4 ms·
> the rolling codes mean they would need to either have access to the "secret" and ban all future codes, or just ban "imnotabot*" which wouldn't be sustainable
by munin 9y ago
> the rolling codes mean they would need to either have access to the "secret" and ban all future codes, or just ban "imnotabot*" which wouldn't be sustainable if multiple botnets started using this method
They will have access to the secret, because they have access to the programs that run the TOTP algorithm.
- Klathmon 9y agoBut it relies on all services I would use to add custom code to block all future rolling codes. For a problem that they don't really have any financial reason to write that custom code to stop it. And any fix that they introduce, can be trivially updated to change around by any of the other services. They'd have to coordinate across all services that are used to update at the same time in order to stop it.
- munin 9y agoNo, you reverse engineer the "domain generation algorithm" and figure out what the secret seeds are as input, then every time you need to know the name of the rendezvous point you figure out what the current seed is (easy if it's static, a little harder if it's dynamic) and run the algorithm. Anyone that does this can register the reddit/twitter handles or domain names as soon as they figure this out, if they aren't pre-registered. And if you're the provider, you are then given a list of accounts to kill. Now you're in a game of cat and mouse with the botnet operator, and each move you take kills off some of the operators bots, perhaps all of them if you get ahead of them by enough.
- jstanley 9y agoThe commands could be cryptographically signed to prevent "malicious" control of the botnet.
- munin 9y agoTrue, but you can prevent the introduction of new commands. In this setting, if there's a central point, it can be cut. It's different if there is no central point (i.e. conficker P2P).