5 ms·
DDoS Letter to Chairman Wheeler
- dwheeler 10y agoI think there are a number of specific laws or regulations that could reduce the problems without harming innovation. Here's a starter list: http://www.dwheeler.com/essays/law-security.html http://www.dwheeler.com/essays/law-security.html . I'm sure that list can be improved on (I'd love to hear about improvements).
- protomyth 10y agoRequested responses 8 and 9 scare the crap out of me. I think those pretty much end open source software on the internet. Requested response 6 looks like a call for forced updates. I would of preferred a call for a rule that prevents cell providers from holding up phone updates.
- Sanddancer 10y ago8 and 9 specify manufacturers -- people selling something that connects to the internet. If you're selling, you should have to certify that you've done due diligence. If this is done through NIST standards being created, one of the side effects of this would mean that everyone would get actual guidelines, and almost certainly tools, which could do checking if a device is configured at least semi-properly. If anything, it would mean that vendors would have more impetus to communicate and send patches, because they would have to actually own their problems.
- protomyth 10y ago8 and 9 deal with manufactures, but could be used to stop non-manufacture open source. Its been a long time since Bell and I worry security will be used as an excuse to remove some competition.
- johncolanduoni 10y agoYes, but even if your standard only states that manufacturers have to provide some sort of resilience to attackers modifying the binaries on the device remotely, I suspect many manufacturers are going to go with the simplest way: preventing any modifications save manufacturer-signed updates, and/or reducing user configurability of the device. My feeling on this are somewhat mixed; on one hand virtually everyone who owns a modifiable device never makes any significant modifications and doesn't know how to properly secure it to boot. On the other hand, that means that even if manufacturers had no selfish reasons to put in such limitations of their own volition, the natural state for most consumer device markets is going to be to have no modifiable devices available for purchase just because making an unlocked version isn't worth it.
- dredmorbius 10y agoA non-Scribd source please?
- nulagrithom 10y agoParts of this letter sound informed, while other parts sound woefully misguided... I'm not sure I understand the point. What's Mark Warner going for here?
- Sanddancer 10y agoHe's going for starting the conversation. Basically saying, "hey, here are my ideas, we need to talk about this."
- dreamcompiler 10y agoISPs don't assign IP addresses to most IOT devices; routers do. So there's one credibility problem with this letter right from the beginning.
- 0xfeba 10y agoMaybe he's an IPv6 fan.
- feld 10y agoISPs wouldn't assign addresses to the IoT devices with IPv6 either...
- angry-hacker 10y agoBut who does? Or what factor decides what my iot's device ipv6 will be?
- wmf 10y agoDevices tend to self-assign IPv6 addresses using SLAAC, but the router would still have MAC-to-IP mappings in its neighbor table. Or some cases the router assigns it using DHCPv6.
- johncolanduoni 10y agoJust to clear things up for people unfamiliar with IPv6, the ISP does have some input in this process: they give your router a unique prefix (basically a subnet) which the router delegates to the devices in your network.
- dronemallone 10y agoYou can do it (by that I mean NOW) with DHCP-PD (prefix delegation). Router asks for a range of addresses from the ISP which it then assigns to the IoT devices on the inside.
- 10y ago
- eatbitseveryday 10y agoLetter on the senator's website itself: http://www.warner.senate.gov/public/index.cfm/2016/10/sen-mark-warner-probes-friday-s-crippling-cyber-attack http://www.warner.senate.gov/public/index.cfm/2016/10/sen-ma... Unfortunately it also links to scribd.
- abstractbeliefs 10y agoHumbly and without snark, what happened to scribd that has upset people? Is it just the non-standard PDF viewer or have they been up to something underhanded?
- slavik81 10y agoWant to keep reading? Download the app for the full version! * Read all 4 pages of DDoS Letter to Chairman Wheeler. ------- Their website cuts off the last page of the letter and tells you to download their app to read it.
- Hello71 10y agoyou need to "Continue With Facebook" to download a real PDF. you know, one that you can actually save, edit, read offline, embed...
- angry-hacker 10y agoI can't read it on mobile. I'm not going to download their damn app - a glorified pdf reader.
- jwtadvice 10y agoHow about we fix DNS?
- tptacek 10y agoTo do what? DNS isn't the only amplifier on the Internet, and not all of the Mirai attacks are amplified to begin with.
- jwtadvice 10y ago"Decentralization of core nameserving and smarter caching downlevel so that single modes of failure on internet name resolution doesn't bring entire swaths of the internet down" is what I was thinking. Reflection (UDP) and amplification are problems, sure - we could address those as well.
- tedunangst 10y agoThis wasn't an attack against the root servers, so it's unclear what decentralization help. Should Dyn stand up two servers? That sounds like a good idea, but also something they can do themselves.
- jwtadvice 10y agoSo a proposal here would look like: redundant resolvers with ISPs and routers failing and load balancing between them along with smarter caching strategies on the entire name resolution stack. Getting more academic and speculative with a “pie-in-the-sky” proposal that would remove both privacy and centralization concerns: quorum strategies over a peer-based, differential privacy protected authenticated database seeded by root servers. The point here is that “IoT” isn’t the problem. Thousands of traditional servers can do just as much damage (or more) than thousands of IoT devices in a DDoS. You want to stop attacks that bring down DNS? Fix DNS. You aren’t going to be able to legislate away compromise-likely devices and services. That’s an imaginary solution, and likely to exacerbate other issues (IoT privacy).
- xenophonf 10y agoIt strikes me as being somewhat dangerous to compromise open network/network neutrality rules in order to kick compromised devices off the Internet, never mind the fact that it puts the cost of security vulnerabilities on end users, who can't fix them, instead of vendors, who can.
- AgentME 10y agoIt forces the users to disconnect the devices and hopefully learn to buy more secure devices (and pressure vendors and stores, etc).
- bogomipz 10y agoBut in front of every compromised IoT device is a compromised router. Whose responsibility is that? I am going to say the majority of users down know how to update the firmware on their routers. From the experience I have had with customer/technical support reps at cable companies for basic things like a service outage. I can't imagine them dealing with compromised devices and firmware upgrades or locating IoT devices in customer's home. I don't think they have either the staff capacity or sometimes even the technical skill to do so with any efficiency. Then there's the potential for false positives or bad data where my connection get s null routed and I have to wait on hold for 45 minutes or an hour to talk to someone who may or many not know whats going on. Then I need to prove that there is no IoT device on my local LAN to a support person who might not even know what a mac address is. This just sounds like a mess.
- wmf 10y agoin front of every compromised IoT device is a compromised router. Why do you say that? AFAIK the devices being infected by Mirai use UPnP to expose themselves so the router probably has no responsibility for the insecurity. It would be great if we could build some sort of immune system into home routers and force IOT companies to pay for it, but that doesn't seem likely. Short of mass-bricking these devices, any solution is going to be incredibly labor-intensive and expensive.