7 ms·
Dutch police take down hornets' nest of DDoS botnets
- rolfvandekrol 7y agoI love how they don't tell the full name of Marco B. and Angelo K., but do tell that they companies were called "Bos IT Holding BV" and "Kreikamp IT Holding BV".
- jmkni 7y ago> Good morning, class. A certain... agitator-- > For privacy's sake, let's call her Lisa S. > No, that's too obvious. Uh, let's say L. Simpson--
- zaarn 7y agoPossibly the newspaper didn't even notice at first, though the abbreviation of the name is usual (and mandatory) in Europe.
- ErikHuisman 7y agoIt is NOT mandatory. This is courtesy of the press but there are no laws or regulations.
- zaarn 7y agoIt's mandatory if the newspaper want to continue being a respected newspaper. So for all intents and purposes it's mandatory.
- archi42 7y agoI can second this. You don't read the full names of suspects (!) in a newspaper in Germany. I believe this is actually due to the law here (e.g. if they're innocent, their name is not ruined). That is somewhat relaxed, as long as they're not a public figure (e.g. no one would say "Angela M. is suspected to be a physicist" if it's about the German Chancellor) and as long as it's clear from the article that they're not (yet) convicted. Can't speak for the rest of Europe of course.
- Doxin 7y agoWell I dunno about germany but over here in the netherlands there's no real law about not using full names. However if a paper does use someones full name and then that person gets their reputation ruined they will usually get a lower sentence if guilty. The idea being that getting your reputation ruined is a punishment in itself.
- Confusion 7y agoThere is currently a court case against a drugs kingpin where one of the reputable newspapers does mention his full name, but each time followed by "-- the suspect's lawyer has indicated the suspect has no objection to his full name being used" (once per article of course)
- hobofan 7y ago"Proper" newspapers don't, but yellow press (e.g. BILD) which is consumed by a large chunk of the German population doesn't really care that much about preserving privacy or correctly reporting on conviction status.
- Ligrev 7y agoBos means a forest, likely nothing to do with his name
- deleted 7y ago[deleted]
- vectorEQ 7y agojust google the company names, atleast one yields name of 'ceo'...
- jbverschoor 7y agoIt’s a normal Dutch last name. Also, the naming of the holdings is the same. So they probably registered it at the same time. Anyway, information can always be checked at the chamber of commerce
- krageon 7y agoIt costs 2.50 to check the names of the owners of these companies at the chamber of commerce if that makes you doubt whether or not it's actually the name. This means that the owners were effectively outed by the publication anyway.
- vectorEQ 7y agoit costs google query.
- avar 7y agoNot really, the point of Dutch privacy law (and similar EU laws) in this context is not to deter a dedicated investigator, but to merely put enough of a hurdle in place that everyone reading the article won't see the names of suspects, and they won't show up in web searches etc.
- gpvos 7y agoThe convention (I don't think it's actually a law) existed before web searches, but it's a nice side effect.
- systemtest 7y agoI remember articles in the style of: "Dennis B., son of Jan Bredewold". I believe it was the Telegraaf newspaper.
- botwriter 7y agoIf even Bulletproof hosts aren't safe why aren't malware authors using P2P infrastructure?
- melcor 7y agoMy guess would be that bulletproof hosts are safe enough for long enough that it's both money and time wise better/easier to deal with than p2p.
- cdirkx 7y agoThere is a difference between ignoring abuse reports and being immune to a raid by law enforcement. For these authors there is a trade-off between convenience, cost and security: using already available infrastructure is probably easier than to set up your own complicated hosting solution. If any of them end up getting caught because of the information gathered by this raid they obviously misvalued one of these aspects in their trade-off analysis. Humans all make mistakes.
- jascii 7y agoIn order to keep a coherent network, most (all?) P2P infrastructure still requires some centralized resource to seed initial peers etc for a node. You would still have a single point of failure, if not for the network, at least for your control of it.
- saag4dinner 7y ago"hosting all sorts of badies, from phishing pages to vulnerability scanners, and from crypto-mining operations to malware repositories." Is crypto-mining now a bad thing or is this article leaving out some details that I'm missing?
- OrderlyTiamat 7y agoPerhaps a virus that uses the computers of unaware victims to crypto-mine. If you infect enough people, I guess you'd stand a chance. Not sure if targeting iot would be the best move for that, and the article seems to insinuate that this was mostly iot based malware, so I don't know.
- asymptotically2 7y agoPeople mine on systems that they do not own. Try leaving SSH open with weak credentials, or use any software with a recently disclosed RCE. It won't be long until somebody drops a Monero miner.
- vanderZwan 7y agoI mean, I've seen ad-block filters for scripts that try to crypto-mine via peoples browsers through ads on websites, so this is hardly surprising.
- hannob 7y agoIt absolutely is a bad thing. Unfortunately it's not illegal.
- holstvoogd 7y agoReminds me of that fun time I had to explain to my boss that providing a 'russian contact' of his with a number of servers that would have some sort of 'remote kill switches to delete everything', probably wasn't a smart venture for our hosting business. At some point the cops will come knocking :)
- mirimir 7y agoKill switch? Maybe just LUKS with dropbear. Then: # cryptsetup luksRemoveKey /dev/mapper/foo
- pjc50 7y agoCheck your local laws on cryptography and destruction of evidence before trying this. You may still be legally obliged to decrypt the material or go to jail.
- mirimir 7y agoTrue. Last I read, that ex cop is still locked up in Philadelphia, for contempt. They don't believe that he forgot his passphrase. But parent was talking about hosting servers for a client. If the client executed that command, I don't see how the provider could be responsible. The client could be. But they'd need to extradite him, from Russia, which might not be so easy, these days.
- Alupis 7y agoSometimes going to jail for obstruction/destruction of evidence is a better option than the alternative...
- Kaotique 7y agoI was in elementary school with one of the suspects. He was always a troubled kid. Very sad how that turned out.
- philprx 7y agoThis is not bidirectional though,.. many troubled kids become great people.
- SmellyGeekBoy 7y agoMany "normal" kids become troubled adults, too.
- silviot 7y agoI thought the initial `D` in DDOS sttod for "distributed". The article reports about "DDoS botnets operating on KV's infrastructure". Wouldn't "DDoS botnets operated from KV's infrastructure" be a better description?
- grepthisab 7y agoI run a distributed system on AWS infrastructure. It's still distributed by all common usage of the word.
- GoblinSlayer 7y agoIf your system goes down together with Amazon, it's not distributed, it just occupies several machines - a farm.
- xboxnolifes 7y agoIf your system goes down together with (the Earth|DNS Routing|ISPs), it's not distributed, it just occupies several machines - a farm.
- callalex 7y agoYes but a Farm Systems Engineer is a very different job than a Distributed Systems Engineer.
- solotronics 7y agolol. I work down at the Cloud Farm.
- giancarlostoro 7y agoThe server that commands the zombies has to run from somewhere. So it's likely the host was used as the Command and Control hub.
- jacquesm 7y agoWhy didn't their upstream provider just blackhole their IP ranges?
- IfOnlyYouKnew 7y agoBecause law enforcement tends to reach for the law as their tool of choice. And since crimes were committed, their goals include not just "stop it from happening again" but also "prosecute", which needs evidence that cannot be obtained by a routing patch.
- KingMachiavelli 7y agoIs it just me, or are the majority of raids of malware/botnet hosters typically in the EU? I mean just 6 days ago a raid was cunducted on a old NATO bunker in Germany. https://news.ycombinator.com/item?id=21090549 https://news.ycombinator.com/item?id=21090549 Is it that it's easier to become a hosting provider there with more protections (rights) and/or does America/NA lack the legal authority/process to conduct as many raids. Obviously eastern Eurupe/Russia is the wild west but I'm just suprised how much comes out of western Europe.
- zelon88 7y agoI'm curious why Eastern Europe/Russia are the wild west of douchey internet behavior. I mean there are seemingly endless bulletproof hosting providers. Who wakes up in the morning with the ultimate goal of being slimy on purpose like that? And why are there so many of them concentrated in Russia/Eastern Europe?
- jungturk 7y agoI'd assume that the ultimate goal that motivates most of them is to make money to improve other parts of their lives. That often boils down to reaping the gains and externalizing the costs, which these hosting solutions seem to do fairly well for their owners (though perhaps not for the operators that get caught up in the eventual stings).
- swalls 7y agoAs far as I know, it's at least partially because Russia doesn't extradite citizens and doesn't respond to other countries requesting they investigate.
- opportune 7y agoIf you think about it from the host countries’ perspective, stealing money from foreigners or nefariously affecting them doesn’t harm the hosts much but can bring in a lot of money to their economies.
- ryanlol 7y ago>And why are there so many of them concentrated in Russia/Eastern Europe? They aren’t, the vast majority of them are in the Netherlands. Why NL? Cheap and just the traditional destination.