TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Internet Attack Spreads, Disrupting Major Websites

309 pointsby pouwerkerkover 8 years ago

35 comments

mancerayderover 8 years ago
Is it confirmed yet that so-called IoT devices were the bots?<p>Bruce was on point if so, arguing a couple weeks ago that accountability needs to happen on the manufacturers:<p>&quot;What was new about the Krebs attack was both the massive scale and the particular devices the attackers recruited. Instead of using traditional computers for their botnet, they used CCTV cameras, digital video recorders, home routers, and other embedded computers attached to the Internet as part of the Internet of Things.<p>Much has been written about how the IoT is wildly insecure. In fact, the software used to attack Krebs was simple and amateurish. What this attack demonstrates is that the economics of the IoT mean that it will remain insecure unless government steps in to fix the problem. This is a market failure that can&#x27;t get fixed on its own.<p>&quot;<p><a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2016&#x2F;10&#x2F;security_econom_1.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2016&#x2F;10&#x2F;security_econ...</a> (&quot;Security Economics of the Internet of Things&quot;)
评论 #12766573 未加载
评论 #12767188 未加载
csallenover 8 years ago
Schneier wrote about related attacks just over a month ago in a post titled &quot;Someone Is Learning How to Take Down the Internet&quot; (<a href="https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2016&#x2F;09&#x2F;someone_is_lear.html" rel="nofollow">https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2016&#x2F;09&#x2F;someone_is_le...</a>)
评论 #12765883 未加载
评论 #12766299 未加载
评论 #12766253 未加载
gamegodover 8 years ago
Irony alert:<p>&gt; <i>&quot;But technology providers in the United States could suffer blowback. As Dyn fell under recurring attacks on Friday, Mr. York, the chief strategist, said such assaults were the reason so many companies are pushing at least parts of their infrastructure to cloud computing networks, to decentralize their systems and make them harder to attack.&quot;</i><p>Pushing your infrastructure to cloud computing is not decentralization - it&#x27;s centralization, and we&#x27;re all doing it. Imagine if an attack like this was against AWS... we&#x27;d all be screwed.
评论 #12766035 未加载
评论 #12765998 未加载
评论 #12766021 未加载
评论 #12766322 未加载
评论 #12766037 未加载
评论 #12782534 未加载
评论 #12767379 未加载
评论 #12766989 未加载
评论 #12767125 未加载
评论 #12767135 未加载
lifeisstillgoodover 8 years ago
We seem to be needing more concerted action on what is a consumer minimum standard for an internet connected device.<p>Consumer devices have to be <i>more</i> secure because if the low user skill level - and interest.<p>I am always reluctant to say &quot;there should be a law against it&quot; but frankly if we cannot mandate minimum standards of uogradbility and security for devices we will just keep handing over our devices to the first person to scan them.
评论 #12766164 未加载
评论 #12765990 未加载
评论 #12766298 未加载
评论 #12766043 未加载
评论 #12766295 未加载
评论 #12767911 未加载
adamiscool8over 8 years ago
It&#x27;s fashionable to blame Russia these days, but what country manufactures the most IoT devices, and has the type of government that could mandate backdoor access?
评论 #12766247 未加载
评论 #12766215 未加载
评论 #12765991 未加载
评论 #12766025 未加载
tedmistonover 8 years ago
&gt; It is too early to determine who was behind Friday’s attacks, but it is this type of DDoS attack that has election officials concerned. They are worried that an attack could keep citizens from submitting votes.<p>&gt; Thirty-one states and the District of Columbia allow internet voting for overseas military and civilians. Alaska allows any Alaskan citizens to do so.<p>I had no idea any states allowed voting online. I wonder if the general population will ever get access to that.
评论 #12766453 未加载
评论 #12766213 未加载
throw2016over 8 years ago
This seems so out of the blue, the last attack was targeting krebs for exposing extortionists. Who is being attacked this time and why?<p>There is a lot of talk of iot botnets but little to no evidence. This seems too vague and up in the air.<p>If all it takes is script kiddies and random extortionists to generate such large 1 Tbps scale attacks then we appear to be reliant on an unbelievably fragile base.<p>There is a growing realization of the need for more decentralization of services but these kind of attacks is going to drive more centralization if only Google scale companies can manage to stay up. I think this is drop everything and fix time for the IT profession.
评论 #12766344 未加载
dsr12over 8 years ago
Wikileaks tweeted:<p>&quot;Mr. Assange is still alive and WikiLeaks is still publishing. We ask supporters to stop taking down the US internet. You proved your point. &quot;<p>Link: <a href="https:&#x2F;&#x2F;twitter.com&#x2F;wikileaks&#x2F;status&#x2F;789574436219449345" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;wikileaks&#x2F;status&#x2F;789574436219449345</a><p>If their claim is true, does anyone think, it will turn many sympathizers against them? I don&#x27;t think attacking normal bushiness is a good thing to do.
评论 #12767906 未加载
peterwwillisover 8 years ago
So. Can we start talking about changing internet protocols to strengthen the integrity of internet network services against DoS attack?<p>Currently, the internet is very very open (as long as you don&#x27;t live in certain countries). A baby monitor in Kansas can send arbitrary traffic to a router connecting a major financial services company in Hong Kong to an internet backbone. The idea, in a very hippy, world peace kinda way, is nice. But... probably not something we <i>need</i> to happen, much less should <i>want</i> to happen or allow, if good sense prevailed.<p>We have hacks in place that can prevent that particular situation from becoming too much trouble, but if you have enough baby monitors, something somewhere is going to choke. And really this is the point to me: you [as the network service provider] should not have to have carrier-grade infrastructure to avoid this scenario. If Casey Brogrammer wants to prop up a start-up on her DSL line (do people still have DSL?) she should be able to without fear of DoS. How do we do that?<p>I have no idea. But i&#x27;m betting it would require some rearchitecting of the internet and heavily modified protocols. Personally, I think the global BGP tables are gross (and, let&#x27;s face it people, depending on RAM to perpetually increase in size while simultaneously decreasing in cost ad infinitum is not a realistic scaling mechanism), I think the many flaws in modern tcp&#x2F;ip protocols are not designed with specific enough use cases in mind, and that the generalist design of the modern Internet has become more of a hindrance to efficiency and progress than a benefit. There is absolutely no requirement that we keep engineering ourselves into a corner, and IPv6 sure as shit isn&#x27;t going to solve it.
评论 #12782546 未加载
tedmistonover 8 years ago
Extensive commentary on this topic is in the update from Dyn - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12759697" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=12759697</a>
nodesocketover 8 years ago
&quot;And in a troubling development, the attack appears to have relied on hundreds of thousands of internet-connected devices like cameras, baby monitors and home routers that have been infected...&quot;<p>Is that really confirmed or just the reporter writing gossip.
评论 #12768824 未加载
codecamperover 8 years ago
Is this the end of the Internet that news.com predicted back in 1995?
评论 #12766469 未加载
评论 #12766526 未加载
seanharr11over 8 years ago
Harold Martin held without bail (high risk of flight) accused of theft of 20 years worth of government (NSA) tools&#x2F;data, Trump stating he will not concede the election, tens of millions of IoT devices used in DDOS attack, Assange (wikileaks originator) cut off from internet, DNC hacked and exposed.<p>A conspiracy theorists dream.
ThePhysicistover 8 years ago
I wonder why companies affected by these IoT-enabled DDoS attacks don&#x27;t sue the companies building those devices, as they currently often choose security over convenience when it comes to securing them. If you can forensically prove that a large fraction of the attack was carried out using a given type of device it should be possible to hold the manufacturer liable for the damage, at least if no reasonable measures were taken to secure it (using blank or default passwords on the device could count as gross negligence).<p>I even kind of wish that somebody would do this, as it would finally provide a strong incentive for the manufacturers to think about security.
评论 #12768533 未加载
cognivoreover 8 years ago
Kind of makes me wonder - why let up? Can it be mitigated at all? Wouldn&#x27;t they have done so by now. Be interesting if they just kept piling it on until they&#x27;ve got the whole internet on it&#x27;s knees.
评论 #12766303 未加载
Chiraelover 8 years ago
One of the Krebs articles mentioned an idea of a certification (similar to UL) which could be on products like DVRs and web cams. You can&#x27;t ever certify something as completely secure of course, but the certification could indicate &quot;firmware updatable&quot;, &quot;no hard-coded default passwords&quot; and &quot;where there are passwords they are generated randomly and unique to each specific product&quot; (not family of products). Maybe even &quot;consumer can change all passwords to new randomly generated values&quot;. I can&#x27;t say that all or even many consumers will care, but if ISPs stepped up and started emailing customers about suspicious traffic coming from their home networks indicating one or more devices may have been compromised, maybe a good number of consumers <i>would</i> start to look for that certification when they buy. Which is important because, let&#x27;s face it, if insecure products don&#x27;t actually <i>impact sales</i> then a lot of companies aren&#x27;t going to care at all. You can try to punish bad behavior after the fact, but only if their government cooperates and even then I think many times they&#x27;d just fold up shop under one name and open again under another. You really have to address it at the point of purchase to affect company behavior IMO.
评论 #12769262 未加载
ehudlaover 8 years ago
Worth noting that even of stories such as these (new media, tech heavy) coverage by traditional media end up on the home page of HN. Beyond this observation, it seems that this election cycle brought home the importance of journalism for many people.
deepsunover 8 years ago
I wonder, how much electricity do these attacks spend on average? Is it significant for economy?
评论 #12765878 未加载
rms_returnsover 8 years ago
Yet another thing to show us that IoT is a can of worms. Yes, the technology is very helpful, but from security perspective, are we ready for it yet? Why not make existing CCTV cameras and nanny monitors more secure before having IoT?
codecamperover 8 years ago
If these sites hosted with google cloud, would they be less susceptible to ddos attacks?
评论 #12765773 未加载
评论 #12765910 未加载
progmanover 8 years ago
Are there any downloadable DNS lookup tables which could be used as hosts.txt or &#x2F;etc&#x2F;hosts in case of emergency?<p>I know that DNS is organized in root zones with hierarchical subqueries. A global hosts file which contains the whole IP space is sort of unfeasible because domain names change within seconds.<p>However, in face of the current attacks the DNS maintainers should seriously consider to offer downloadable hosts files so that we could use them temporarily to circumvent DNS queries in cases of further attacks.
marmot777over 8 years ago
Would longer, say, week long TTL along with some redundancy have prevented this problem? Can it be done now to prepare for next attack? That is, TTL shortened when making updates, etc., but then set to a week the rest of the time. Here&#x27;s an article that I think could be useful: <a href="https:&#x2F;&#x2F;medium.com&#x2F;@brianarmstrong&#x2F;youre-probably-doing-dns-wrong-like-we-were-6625efaed390#.1xnqip9w1" rel="nofollow">https:&#x2F;&#x2F;medium.com&#x2F;@brianarmstrong&#x2F;youre-probably-doing-dns-...</a>
cervedover 8 years ago
Typical Dark Army
hellogoodbyeeeeover 8 years ago
How long could this go on for?
评论 #12765763 未加载
评论 #12765791 未加载
rmchughover 8 years ago
Wikileaks seem to be claiming the attack for their supporters here: <a href="https:&#x2F;&#x2F;mobile.twitter.com&#x2F;wikileaks&#x2F;status&#x2F;789574436219449345" rel="nofollow">https:&#x2F;&#x2F;mobile.twitter.com&#x2F;wikileaks&#x2F;status&#x2F;7895744362194493...</a><p>Any evidence to support that?
marmot777over 8 years ago
Would longer, say, week long TTL along with some redundancy have prevented this problem? Can it be done now to prepare for next attack? That is, TTL shortened when making updates, etc., but then set to a week the rest of the time?
netcommentatorover 8 years ago
Given national security interests, we need new laws: 1. IOT devices should not ship with default passwords. 2. Internet infrastructure companies should not be allowed to get &quot;too big to fail&quot;.
评论 #12767104 未加载
orthoganolover 8 years ago
WL&#x27;s Twitter has claimed it was WL supporters. Although no one can really confirm what&#x27;s going on with them since the Ecuadorian embassy events the other day.
评论 #12766273 未加载
评论 #12767105 未加载
tedd4uover 8 years ago
Since it&#x27;s impossible to update many permanently-insecure &quot;IoT&quot; devices we may need laws to legalize gov&#x27;t permanently bricking them.
kylelibraover 8 years ago
Can&#x27;t recall ever seeing the NY Times embed tweets in a story, is this a first?<p>edit: apparently it&#x27;s because I mostly read the site within the app.
评论 #12765740 未加载
评论 #12765752 未加载
评论 #12765822 未加载
评论 #12766022 未加载
owaisloneover 8 years ago
or Jen just dropped the internet.
评论 #12765957 未加载
misrabover 8 years ago
could we just move along with ipfs and a distributed web please guys, it&#x27;s about time!
评论 #12766974 未加载
e_e_eover 8 years ago
Brainstorming: We should make DNS mines like for Bitcoins
评论 #12765913 未加载
fowlerpowerover 8 years ago
The U.S. has changed the rules of engagment to state that any cyber attack can be met with real military counterattack.<p>If the Russians are behind it, after being emboldened by Ukraine and Syria, the United States has to respond. I&#x27;m not saying all out war but I am saying we have to show the Russians that this affects everything we are about. It affects our businesses, our elections, and our way of life.<p>I am saying there should be military action and if that leads to war then so be it, everyone will think twice about this sort of thing again and we will all be safer because of it.
评论 #12765967 未加载
评论 #12765946 未加载
评论 #12766129 未加载
评论 #12765975 未加载
评论 #12766277 未加载
评论 #12765963 未加载
codedokodeover 8 years ago
I think the main problem is that the Internet is decentralized. As it has no single owner nobody is responsible for mitigating the attacks and noone wants to pay for developing and implementing new protocols, installing new hardware.
评论 #12767449 未加载