3 ms·
The elephant in the room is: Probably these attacks would not be possible if all the money put into governmental surveillance activities would have been invest
by LinuxFreedom 10y ago
The elephant in the room is:
Probably these attacks would not be possible if all the money put into governmental surveillance activities would have been invested in building a secure and resilient internet.
This attack is the logical answer to the governmental attacks on all networked infrastructure.
The root cause for these problems is a primitive way of thinking that is a wrong recipe for the path humanity has to take to not destroy itself.
Competition, dominance, control, surveillance, fear vs. cooperation, consistency, trust, freedom, love.
This is not about ethics or morality. It is about the fact that this way of primitive thinking just does not work - it is a stupid recipe for complicated problems and just fails.
Neanderthalers that like to imprison themselves into hierarchies and dominate the whole world should be put into mental hospitals, but never into governmental institutions or positions.
We must stop the domination and hierarchy adoring primitives with their non-working and self-destroying ideas to find an appropriate way to prepare for the future and its challenges.
An important first step is to put the military dog back on the chain and show it the place where it belongs to and never ever allow it to infiltrate politics.
Military solutions must only be the last step of self-defense that we need to use when all politics failed.
A society that allows military thinking to penetrate or even dominate political ideas will be destroyed in the long run, as destruction is the only solution that militarism knows.
Again this is not about ethics or morality, it is about logic. If you throw a stone into water, it will make waves.
- formula1 10y agoFirst off, putting a negative spin to competition already tells me you have either a very narrow view or see something I dont. When iojs forked from nodejs, it was a competitor. Linux is a competitive landscape. Browsers are a competitive landscape. The idea that cooperation and consistancy leads to the best possible product is only as accurate as who is trusted to be the leader. There are some pretty dumb leaders out there but convincing enough to be trusted with millions of dollars. Second off, the government didnt force all devices to be vulnerable. "Agile" development practices which we trust so much are what led us here. Build first, worry about security later. The fact that a persons information is valuable to the creator of these devices and they provide a direct gateway so they could be accessed by a third party. And the fact that consumers ignore any possible issues that may arise because they see the benefits. You talk about logic, well logically we wouldnt have computers or any of this if it wasnt for competition abd the desire to evolve. And logically trust and freedom allowed these vulnerabilities to ho unchecked because the software is not open source and companies are free to do whatever they want since its up to the consumer to judge whether its worth it or not. I understand why you want to make this political and pro-love because arguably any problem can be answered by pro-love. But logically, you should think before you dpeak and attempt to frame your argument with a consistant locigal tree than start blaring out hatred for the capitalist system
- mhurron 10y ago> "Agile" development practices which we trust so much are what led us here. Build first, worry about security later Hardly. It's not like everyone stopped caring about security once they moved to Agile flows. The industry never cared about security. This last attack on Dyn appears to be Mirai again, so devices with unchangeable default username/password combinations. The same poor practices that have existed since there were engineering practices at all.
- bogomipz 10y ago>"This last attack on Dyn appears to be Mirai again, so devices with unchangeable default username/password combinations" The credentials can't be changed on these? Ouch. I didn't know this. Has Mira released any kind of firmware upgrades for their set top boxes and IP cameras?
- mhurron 10y agoMany, if not most, can not. Sometimes even if the user thinks they have. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powered-todays-massive-internet-outage/ https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe... 'That’s because while many of these devices allow users to change the default usernames and passwords on a Web-based administration panel that ships with the products, those machines can still be reached via more obscure, less user-friendly communications services called “Telnet” and “SSH.” ... “The issue with these particular devices is that a user cannot feasibly change this password,” Flashpoint’s Zach Wikholm told KrebsOnSecurity. “The password is hardcoded into the firmware, and the tools necessary to disable it are not present. Even worse, the web interface is not aware that these credentials even exist.”'
- Hydraulix989 10y agoIt's not just Agile, it's competitive enterprises at work. Ship a product now (before your competitor), get EMA; or spend many extra months pentesting and laboriously auditing your code OpenBSD-style. It's much easier to win the market first and then go on PR damage control the next time there's a security incident, pointing the blame on those "evil hackers" while your software has more holes than Swiss cheese. Meanwhile, as an engineer, it's much easier to appease upper management and meet your deadlines (set artificially close by people who don't understand the development process) by writing unsecure code, shipping, and then if something happens, talking your way out of said responsibility. Meanwhile, you're stressed out because of how impossibly unrealistic the deadlines are, and so you're making more mistakes; maybe you're also running off solely caffeine and three hours of sleep the night before while on the trajectory towards burn-out because you're putting in so many hours.
- tdb7893 10y agoWhat do these attacks have to do with the government? My current understanding is that it was an attack against a private organization
- marricks 10y agoI think their first point was the massive amount of money NSA uses is to make weaknesses in the internet infrastructure. While this likely isn't an example of a specific NSA hack being exploited, with all that time, money, and expertise it's likely one they could have fixed. We've had some pretty nasty hacks in recent years, and with the National Security Agency that takes the public's money and actively makes our systems less secure, they're sure not helping our problems...
- deleted 10y ago[deleted]
- smsm42 10y ago> An important first step is to put the military dog back on the chain and show it the place where it belongs to and never ever allow it to infiltrate politics. You seem to be under the impression that military largely controls the politics and that's why there are wars. It's not true, at least not in western democracies. Most wars start when they are popular (and they are made popular by career politicians and not military) and end very soon after becoming unpopular (and the military can't do anything about it). > Military solutions must only be the last step of self-defense that we need to use when all politics failed. That's a nice thing to say but politics fails all the time. In fact, politics fails way more often than military is used - in most cases, the solution for politics failing is just sigh and wait until maybe something changes, military is used in rare occasion where it's politically feasible and seems to be achievable by military.