13 ms·
Internet Attack Spreads, Disrupting Major Websites
- e_e_e 10y agoBrainstorming: We should make DNS mines like for Bitcoins
- h4nkoslo 10y agohttps://en.wikipedia.org/wiki/Namecoin https://en.wikipedia.org/wiki/Namecoin
- fowlerpower 10y agoThe U.S. has changed the rules of engagment to state that any cyber attack can be met with real military counterattack. If the Russians are behind it, after being emboldened by Ukraine and Syria, the United States has to respond. I'm not saying all out war but I am saying we have to show the Russians that this affects everything we are about. It affects our businesses, our elections, and our way of life. I am saying there should be military action and if that leads to war then so be it, everyone will think twice about this sort of thing again and we will all be safer because of it.
- drdrey 10y ago> if that leads to war then so be it Well gee, slow down there buddy
- JohnStrange 10y agoThat's a great way into a nuclear holocaust, and I appreciate it. I always wanted to test my prepper skills, although I have to admit that I'm not really a prepper, more like a guy who makes fun of them, and don't even own a Geiger counter (because the good ones are fucking expensive).
- carbocation 10y ago> I am saying there should be military action and if that leads to war then so be it I don't think that war with any nation, much less Russia, should ever be such a casual consideration. Measured in human suffering, military conflict is inestimably more awful than brief internet downtime.
- fowlerpower 10y agoOf course I agree with you but it's not about the internet downtime. It's about messing with or elections it's about the invasions. You let it all go on long enough and you will have much bigger problems in a few years time.
- whybroke 10y agoYour point is completely accurate and critical to follow up on in a considered way. In the real world anyway. But unfortunately, since Thiel has invited HN to go full /pol/ the answer you're gonna get is that it's a 400lb guy on a couch saving us from the devil.
- j1vms 10y agoI disagree. A cyberattack that were a short/medium-term risk to lives being the exception to this. But a cyberattack that plausibly affects at most the economy (and a fraction of it at best), if it be so proved, should be responded in a way that affects an economy or the like. The world, as it is, already has enough human lives being ended each day or put at risk for what are often tenuous reasons at best.
- codedokode 10y agoWould not disconnecting a cable from Russia or installing a firewall be a cheaper solution?
- Jerry2 10y agoTheir next move would be disconnecting the US. http://www.hisutton.com/Yantar.html http://www.hisutton.com/Yantar.html What then?
- codedokode 10y agoI remember reading the same about american submarines installing unknown devices on underwater cables.
- Jerry2 10y agoYeah, they both do it. US has been doing it for decades, however. https://en.wikipedia.org/wiki/Operation_Ivy_Bells https://en.wikipedia.org/wiki/Operation_Ivy_Bells
- rohit89 10y ago> everyone will think twice about this sort of thing again and we will all be safer because of it. Sure. Respond to an cyber attack on infra by starting a physical war that will permanently remove all infrastructure. Its the equivalent of burning down your building because a neighbor cut your cable. War should always be a last resort - only when all other options are exhausted. Especially nuclear war.
- gamegod 10y agoIrony alert: > "But technology providers in the United States could suffer blowback. As Dyn fell under recurring attacks on Friday, Mr. York, the chief strategist, said such assaults were the reason so many companies are pushing at least parts of their infrastructure to cloud computing networks, to decentralize their systems and make them harder to attack." Pushing your infrastructure to cloud computing is not decentralization - it's centralization, and we're all doing it. Imagine if an attack like this was against AWS... we'd all be screwed.
- Symbiote 10y agoYou're correct, it's centralisation, at least for the whole community. It decentralises that one company's DNS -- instead of having one or two DNS servers, perhaps at two sites, they now have 20, at 20 sites. If someone wants to target them, they're probably better protected. But it's the same 20 servers as a million other companies, so the chance of those servers being a target is much greater.
- gamegod 10y ago> But it's the same 20 servers as a million other companies, so the chance of those servers being a target is much greater. Yeah, that's what I was getting at. I feel like my chances of being collateral damage on an attack against someone else is way higher in the cloud. Even today with GitHub and other SaaS platforms going down, we were all affected.
- smegger001 10y agoThe cloud can be more decentralized but it more expensive, Done properly having redundancy across multiple clouds aws, rackspace, google, azure, in geographically different areas with different internet service providers it can be done in a very distributed decentralized fashion, just no one actaully does that. Instead they throw everything on one provider and pray its is backed up and secured by that cloud provider better than the IT guy down the hall they just laid off.
- paulddraper 10y ago
- fowlerpower 10y agoWhy? Let them invade another country, let them hack our infrastructure next such as our water supply? You think letting it go or doing nothing is the answer? This guy Putin is no different than Hitler, let him do this sort of thing and you will have much bigger problems in a couple of years.
- palunon 10y agoThis guy Putin has nukes. Lots of them.
- fowlerpower 10y agoThat's a mute point. We do too. Do you not think Hitler scared the whole world? If you let this guy scare you into inaction then he's already won.
- duaneb 10y agoAt the same time, declaring unilateral war against hitler would have been stupid.
- fowlerpower 10y agoReally? Right after he hit Poland? That would have been the smartest move the world could have done and you would have had much less bloodshed than you did. You would have prevented the holocaust prevented the destruction of most of Europe. But you keep telling yourself that.
- duaneb 10y agoThis is so much easier to say if you're not a historian. "What if" scenarios are invaluable. You might as well say we should have killed him. Easier said than done!
- 10y ago
- adamiscool8 10y agoIt's fashionable to blame Russia these days, but what country manufactures the most IoT devices, and has the type of government that could mandate backdoor access?
- dimino 10y agoWho is... China?
- deleted 10y ago[deleted]
- tptacek 10y agoWhat "backdoor access" are you talking about? These botnets spread via static admin passwords.
- danieltillett 10y agoI think what the OP is implying is that these static admin passwords were put as a deniable backdoor. If it was a Chinese gov scheme it is quite clever as a real backdoor would have been obvious, while this just looks like total incompetence.
- tptacek 10y agoThis makes no sense. Everyone knows what the default passwords are. And all sorts of products not made in China have default passwords. And, some of the products implicated in these attacks aren't Chinese. I think the OP is grasping at straws.
- adamiscool8 10y agoI was thinking of the hardcoded passwords in Xiongmai Tech components that were linked to the Krebs DDOS. Very much in line with the rumors about Huawei and ZTE a few years back, I don't think it's out of the realm of possibility. Hard to define a motive though.
- throw2016 10y agoThis seems so out of the blue, the last attack was targeting krebs for exposing extortionists. Who is being attacked this time and why? There is a lot of talk of iot botnets but little to no evidence. This seems too vague and up in the air. If all it takes is script kiddies and random extortionists to generate such large 1 Tbps scale attacks then we appear to be reliant on an unbelievably fragile base. There is a growing realization of the need for more decentralization of services but these kind of attacks is going to drive more centralization if only Google scale companies can manage to stay up. I think this is drop everything and fix time for the IT profession.
- cdvonstinkpot 10y agohttps://news.ycombinator.com/item?id=12763501 https://news.ycombinator.com/item?id=12763501
- orthoganol 10y agoWL's Twitter has claimed it was WL supporters. Although no one can really confirm what's going on with them since the Ecuadorian embassy events the other day.
- rconti 10y agoI have no idea what that stands for. I've exhausted a Google search and 30 seconds of memory probing for recent events/people/places/governments that match "WL".
- sehr 10y agowikileaks
- cdvonstinkpot 10y agoWikiLeaks I think
- Renaud 10y agoMaybe WikiLeaks?
- deleted 10y ago[deleted]
- phereford 10y agoI _think_ WL == WikiLeaks.
- rconti 10y agoThanks everyone. I don't know how I wasn't able to come up with it given the reference to the Ecuadoran embassy.
- breakfastpizza 10y agoWikiLeaks
- deleted 10y ago[deleted]
- cognivore 10y agoKind of makes me wonder - why let up? Can it be mitigated at all? Wouldn't they have done so by now. Be interesting if they just kept piling it on until they've got the whole internet on it's knees.
- nodesocket 10y agoWell because a lot of the companies that went down today, addressed the problem by now running a blend of different dns providers.
- cognivore 10y agoBut it hasn't really dropped off since earlier today.
- misrab 10y agocould we just move along with ipfs and a distributed web please guys, it's about time!
- woodandsteel 10y agoI agree. From what I understand, ipfs is designed to solve this problem (and several others). Maybe this will motivate the big actors to look into it seriously. Anybody disagree?
- niftich 10y agoI love IPFS but how exactly does IPFS/IPNS solve the DDOS problem? The FAQ entry on this is not very convincing [1]. [1] https://github.com/ipfs/faq/issues/171 https://github.com/ipfs/faq/issues/171
- mancerayder 10y agoIs it confirmed yet that so-called IoT devices were the bots? Bruce was on point if so, arguing a couple weeks ago that accountability needs to happen on the manufacturers: "What was new about the Krebs attack was both the massive scale and the particular devices the attackers recruited. Instead of using traditional computers for their botnet, they used CCTV cameras, digital video recorders, home routers, and other embedded computers attached to the Internet as part of the Internet of Things. Much has been written about how the IoT is wildly insecure. In fact, the software used to attack Krebs was simple and amateurish. What this attack demonstrates is that the economics of the IoT mean that it will remain insecure unless government steps in to fix the problem. This is a market failure that can't get fixed on its own. " https://www.schneier.com/blog/archives/2016/10/security_econom_1.html https://www.schneier.com/blog/archives/2016/10/security_econ... ("Security Economics of the Internet of Things")
- rayuela 10y agoI feel like I hadn't thought of this as a market failure until reading your post calling it that. You're absolutely right about it. That's exactly what it is and the need for government involvement is quite obvious now. Suppliers are going to need to be held liable for the negative externalities their product offerings create, otherwise we're stuck at an equilibrium point where this situation does not improve.
- exolymph 10y agoYup, it's a classic externality.
- Splines 10y agoIf ISPs were treated like a utility and charged per bit, customers would have an incentive to ensure that their devices weren't dumping traffic onto the internet. It's rare that you can see a dashboard showing your usage, even rarer to see a dashboard showing your usage, broken down by device.
- tyre 10y ago
- codedokode 10y agoI think the main problem is that the Internet is decentralized. As it has no single owner nobody is responsible for mitigating the attacks and noone wants to pay for developing and implementing new protocols, installing new hardware.
- Falkon1313 10y agoMore the opposite, because it's too centralized, an attack can take out the few 'authority' servers and knock off everything downstream.
- nodesocket 10y ago"And in a troubling development, the attack appears to have relied on hundreds of thousands of internet-connected devices like cameras, baby monitors and home routers that have been infected..." Is that really confirmed or just the reporter writing gossip.
- tyingq 10y agohttps://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powered-todays-massive-internet-outage/ https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe... According to researchers at security firm Flashpoint, today’s attack was launched at least in part by a Mirai-based botnet. Seems in-between. Not confirmed, but not just conjecture either.
- netcommentator 10y agoGiven national security interests, we need new laws: 1. IOT devices should not ship with default passwords. 2. Internet infrastructure companies should not be allowed to get "too big to fail".
- cderwin 10y agoAs far as (2) goes, they actually need to be too big too fail. Otherwise, it's plainly impossible for internet infrastructure companies to be able to financially weather ddos attacks like this. These sorts of attacks are very expensive to mitigate, and part of the way we can do that is to centralize under services like AWS and collectively pay for ddos protection (short of the government doing so and separating our network from those of major malicious foreign actors').
- hellogoodbyeeee 10y agoHow long could this go on for?
- cryptoz 10y agoThis particular attack will likely eventually be mitigated (hours? days?). But it seems there is nothing preventing similar attacks from starting at any time, and be less possible to prevent each time. Personally, I fear we are closer to global-scale, machine-learning-based attacks that find vulnerabilities, exploit them, and change patterns on the fly. We may not have a stable internet any more. Am I blindly fearmongering? I hope not. But these are new waters. Insecure IoT is growing every hour and there's no clear path to stop it from being exploited more and more.
- leephillips 10y agoTrying to fight a war purely with defense is usually a dangerous strategy. The only long-term solution is to find the attackers and take them out.
- tunesmith 10y agoThat's irony, right? I can't even tell anymore.
- gtirloni 10y agoMicrosoft has had an active role in taking down botnets. https://krebsonsecurity.com/2012/03/microsoft-takes-down-dozens-of-zeus-spyeye-botnets/ https://krebsonsecurity.com/2012/03/microsoft-takes-down-doz...
- mancerayder 10y ago"War is peace. Freedom is slavery. Ignorance is strength."?
- sosuke 10y agoI do remember something about a virus that patched the computers it infected. White hat virus!
- kylelibra 10y agoCan't recall ever seeing the NY Times embed tweets in a story, is this a first? edit: apparently it's because I mostly read the site within the app.
- thomasthomas 10y agowhy i think adding an edit feature to twitter is thorny issue
- jlebar 10y agoNo, they do it all the time, especially for politically-related stories.
- augustt 10y agoThey've done it before, especially for trump: http://www.nytimes.com/2016/10/21/us/politics/trump-apprentice-emmy.html http://www.nytimes.com/2016/10/21/us/politics/trump-apprenti...
- tedmiston 10y agoI wonder if the embeds break when a tweet gets deleted. That was always one of my biggest concerns when using them: that someone else can change / break your article in the future.
- danso 10y agoThe embeds resolve to plaintext when a tweet is deleted. In fact, the standard embed code includes the Tweet text in plaintext, so that at least the content is preserved
- tedmiston 10y agoExtensive commentary on this topic is in the update from Dyn - https://news.ycombinator.com/item?id=12759697 https://news.ycombinator.com/item?id=12759697
- codecamper 10y agoIf these sites hosted with google cloud, would they be less susceptible to ddos attacks?
- deleted 10y ago[deleted]
- atishay811 10y agoThis attack is on the DNS and niṛ in the sites themselves. The sites are working fine. We need better infrastructure for the internet.
- palunon 10y agoGoogle cloud can host your DNS zones for you.
- lucaspiller 10y agoThat's also true of AWS, Digital Ocean, Linode, etc. Hell, you can even host your DNS yourself!
- cerved 10y agoTypical Dark Army
- codecamper 10y agoIs this the end of the Internet that news.com predicted back in 1995?
- djsumdog 10y agoAre you talking about this Newsweek article? http://www.newsweek.com/clifford-stoll-why-web-wont-be-nirvana-185306 http://www.newsweek.com/clifford-stoll-why-web-wont-be-nirva...
- pyre 10y agoLooks like that author has continued down the path of that line of though though, if you look at the books listed on his Wikipedia page: https://en.wikipedia.org/wiki/Clifford_Stoll#Books https://en.wikipedia.org/wiki/Clifford_Stoll#Books
- codecamper 10y agoI just remember seeing this article on news.com cira 1995 that predicted the imminent demise of the Internet due to the commercialization of it. It worried that the net just couldn't handle all the traffic from all those 56k dialup hitting and getting email all at once. So my comment was a bit on the ironic / goofy side.
- tbihl 10y agoI have no doubt we'll see the end of the global internet in the next couple decades, but it's going to take quite a few more of these before we get there.
- lifeisstillgood 10y agoWe seem to be needing more concerted action on what is a consumer minimum standard for an internet connected device. Consumer devices have to be more secure because if the low user skill level - and interest. I am always reluctant to say "there should be a law against it" but frankly if we cannot mandate minimum standards of uogradbility and security for devices we will just keep handing over our devices to the first person to scan them.
- tapoxi 10y agoIt's controversial, but I kind of agree. You need FCC approval to broadcast a radio signal due to the risk of interfering with other traffic, and you should have FCC approval that your IOT device meets minimum security standards before being sold.
- dwheeler 10y agoIt may be controversial, but I think there ought to be a law. Some ideas: http://www.dwheeler.com/essays/law-security.html http://www.dwheeler.com/essays/law-security.html
- ozaark 10y agoIf only there were an app for consumers to securely scan their own network for unspoken traffic in these connected devices. The amount of consumer IoT currently connected with default and often outdated device settings is beyond belief.
- mjevans 10y agoOr you need to make it easier for the 'black hole' solution to be pushed further and further back to the sources of the bad traffic. A remote site shouldn't be able to get you banned from the Internet (by it's self); but it MUST be able to say, "This host is being abusive, restrain them from sending me data". ISPs SHOULD use that information to evaluate if a host from their network might be compromised or otherwise a negative player. ISPs SHOULD also take steps to inform, and link to educational resources, customers which are being bad citizens of the Internet. ISPs SHOULD also be financially motivated (punishments to them) for allowing too many uncivil customers online; this might take the form of instead banning that ISP from the Internet as a whole.
- csallen 10y agoSchneier wrote about related attacks just over a month ago in a post titled "Someone Is Learning How to Take Down the Internet" (https://www.schneier.com/blog/archives/2016/09/someone_is_lear.html https://www.schneier.com/blog/archives/2016/09/someone_is_le...)
- msane 10y agoHopefully it's not related threats about hacking during the election. Remember that recently Biden openly threatened cyber attack on Russia if they make any attempt to tamper with the election. Which is completely unprecedented, as is the notion that DOD is openly saying Russia was behind DNC and other attacks.
- cm2187 10y agoAlso what amazed me is that he would casually threaten to strike Russia. It seems that no one considers these attacks as an act of war. But that's what they are.
- meowface 10y agoIt's espionage, not necessarily an act of war. The US government is threatening to strike back with more espionage. (If they haven't already...)
- cm2187 10y agoEspionage is stealing data. Disrupting utility services is an act of war, whether it is shutting down an electricity power plant, cutting communications, or any other act of sabotage.
- rfrank 10y agoWhat about say, stealing a map of secret military installations? Can stealing certain pieces of data be considered an act of war?
- owaislone 10y agoor Jen just dropped the internet.
- cyberferret 10y agoLOL - I just re-watched that episode last night, as it turns out. Hilarious. The Elders of the internet will be miffed!
- tedmiston 10y ago> It is too early to determine who was behind Friday’s attacks, but it is this type of DDoS attack that has election officials concerned. They are worried that an attack could keep citizens from submitting votes. > Thirty-one states and the District of Columbia allow internet voting for overseas military and civilians. Alaska allows any Alaskan citizens to do so. I had no idea any states allowed voting online. I wonder if the general population will ever get access to that.
- tptacek 10y agoMany of us in the industry hope not.
- djsumdog 10y agoIf they're absent T ballots, they're not counted until several weeks later (unless the total amount of absent T ballots is larger than the margin between any candidate to ballot measure).
- combatentropy 10y agoWhat does the T stand for?
- speedplane 10y agoHillary. Oh no, voter fraud!
- function_seven 10y ago"Absent T" Is this a reference I'm not getting, a speech-to-text error, or a simple misspelling of "absentee"?
- matt4077 10y ago"absentee" – for those grasping for meaning in a sea of autocrat.
- deepsun 10y agoI wonder, how much electricity do these attacks spend on average? Is it significant for economy?
- laurentdc 10y agoI don't think so. Modern botnets are mostly made of devices that are operating 24/7 already, such as compromised IP cameras, set top boxes, SOHO routers, IoT devices, etc. The energy spent for TCP/IP stack usage is negligible at best, even when pushing those embedded CPUs to 100%.
- msane 10y ago> The energy spent for TCP/IP stack usage is negligible at best. Not true, especially en masse. Even less true for wirelessly connected devices.
- laurentdc 10y agoHm, in my experience the difference between idle and 100% CPU usage on a modern ARM processor (e.g. Allwinner H3) is around 1 Watt. That's more or less what an LCD monitor in standby draws. I wouldn't call that significant (as in, impacting the global energy consumption significantly) even if thousands of devices started the attack at the same time.
- drvdevd 10y agoWould you call that detectable? Eespecially en masse. Perhaps a smart grid could detect these attacks in some way and dynamically adjust power to compromised devices?
- mjevans 10y agoI wouldn't. The signal ratio to noise very likely just isn't there. Remember, people regularly operate toaster ovens, microwaves, hairdryers, etc on a fluxuating basis, and THOSE tend to consume more like 1200+ Watts for a /single/ device.
- dsr12 10y agoWikileaks tweeted: "Mr. Assange is still alive and WikiLeaks is still publishing. We ask supporters to stop taking down the US internet. You proved your point. " Link: https://twitter.com/wikileaks/status/789574436219449345 https://twitter.com/wikileaks/status/789574436219449345 If their claim is true, does anyone think, it will turn many sympathizers against them? I don't think attacking normal bushiness is a good thing to do.
- idlewords 10y agoI think this tweet says more about Assange's vanity than anything else. The motives of the attackers are much less interesting than the fact that such attacks are now possible.
- virtuabhi 10y ago"Assange's vanity than anything else" -> Don't get too ahead of yourself. Has there been any instance where Wikileaks had made a false claim?
- peterwwillis 10y agoSo. Can we start talking about changing internet protocols to strengthen the integrity of internet network services against DoS attack? Currently, the internet is very very open (as long as you don't live in certain countries). A baby monitor in Kansas can send arbitrary traffic to a router connecting a major financial services company in Hong Kong to an internet backbone. The idea, in a very hippy, world peace kinda way, is nice. But... probably not something we need to happen, much less should want to happen or allow, if good sense prevailed. We have hacks in place that can prevent that particular situation from becoming too much trouble, but if you have enough baby monitors, something somewhere is going to choke. And really this is the point to me: you [as the network service provider] should not have to have carrier-grade infrastructure to avoid this scenario. If Casey Brogrammer wants to prop up a start-up on her DSL line (do people still have DSL?) she should be able to without fear of DoS. How do we do that? I have no idea. But i'm betting it would require some rearchitecting of the internet and heavily modified protocols. Personally, I think the global BGP tables are gross (and, let's face it people, depending on RAM to perpetually increase in size while simultaneously decreasing in cost ad infinitum is not a realistic scaling mechanism), I think the many flaws in modern tcp/ip protocols are not designed with specific enough use cases in mind, and that the generalist design of the modern Internet has become more of a hindrance to efficiency and progress than a benefit. There is absolutely no requirement that we keep engineering ourselves into a corner, and IPv6 sure as shit isn't going to solve it.
- dredmorbius 10y agoThis would make an interesting Ask HN (or StackExchange or Reddit) question.
- seanharr11 10y agoHarold Martin held without bail (high risk of flight) accused of theft of 20 years worth of government (NSA) tools/data, Trump stating he will not concede the election, tens of millions of IoT devices used in DDOS attack, Assange (wikileaks originator) cut off from internet, DNC hacked and exposed. A conspiracy theorists dream.
- marmot777 10y agoWould longer, say, week long TTL along with some redundancy have prevented this problem? Can it be done now to prepare for next attack? That is, TTL shortened when making updates, etc., but then set to a week the rest of the time. Here's an article that I think could be useful: https://medium.com/@brianarmstrong/youre-probably-doing-dns-wrong-like-we-were-6625efaed390#.1xnqip9w1 https://medium.com/@brianarmstrong/youre-probably-doing-dns-...
- marmot777 10y agoWould longer, say, week long TTL along with some redundancy have prevented this problem? Can it be done now to prepare for next attack? That is, TTL shortened when making updates, etc., but then set to a week the rest of the time?
- deleted 10y ago[deleted]
- rms_returns 10y agoYet another thing to show us that IoT is a can of worms. Yes, the technology is very helpful, but from security perspective, are we ready for it yet? Why not make existing CCTV cameras and nanny monitors more secure before having IoT?
- ThePhysicist 10y agoI wonder why companies affected by these IoT-enabled DDoS attacks don't sue the companies building those devices, as they currently often choose security over convenience when it comes to securing them. If you can forensically prove that a large fraction of the attack was carried out using a given type of device it should be possible to hold the manufacturer liable for the damage, at least if no reasonable measures were taken to secure it (using blank or default passwords on the device could count as gross negligence). I even kind of wish that somebody would do this, as it would finally provide a strong incentive for the manufacturers to think about security.
- rasur 10y agoPoul-Henning Kamp had this proposal on the subject back in 2011: http://queue.acm.org/detail.cfm?id=2030258 http://queue.acm.org/detail.cfm?id=2030258 I think it's a good idea.
- rmchugh 10y agoWikileaks seem to be claiming the attack for their supporters here: https://mobile.twitter.com/wikileaks/status/789574436219449345 https://mobile.twitter.com/wikileaks/status/7895744362194493... Any evidence to support that?
- Chirael 10y agoOne of the Krebs articles mentioned an idea of a certification (similar to UL) which could be on products like DVRs and web cams. You can't ever certify something as completely secure of course, but the certification could indicate "firmware updatable", "no hard-coded default passwords" and "where there are passwords they are generated randomly and unique to each specific product" (not family of products). Maybe even "consumer can change all passwords to new randomly generated values". I can't say that all or even many consumers will care, but if ISPs stepped up and started emailing customers about suspicious traffic coming from their home networks indicating one or more devices may have been compromised, maybe a good number of consumers would start to look for that certification when they buy. Which is important because, let's face it, if insecure products don't actually impact sales then a lot of companies aren't going to care at all. You can try to punish bad behavior after the fact, but only if their government cooperates and even then I think many times they'd just fold up shop under one name and open again under another. You really have to address it at the point of purchase to affect company behavior IMO.
- collinmanderson 10y ago"if ISPs stepped up and started emailing customers about suspicious traffic coming from their home networks indicating one or more devices may have been compromised" - I remember Comcast doing something like that back in 2008ish.
- ehudla 10y agoWorth noting that even of stories such as these (new media, tech heavy) coverage by traditional media end up on the home page of HN. Beyond this observation, it seems that this election cycle brought home the importance of journalism for many people.
- tedd4u 10y agoSince it's impossible to update many permanently-insecure "IoT" devices we may need laws to legalize gov't permanently bricking them.
- progman 10y agoAre there any downloadable DNS lookup tables which could be used as hosts.txt or /etc/hosts in case of emergency? I know that DNS is organized in root zones with hierarchical subqueries. A global hosts file which contains the whole IP space is sort of unfeasible because domain names change within seconds. However, in face of the current attacks the DNS maintainers should seriously consider to offer downloadable hosts files so that we could use them temporarily to circumvent DNS queries in cases of further attacks.