未加载
评论 #12765190 未加载
gorbachevover 8 years ago
Here&#x27;s a better article from Mr. Krebs:<p><a href="https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2016&#x2F;10&#x2F;ddos-on-dyn-impacts-twitter-spotify-reddit&#x2F;" rel="nofollow">https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2016&#x2F;10&#x2F;ddos-on-dyn-impacts-twit...</a><p>Personally I think his case is pretty convincing.
评论 #12764909 未加载
评论 #12764413 未加载
评论 #12764281 未加载
bcheungover 8 years ago
I know the TTL is set really low for a lot of DNS entries but this recent outage got me wondering if it makes sense for servers further down the chain to hold onto it for longer than the TTL, honor it when they are able to get a new DNS entry within a reasonable amount of time, but fall back to the &quot;expired&quot; version if the authoritative server is not reachable.<p>I&#x27;m wondering what would be the negative consequences of this and if they outweigh the benefit of being more resilient to these types of attacks.
评论 #12764366 未加载
elmigrantoover 8 years ago
No luck with Google DNS for me, but Yandex seems to work:<p><pre><code> 77.88.8.8 77.88.8.1 </code></pre> <a href="https:&#x2F;&#x2F;dns.yandex.ru" rel="nofollow">https:&#x2F;&#x2F;dns.yandex.ru</a>
评论 #12764307 未加载
评论 #12764361 未加载
评论 #12764392 未加载
jpeg_heroover 8 years ago
bloomberg was down for me.<p>I had disabled adblock at their insistence...<p>i re-enabled adblock and I could get the article. hmmmm. maybe something about the 50 unrelated js calls?? perhaps?
inostiaover 8 years ago
More specifics about Mirai bots and their numbers:<p><a href="https:&#x2F;&#x2F;threatpost.com&#x2F;mirai-bots-more-than-double-since-source-code-release&#x2F;121368&#x2F;" rel="nofollow">https:&#x2F;&#x2F;threatpost.com&#x2F;mirai-bots-more-than-double-since-sou...</a>
kakarotover 8 years ago
Unfortunately, forced firmware updating is an area our governments should not be mandating. That puts unnecessary strain on small companies and creates a larger gap that companies must cross to become commercially viable
评论 #12764082 未加载
评论 #12763991 未加载
评论 #12763899 未加载
评论 #12764058 未加载
评论 #12764131 未加载
评论 #12763932 未加载
评论 #12765582 未加载
评论 #12764109 未加载
评论 #12766250 未加载
thestevericheyover 8 years ago
Any evidence this is using the IoT botnet that was reported on earlier this year?
评论 #12763970 未加载
rrggrrover 8 years ago
These attacks are possible because the US Congress hasn&#x27;t extended tort liability to manufacturers of software and network hardware. The full weight of the US products liability bar will quickly and rapidly motivate manufacturers to ship secure devices. The lack of accountability is enabling vulnerability.
评论 #12767293 未加载
davidf18over 8 years ago
The failing here as in many cases such as a number of security breaches was a lack of investment. As someone with an engineering degree that worked as a VLSI design engineer, good engineering requires <i></i>* backup systems <i></i>*. This costs money that people don&#x27;t want to spend. In some cases such as a startup they might be cash short, but many firms have the money but don&#x27;t want to spend it ensuring that they have well engineered software that includes backups, up-to-date software and security upgrades, hiring (expensive) highly competent software engineers and consulting firms.<p>The mistake in this case was relying on one vendor for DNS. Amazon Route 53 would be a good alternate vendor for DNS, for example.
patrickg_zillover 8 years ago
I think even basic home routers these days, have enough cpu power to handle egress filtering.<p>If you have an iot device, by its nature it only needs to connect to a few services and hosts.<p>The manufacturer can provide this in their docs, and give an automatic config url that the router uses to load its egress rules.<p>The rules to load are displayed and the user checks they are legit by comparing to the printed version in the manual, then clicks ok. Or something like that.<p>Rate limits in terms of packets per second, total bandwidth both instantaneous and over time, are set also.
raverbashingover 8 years ago
Not only East Coast, Twitter can&#x27;t be resolved in Ireland&#x2F;UK right now (I assume the mobile app uses some kind of &#x27;dns pinning&#x27; as that is working)
评论 #12764797 未加载
woliveirajrover 8 years ago
I love those comments about IoT and who should be responsible for error-proof products, or ISP monitoring traffic, or ...<p>Internet, in the beginning, was even more insecure. Including the computers and OSes. There were less abuse because few had resources and knowledge. Read some old software and you&#x27;ll find all bad designs in it. Software didn&#x27;t become worst, it&#x27;s just targeted with more knowledge and intensity.
ilakshover 8 years ago
DNS is actually fairly centralized the way it is actually used.<p>We need protocols and systems that are designed to be distributed from the outset.
pc2g4dover 8 years ago
I always thought DNS had enough redundancy built-in that this sort of thing wouldn&#x27;t really have much effect. But here I am unable to access websites, simply because name resolution isn&#x27;t working. If my local DNS server were caching things longer there would largely be no issue.
评论 #12766925 未加载
reacharavindhover 8 years ago
Perhaps a naive question, but Why can&#x27;t a DNS provider identify such participants in a DDOS and ban their IPs forever?
评论 #12765672 未加载
anotherevanover 8 years ago
Did any one else find the style of writing in this article really annoying? Things like using prefacing statements with &quot;so-called&quot; or putting terms in quotes to make them seem suspect.<p>e.g.s:<p>a so-called distributed denial-of-service (DDoS) attack<p>York said Dyn was “actively” dealing with a “third wave” of the attack.
评论 #12766149 未加载
meiraover 8 years ago
Not working, is bloomberg down too?
trendiaover 8 years ago
If you are unable to connect because of DNS problems, switch your DNS server to 8.8.8.8 (Google).<p>Edit: sorry there, this worked for me but apparently it&#x27;s not guaranteed.
评论 #12763877 未加载
评论 #12763963 未加载
评论 #12764822 未加载
评论 #12764053 未加载
评论 #12763992 未加载
评论 #12763918 未加载
评论 #12763966 未加载
nastyasiwannabeover 8 years ago
I&#x27;m suggesting this just so someone more knowledgeable can debunk it. Suppose FBI or someone up there had a meeting and said &quot;in three weeks, there could be millions of armed Americans who believe that democracy was just stolen from them by some evil dictator in a massive globalist conspiracy. These people love twitter. Is there a way to make twitter go down without making it look like we&#x27;re suddenly pulling the plug?&quot; The answer was yes, we&#x27;ll do a test run Friday.
评论 #12764501 未加载
评论 #12764628 未加载
评论 #12766546 未加载
评论 #12764623 未加载