10 ms·
Someone Is Learning How to Take Down the Internet
- akerro 10y agoWhen my Omnia Turris arrives I will connect it with second WiFi card and enable cjdns on it. We need to start showing it.
- goda90 10y agoSince there are lots of hobbies that sometimes overlap with community service I'd love to see a club that focuses on being prepared to reestablish intra-community communication in case the Internet goes down. Yes, it'd be great if everyone was self hosting, using distributed services and involved in a mesh network now, but without motivation it won't happen. So this club could focus on developing the resources that a few individuals in a community could use to set these things up after the network is already down. They could have offline caches of Wikipedia and Openstreetmaps, copies of firmware, apps and instructions for attaching consumer routers and other Wi-Fi devices to a mesh network, systems for registering people with a locally functioning email address, etc. User friendly portals could be made that provide the basic instructions for people who stumble on a mesh network access point with their otherwise disconnected smartphones. All of the tech exists in some form or another, but if it were well packaged, it's not hard to see there being a sufficient distribution of members to get people connected easily.
- norea-armozel 10y agoI'm definitely interested in such an idea. I might have to check around the MPLS area to see who's doing any sort of DIY electronics and other such meetups here.
- kej 10y agoThe amateur radio community already has the technical know-how and disaster readiness to do most of that, and I'd be willing to bet there's enough overlap between them and the meshnet crowd to take care of the rest.
- M_Grey 10y agoA good friend of mine has been into ham radio since he was a young guy, and this is definitely true. In fact a lot of people in that community play a role in plans for a disaster that would knock out other communications, integrated with some local, and state governments. I'm not sure about the federal level, but I'd guess it's integrated there too. And there are a lot of them, and at this point if you're into ham radio, it's for the love and you tend to be pretty proficient.
- justifier 10y agocombined with a project like this: http://icrobotics.co.uk/wiki/index.php/Turning_the_Raspberry_Pi_Into_an_FM_Transmitter http://icrobotics.co.uk/wiki/index.php/Turning_the_Raspberry... and you've basically got the web ;p at least a one way communication network form
- Florin_Andrei 10y agoKG6YHQ here. It's doable, but if the wired net becomes unusable and you have to rely wholly on the RF spectrum, bandwidth would be stupendously tiny. Forget about sending anything else but, basically, text-based messages. Perhaps in an event like that a decision would be made to temporarily open up the spectrum, but even then there are only so many of us, only so many transceivers out there. I feel the HAM net would be more useful after a natural catastrophe, where the infrastructure would be destroyed physically. Which is exactly what a lot of us are preparing for.
- harshreality 10y agoWouldn't SDRs be a lot more useful for creating higher-bandwidth wireless networks in the sort of disaster where the FCC opens up other frequency ranges? The amateur radio regulation regime and common ham radios work well for small numbers of small messages sent around in a well-regulated way, without the government initiating a frequency band jubilee. But beyond that, HAM radios are limited, even if they're modded, and the cheap SDRs are even cheaper than baofeng handhelds, so where does that leave amateur radio in a real frequency free-for-all? I think what would matter is, as mentioned above, availability of SDRs, and secondly, parties of people tracking down transmitters that are messing up the ad-hoc sdr wireless nets.
- matt4077 10y agoThere should be a term for "overprepping for disaster because it's so exciting to think about".
- rexfm 10y ago"Preppers" ?
- 0xdeadbeefbabe 10y agoengineering?
- rabidrat 10y agoYou mean, like this guy? http://www.dailymail.co.uk/news/article-1386978/The-Japanese-mayor-laughed-building-huge-sea-wall--village-left-untouched-tsunami.html http://www.dailymail.co.uk/news/article-1386978/The-Japanese...
- M_Grey 10y agoThe man lived through a tsunami in the area, that was hardly a matter of exciting thoughts, but a desperate desire to prevent a predictable tragedy. By contrast people prepping for the end of days in whatever form, often nuclear, strike me as mad. If there's a nuclear war, I want to be in the hypocenter of the first detonation, because we're not climbing out of that hole as a species in any meaningful way. I suppose that reality is why so many have turned to fantasies of a worldwide EMP of some exotic type which is at least survivable in their imagination. Me? I've read my history, if civilization comes tumbling down, my plan is to eat a gun. Meanwhile I'll live my life without terror, and plan only for disasters that can reasonably be managed without dedicating my limited lifespan to it.
- WilliamDhalgren 10y agoAgreed, if civilization does come tumbling down. However, as far as I could read, for it to survive a nuclear exchange is quite possible, even probable. Blasts themselves seem relatively harmless, beyond the hundereds of millions they just outright kill that is, radiation we're just characteristically paranoid about, but can actually deal with at least in many remaining areas, and the main issue at debate is whether a nuclear winter of substantial duration would be formed or not. Which depends on the scope of the fires, so flammability of urban environments and the like. We can't pretend to know a real answer, but its certainly possible. And then there's the issue of whether the south hemisphere could avoid that fate even in such a case, due to weather patterns, provided there's no detonations there (as there are no weapons there). Now that doesn't seem substantially different from any large-scale warfare civilization easily survived previously, like world war II; urban devastation and millions of dead. Hardly a civilization-ending event.
- rfrank 10y agothings along those lines are already happening in oakland and a number of other cities across the country. https://sudoroom.org/wiki/Mesh https://sudoroom.org/wiki/Mesh
- busterarm 10y agoSeconded. Definitely look into meshnets. There's one in Red Hook (brooklyn) that's been up and running for a long time.
- thinkmassive 10y agoI recently discovered a startup called Endless that appears to be working on the content/caching side of this problem. They're for-profit but seem to have good intentions between releasing their OS as open source and creating affordable hardware targeted at emerging markets. https://endlessm.com/ https://endlessm.com/
- jcl 10y agoThere are educational projects that focus on providing the benefits of the internet to communities that have poor or no connectivity, like: http://internet-in-a-box.org/ http://internet-in-a-box.org/ While internet failure mitigation isn't an explicit goal of such projects, their resources might make a good starting point.
- davidhyde 10y agoThis guy in Spain created his own internet infrastructure: https://backchannel.com/forget-comcast-heres-the-diy-approach-to-internet-access-ef1e37bc09e1#.z2xn9wg57 https://backchannel.com/forget-comcast-heres-the-diy-approac... It's been running successfully for years and has grown quite a bit.
- asclepi 10y agoSo how exactly is one entity, even a state entity, going to take down all 13 root servers, assuming that that is what Schneier is talking about since the man speaks in mysteries? What would it take to do that? Let's safely assume that these servers, every single one of them, are subject to DDoS attacks all the time and have at least some experience in handling them, and have a backup scenario ready for a serious attack. One of the reasons why the root servers are not centralized is to avoid the kind of disaster that Schneier predicts. Also what if I maintain a list of IP addresses of the websites I visit most and update that list daily. When the "big attack" strikes, I put that list in /etc/hosts. Would I still be able to do my holiday shopping from Amazon? Would I still be able to read the logs on my VPS by ssh'ing to its IP? How long would such an attack sustain before BGP modifications start blackholing the sources? Long enough to let the average TTL cache expire? Would an attack on the root servers really take down the internet? Or in case Schneier isn't talking about that, what kind of attack on the decentralized internet is actually able to take it all down? I'm not saying he is wrong, but I have a hard time thinking about how we should prepare and protect our infrastructure if he doesn't want to share the intel he knows instead of some generic warnings.
- wtracy 10y agoJust a little heads-up, your account appears to have been shadowbanned.
- rl3 10y agoThat post is publicly visible to me. It also seems to be the first post for the account, and is fairly substantive. Moreover, I don't think it's even possible to reply to posts made from shadowbanned accounts.
- wtracy 10y agoOkay then. I didn't look at the poster's history, I just saw a constructive-looking comment that seemed to be modded to oblivion, and jumped to conclusions. I had to vouch for the post before HN would let me reply, which seems consistent with how shadowbanned accounts are handled here.
- norea-armozel 10y agoThis is why I worry about the centralization of all communications as we've done over the entirety of human history. Letting the Internet be centralized as it has been might be make economic sense but as for sustaining the world economy through a potentially global conflict it doesn't make any sense to put all our eggs in one basket here. It's like I mentioned on the "napalm girl" post that we've become too complacent with having ease of use trump reliability of communication. This is just one of the larger consequences of our individual and collective choices coming to bite us in the butt. I hope this spurs people to get smarter and put together p2p solutions that can weather such a conflict at least for regional and/or city-wide communications.
- Grishnakh 10y agoThe internet is decentralized, for the most part; it was designed to be that way from the start. Whole pieces of the internet can go offline that the rest of it will continue operating as normal, with packets routed around the damage. The TCP and IP protocols were designed for this. It's not the designers fault that so many people are dumb enough to happily give one company a near-monopoly over certain forms of communication. It's very simple: stop using Facebook for everything. Use different sites/services, or switch to a decentralized service like Diaspora. Otherwise, stick with Facebook for everything and stop complaining when it bites you in the butt, and suffer the consequences when disaster strikes.
- norea-armozel 10y agoYou're confusing the issue by focusing on protocols versus actual physical implementations (data centers, trunk lines, etc). The physical installations for what we call the Internet are centralized. Companies like Level 3 might put some redundancy but at some point the cost of redundancy out weighs its benefits for them and other companies like them. This is especially true of consumer financial services like banking. If an attacker wanted to disrupt the United States they only have to do it to banking to cause a panic. They could easily ignore emergency services, hospitals, and even the government itself (outside of ACH) while doing this. And it would be such a mess that we couldn't resolve it immediately. The happiest outcome is the disruption is only for a few hours but the more likely outcome is possibly days or weeks of disruption where a large part of the banking system would be inoperable. It doesn't matter if you used TCP/IP or switch based communications the outcome is the same: the American economy shaken and possibly worse. So, we can take all day about Facebook and Diaspora but neither of those services do anything important for the average user like your bank which also uses the same centralized infrastructure. There is no Diaspora for banking and not one that's widely used or not using the current banking/financial transfer systems which are centralized.
- phantom_oracle 10y agoBlaming China or Russia is lazy writing. It could be just about anyone, including a rogue internal agency doing a spoof-attack to precisely cause the blame to go towards the obvious "state actors". Cyber-warfare is the 'new' war and just like any war, misinformation plays an important role.
- m0nty 10y ago> Blaming China or Russia is lazy writing It's what the author is being told by the people he has spoken too. Maybe a lazy assumption on their part, but it's not lazy writing. And your point is directly addressed in TFA: "The data I see suggests China, an assessment shared by the people I spoke with. On the other hand, it's possible to disguise the country of origin for these sorts of attacks." It would be interesting to know the sort of resources needed for this kind of attack/probing. Is it limited to state actors, or could we all play? Is the objective simply to be prepared, or is there a plan afoot?
- AnimalMuppet 10y ago> Is it limited to state actors, or could we all play? Per the article, no, we can't all play. We don't have either the bandwidth or the expertise.
- m0nty 10y ago> Per the article Not quite, it says "If the attacker has a bigger fire hose of data than the defender has, the attacker wins" and "the size and scale of these probes—and especially their persistence—points to state actors" which is not quite the same as saying you need to own the bandwidth. For example, DNS amplification can be used "to turn initially small queries into much larger payloads, which are used to bring down the victim’s servers". https://www.incapsula.com/ddos/attack-glossary/dns-amplification.html https://www.incapsula.com/ddos/attack-glossary/dns-amplifica... So maybe there are other techniques which might allow for similar leverage. Neither is the article conclusive about "state actors", they are merely "pointed to". As for expertise ... I don't doubt there are people out there who have it or might acquire it. So it's still an interesting question imo.
- linkregister 10y agoAlthough Schneier is probably correct in this instance, one of the most exasperating features of his computer security writing is an utter lack of citations or evidence to back up his claims. (His writing about cryptography should require no citations because he is an actual crypto expert.) After the significant inaccuracies and frequent unsubstantiated speculation in Schneier on Security, I don't think credible security researchers can take his analysis at face value. Additionally, the halo effect of his actual expertise, cryptography, convinces people who aren't security experts that his opinions and speculations are correct. Worse, he rarely frames his speculation as such; he states conjecture as fact. This is counterproductive and leads to confusion among journalists and eventually the general public. To the imminent downvoters, I'm not offended; I expect it with an unpopular opinion. I'd prefer you engage with a reply in addition to the downvote so we can have a discourse. I think it's important that I add my dissent to the conversation.
- tptacek 10y agoHis writing about cryptography certainly should include citations.
- linkregister 10y agoIt might sound blasphemous but I (as a non-expert in crypto) would be satisfied if either you or Bruce didn't cite their writing about crypto. Yes, appeal to authority and all that, but I don't have time to fully learn a field to find out if a cryptographer is mistaken. Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in.
- AnimalMuppet 10y agoThat works for you, but on the subject of security, tptacek is on a different level than most of the rest of us. It's perfectly valid for him to say that he wants to see Schneier's references, and for you to say that you will take it on trust from either of them. > Also, the point I was making is that if he wants to leave work uncited, it should at least be the work he has actual credibility in. A totally valid point. Way too often, people smuggle credibility from an area where they have expertise (and therefore deserve the credibility) to areas where they don't. In this case, though, the real credibility is Schneier's honesty, not his expertise, since he's passing on (obscured) reports from others.
- m-jones 10y agoThis is (one of) the reason(s) I moved my website to the decentralized web-hosting platform ZeroNet. It is still accessible to regular web users (through the use of proxies) but is ultimately secure against DDOS attacks and the like as there is no single server to attack (it could still be done, but it would take much more effort as you would have to attack each user of ZeroNet individually). As applicable with all areas of life, association is a security risk. By depending upon any centralized authority (such as a server or domain name registrar) you are open to being censored (either by them or an attacker). At this point however, decentralized web-hosting solutions still rely upon clearnet centralized port checkers, which is (ofcourse) an issue. The best the community can do is help to raise awareness of decentralized web hosting in the hopes more people will adopt it leading to a higher likelihood that the problems will be solved.
- segmondy 10y agoThe Internet is suppose to be decentralized. Yet we have these centralized groups, proving backbone, DNS, certs. Well duh, it's no surprise. Why can't I connect to my neighbor who lives next door without the packet doing a 200 mile trip? The Internet is really only devices that can route packets through at least 2 different gateways. If you only have one route. You are not part of the vision of the Internet.
- deleted 10y ago[deleted]
- evgen 10y agoYou can make such a connection and establish a mesh network, most people are just too lazy or technically unsophisticated to pull it off apparently. Centralization is a consequence of that fact that people do not actually want to maintain their own infrastructure, they just want it to work while they get back to the rest of their life.
- chmike 10y agoI totally disagree that we can't do anything. With the existing TCP/IP protocol we can't do anything because it's possible to forge the origin IP address or modify the datagram content on its route to destination. A receiving end has no way to verify the validity of the datagram. An IP datagram authentication at the lowest level is required so that anyone on the route can detect forgery, error or tempering with the data. This would allow tracking the real sources of DDOS attack, diagnose the cause and fix it. What's the point of keeping digging deeper trenches ? This should be a top priority change of the Internet. There was no incentive to move to IPv6. Now there is one to move to a more secure Internet.
- pjc50 10y ago> top priority change of the Internet See you in thirty years. Also, IP authentication doesn't help you. DDOS traffic often has real IP source addresses on. It tells you that the traffic is several hundred thousand home PCs. Now what?
- mhandley 10y agoIf you knew for sure that an IP src address involved in a DDoS attack was not spoofed, we could easily design a control protocol that allowed a recipient to contact the origin ISP and enable a block on that particular {src,dst} pair. Unless you know for sure that the src address isn't spoofed though, such a mechanism would itself be abused to deny service. Having the ability to validate a source address would be the enabler for proper defense mechanisms. We wrote about one way to do this about ten years ago, but no-one was really interested at the time: http://www0.cs.ucl.ac.uk/staff/M.Handley/papers/terminus2007.pdf http://www0.cs.ucl.ac.uk/staff/M.Handley/papers/terminus2007...
- oarsinsync 10y ago> Unless you know for sure that the src address isn't spoofed though, such a mechanism would itself be abused to deny service. Unfortunately, even if you know that the source address isn't spoofed, such a mechanism would itself be abused to deny service
- gpvos 10y ago>The NSA, which has more surveillance in the Internet backbone than everyone else combined, probably has a better idea, but unless the U.S. decides to make an international incident over this, we won't see any attribution. Or unless it's the US itself. Not the most likely possibility I think, but still a possibility.
- M_Grey 10y agoThis is both unsurprising, and worrying. Unsurprising because it's the job of any nation's military and espionage arms to consider and form plans to cripple or destroy their potential enemy's infrastructure, information included. Worrying, because as far as I can tell most people remain deeply ignorant and/or unconcerned (present company excluded both from that remark, and realistically the descriptor "most people") about 'cybersecurity' in any form. That needs to change, and the author is right that while there seems to be little to do now, people should be aware of it.
- grokas 10y ago'the author' (Bruce Schneier) is right a lot.
- M_Grey 10y agoHe certainly is, although too often I wish that wasn't the case. For instance, right now I wish that very much!
- increment_i 10y agoHe suspects China or Russia as the likely culprit. What exactly rules out an American agent? Is it because American economic and social activity rely disproportionately on internet backbones more so than other state actors? If so, that would be especially interesting.
- WorldMaker 10y agoOr vice versa? The internet relies disproportionately enough on American backbones/services that an American agency doesn't need to probe because it already has the keys, or at least the power switch?
- exolymph 10y agoIt would be profoundly stupid for the American government to take down the internet under normal circumstances, but then against it would be equally stupid for China or Russia to do it (again, under normal circumstances). But developing the capability seems like a good idea of the face of it. That said, Schneier obviously has more information than he's currently sharing.
- angrydev 10y agoCan anyone elaborate on what he means when he says that Verisign can 'go down' and take down most of the internet with it? How would a registrar going down affect anything to do with actual hosts?
- falcolas 10y agoIf Verisign is running the nameservers for .com and .net, it will cause DNS problems across the board. We'd have to rely on DNS caches until new .net and .com nameservers come up. This would impact not only new domain registrations, but DR grade migrations, and DNSSEC. If coordinated with an attack against the root nameservers so we couldn't change the .com and .net nameservers, DNS would become a real disaster. If combined with some BGP trickery, you could even see domain names being poisoned. We should be able to be worked around the damage eventually; but so much of the internet relies on so few root servers/hosts/routers.
- reitoei 10y agoWould there a use case for decentralizing DNS into blockchain, or for creating an alternative?
- cwkoss 10y agoThis is one of the goals of Namecoin, but I'm not sure how successful they've been so far.
- deleted 10y ago[deleted]
- duaneb 10y agoFor some reasons to use DNS (e.g. service discovery) the latency associated with a blockchain would be prohibitive. Generally, I think it's an excellent application.
- falcolas 10y agoI think the problem with the blockchain is that it is relatively immutable, while the internet is anything but. Also, the cost for making a Namecoin change is inexpensive now, but if it were to take over full operations for even one TLD, that would not remain the case.
- sgnelson 10y agoMakes me wonder if we'll ever see a "hot" war that starts off as a "cyber" war.
- AnimalMuppet 10y agoIf you see a hot war, under current circumstances it will almost certainly be preceded (if only for a few minutes) by a full-on cyber attack.
- Bartweiss 10y agoIt's an interesting arrangement. Launching a cyber war for its own sake might or might not escalate to a hot conflict, but a hot conflict would almost certainly be backed by the cyber version.
- a3n 10y agoSo in addition to debating launch on warning, we now have to think about launch on DDoS.
- knappe 10y agoThis has already happened. https://en.wikipedia.org/wiki/Cyberattacks_during_the_Russo-Georgian_War https://en.wikipedia.org/wiki/Cyberattacks_during_the_Russo-...
- Zigurd 10y agoThe start of every US war in the ME has featured attacks on communication and infrastructure, starting with hacking in to the telephone exchanges weeks or months before the hot war starts, and culminating with the takedown of critical physical infrastructure, like power, water, etc. as the first thing to go when the shooting starts.
- linkregister 10y agoCan you clarify this? I remember seeing some articles about this tactic in maybe 2010, but nothing before then. I recall the Gulf War and OIF/OEF infrastructure damage being primarily from aerial bombing, but it's possible I missed the articles about the hacking element. I'm not doing the snarky "citations pls" thing; I don't dispute it happened. I just want to know more.