8 ms·
Apparently this group is behind it. Also attacked WoW and twitch servers.. https://twitter.com/ukdrillas https://twitter.com/ukdrillas
by Theboda 7y ago
Apparently this group is behind it. Also attacked WoW and twitch servers..
https://twitter.com/ukdrillas https://twitter.com/ukdrillas
- Nextgrid 7y agoPart of the liability should be shared with the people owning the compromised machines these crazies are using for their attacks, otherwise attacks like these will never stop as long as enough free “ammunition” is being left around by incompetent people who can’t be bothered to secure & monitor their systems properly. Edit: in reply to some of the (valid) counter-arguments, I'd like to say that there are indeed many issues that will need to be considered before passing such a law - this is just an overall idea. In addition, my intent isn't to punish the occasional kid doing something stupid and leaving a misconfigured device, it's to punish companies selling/deploying obviously insecure devices at a large scale, like ISPs deploying cheap shitty outdated network hardware or the countless resellers white-labelling insecure network cameras. Currently there is no penalty for manufacturing insecure hardware and this situation is the consequence of that - I'd like to fix this problem. We have regulations that (mostly successfully) prevent companies from selling hardware that blows up and destroys your house, why can't we have the same for networked hardware?
- deleted 7y ago[deleted]
- Torok 7y agoAward for worst hot take of the day goes to....
- iikoolpp 7y agoI, too, wish to punish people for daring to own something that might have a zero-day.
- Nextgrid 7y agoAre we talking about zero days here or obvious vulnerabilities known for decades but nothing gets done because there’s no cost associated with leaving it insecure? I strongly suspect the latter.
- roywiggins 7y agoHow are you supposed know what chipsets are in your smart lightbulb?
- myself248 7y agoThe negative externalities of owning vulnerable devices need to come home to roost at some point, yeah. I've chosen to own a "dumb" (read: "reliable") washing machine, and it cannot be used in such an attack. I have to endure the indignity of peeking downstairs to see if I left clothes in it, which is a cost of sorts, but it's nowhere near the cost I'd expect to bear if I bought a vulnerable washing machine and it provided resources to knock Wikipedia off the internet. What other disincentive to putting vulnerable devices on the internet do you propose?
- Moru 7y agoHow many of those systems are owned by private people that has no idea what to do about it? Do you plan on suing half the planet?
- Nextgrid 7y agoIf these systems are owned by private people then the company who designed it/deployed it is liable. If I have root on the device then it's my fault if I screw up, if I don't have root and it's just a plug and play appliance then whoever designed it/sold it can be liable. This solves the issue of "grandma buying an IoT washing machine" mentioned in another comment as the manufacturer of the machines can be sued directly without bothering grandma (besides a recall program and/or firmware update to patch the vulnerabilities).
- braythwayt 7y agoYou seem familiar with hardware and software hacking, but not the creativity of bad-faith legal hacking ;-) If you pass that law on Day Zero, I claim that on Day One, manufacturers provide some horribly arcane command-line interface for rooting lightbulbs and washing machines, and add some boilerplate to their shrink-wrap licenses forcing customers to acknowledge that they have admin privileges on their devices. Problem solved for them, Granny is liable again according to your system.
- Nextgrid 7y agoDoes the license auto-root the device? If yes, then it's an obviously dishonest circumvention of the law and judges will see right through it. If not, then the manufacturer has to prove the device was rooted if they want to pass liability to someone else. If that still doesn't solve the problem, the media will take care of it. "Buying this smart lightbulb puts you at risk of being sued for thousands of $$$" can't be good for manufacturers and they'd want to avoid the bad press.
- braythwayt 7y agoIt seems simpler and more direct for the media to say, "Selling this insecure IoT-device/phone/router/tv that requires every consumer to become a security expert, and taking no responsibility for OTA patches and so forth, puts you at risk for paying hundreds of millions of dollars in fines and/or damages."
- throwamay1241 7y agoCan't wait to tell Gran she's legally liable for a DDoS because her unsecured IOT washing machine best buy sold her caused the internet to cave in ;)
- ohazi 7y agoSkip Gran and sue Best Buy and the IoT washing machine manufacturer.
- BetaDeltaAlpha 7y agoThere are exactly zero big box retailers or lobbyists that will abide that.
- yorwba 7y agoBig box retailers seem to be able to comply with regulations mandating physical safety. Digital security requirements could be enforced by a similar system.
- RyanAF7 7y agoNo thanks. I'd rather DDoS attcks than whatever the version of a seatbelt locking "safety" mechanism is that these moron companies would force upon people. "Place eyeball for retina scan to unlock your dick pic machine." No thanks.
- majewsky 7y agoBecause "physical safety regulations" is something that the majority understands, so it's hard to argue against that in public. With digital security, most people lack the mental models to follow the discussion, so it's really easy for lobbyists to tell them flatout lies about how those damn dems are out to take their smart lightbulbs away from them.
- rhizome 7y ago
- jolmg 7y agoYou can't expect everyone, kids and elderly included, to be able to identify when their machine is running a rootkit from the result of exploiting a 0-day, for example. People also have a very limited view on what's happening on their phones, too. What if the rights to the source and distribution of a free closed-source app is purchased by someone that's going to modify it to include all users in their botnet? It's not like you can monitor what kind of traffic your phone apps send out.
- betaby 7y agoYou can't expect everyone to be able to identify when their car is not running as expected. Wait, you can and you must under the law. Also there are liabilities.
- owenmarshall 7y agoBrakes squeal when they are wearing down. If I put a penny in the tread of my tires and see Abe Lincoln’s head I know they are bald. If my head lamps go out I’ll notice; if it’s a brake light I get a red indicator lamp on my dash that says I have a problem. Let’s talk about liability when home routers make a revving engine sound when they push too many packets per second, or start playing a “buckle up” warning chime every 6 seconds if they see packets heading to a C2 server.
- betaby 7y agoI'm liable if water/sewage breaks in my condo and there won't be any 'squeal'. Analogies work but are not equal. My point is that there should be liability for the malfunctioning internet equipment, definitely so for businesses.
- owenmarshall 7y agoMaybe. Or maybe liability exists for outside parties in that case: the plumber who was drunk when they put the pipes in, the architect who designed the wall in such a way to force a ton of joints in one weak spot, the building inspector who signed off on it... heck, maybe the water company is causing a water hammer to form because their pumps are busted. Now if my home owners insurance finds that I flooded the downstairs condo because I fell asleep with the bath running, you bet I’ll pay. But no matter what, either of your examples have a robust regulatory structure around them in terms of licensing and inspections. That is why liability works - without those structures you can’t say “you fucked up, therefore you pay”. I’m all for adding liability into the system but if we do we must do it in a way that spreads the burden to the right places (IoT manufacturers, negligent ISPs) and doesn’t push it straight to the consumer.
- neiman 7y agoThat's exactly how over-regulation starts.
- dangom 7y agoCould you ELI5 how these sorts of attacks are possible and what the average Joe can do to mitigate them?
- hombre_fatal 7y agoI don't see why you'd come up with something that so misaligns the interests of everyone except lawyers. Instead, imagine the DDoS landscape if we had to pay a small price for bandwidth. There would be a natural disincentive to having a toaster saturating your bandwidth as part of a botnet because it would quickly show up on your bill. And something as simple as shipping an IoT product or Rasberry Pi with bad default username/password might suffer bad reviews like "1/5 stars, this product immediately raised my internet bill." I know it's not perfect and most of us have a bad taste in our mouth from paying out the wazoo when bandwidth is priced per Gb, but it can be a fair system if priced well that fights against our botnet reality where we basically have zero insight when our networked devices our compromised. I can also imagine better tooling provided by our ISPs in this world where they help us track down and itemize our bandwidth costs. "Honey, why is SmartToaster89 costing us $24 in network fees?" It's impressive how poorly our current system equips everyone except malicious actors. How many ISPs don't even filter spoofed outbound packets? It's hard to complain about everyone centralizing around Cloudflare with the state of cheap DDoS muscle.
- master-litty 7y agoI don't see why you'd come up with something that so misaligns the interests of everyone except Comcast :) We don't need to be priced by the bandwidth, we just need better accessibility to metering. Something my mother could look at and say "huh, the toaster's sent 8gb of data today..."
- johncolanduoni 7y agoIf you’re not charged for it and it’s not enough for you to feel reduced performance on your other devices, why would you even both looking?
- master-litty 7y agoIt would consume more electricity, though let's assume by a marginal amount. I suspect many people are uncomfortable holding a compromised device like that. The unpredictability of a toaster helping to take down Wikipedia is wild and potentially seen as a sign of chaos, especially for less technical users. Who knows what else this crazy toaster will do next? Will it do the same thing again?
- nickpsecurity 7y agoI proposed regulation as interim step in the past. Here's a reprint of it: A combo of per-customer authentication at packet-level, DDOS monitoring, and rate limiting (or termination) of specific connection upon DDOS or malicious activity. That by itself would stop a lot of these right at the Tier 3 ISP level. Trickle those suckers down to dialup speeds with a notice telling them their computer is being used in a crime with a link to helpful ways on dealing with it (or support number). Far as design, they could put cheap knockoff of an INFOSEC guard in their modems with CPU’s resistant to code injection. Include accelerators for networking functions and/or some DDOS detection (esp low-layer flooding) right at that device. https://en.wikipedia.org/wiki/Guard_(information_security) https://en.wikipedia.org/wiki/Guard_(information_security) Old one from high-assurance field, albeit with medium rating, that did what I’m describing in an Ethernet, card computer: https://web.archive.org/web/20040623100328/http://www.cryptek.com/SecureNetworks/products_diamtek_dia_link.php https://web.archive.org/web/20040623100328/http://www.crypte... Modern implementation could probably be done in a cheap clone and security-enhanced mod of this product: https://www.cavium.com/OCTEON-II_CN68XX.html https://www.cavium.com/OCTEON-II_CN68XX.html
- dahart 7y ago> Part of the liability should be shared with the people owning the compromised machines You’re voluntarily signing up to get fined when someone hacks the computer in your house, because you connected it to the internet, right? > Currently there is no penalty for manufacturing insecure hardware I’m glad you see some validity in the counter-points, but doubling down on this idea of punishing manufacturers for things people do with their hardware seems misguided at best. You can’t prove any hardware is secure, if there were such penalties there would be no hardware, this is a total and complete non-starter. Moreover, there are lots of other bad things you can do with hardware, this would open the door to holding manufacturers accountable for everything. Do you think Intel or Dell will accept fines for every successfully hack into machines they made? This isn’t unlike suggesting that ISPs should be held liable for people doing illegal things on the internet, or suggesting that it should be illegal to pay ransoms. It’s hurting the wrong people, and failing to punish the people doing wrong. > this situation is a consequence of that That’s a purely subjective opinion that ignores multiple causes, and ignores the single most direct cause: people who wish to do bad things. It would be just as valid to blame this on a failure of the education system & social civics as to blame hardware manufacturers. Maybe we should fine teachers who have students that later do bad things? > We have regulations that (mostly successfully) prevent companies from selling hardware that blows up and destroys your house, why can’t we have the same for networked hardware? First, the analogy is bad because there are zero good uses for consumer bombs in houses, while there are plenty of non-harmful uses for IoT devices. Second, because there is a market for simple hardware that can be deployed inside of secure networks, and doesn’t require a team of security experts to run. Secure hardware is more expensive to produce than simply-connected hardware.
- adrusi 7y agoThis stands out to me as a problem that mandatory liability insurance would be well suited to. Make everyone liable for damages to people and organizations harmed by illegal use of their unsecured computers. Then everyone who has an internet-connected device has to purchase liability insurance. They would be able to choose between expensive policies that impose no surveillance or restrictions, or purchase cheap policies that require running surveillance software, or submitting to regular security audits. Most individual consumers would probably end up with cheap policies that just require them to use devices that receive timely security updates from vetted manufacturers and run behind typical home internet firewall rules.
- Waterluvian 7y agoThat's such a terrible idea but it would make a fantastic satire Sci fi short story premise. Technology that cannot be used by anyone but the snobbish tech elite because anyone else just gets sued to oblivion.
- k5hp 7y agoHow can it be that a single group can take down Wikipedia? The internet is broken.
- kminehart 7y agoIt's a bit sad. With a bit of money and some connections, you have access to a botnet large enough to cause some serious downtime.
- time0ut 7y agoI heard he used the same email on twitch as his personal facebook and has already been identified.