6 ms·
Anonymous plans to take down the 13 root DNS servers that power the Internet?
- paulhauggis 15y agohmm..and people here on HN say they aren't a digital terrorist group.....
- snsr 15y agoWhile the DOS discussed in that link is quite obviously misguided, counterproductive, juvenile and likely criminal, 'terrorism' seems like a pretty strong word.
- eli 15y agoWhat is the purpose of the action if not to create some small amount of terror on the part of "our irresponsible leaders"?
- sp332 15y agoDOS is a kind of protest, like a picket line. Protest != terrorism.
- devnul3 15y agoA protest becomes terrorism when it prevents access to vital services (eg "picketing" a hospital and not allowing ambulances in/out)
- pyre 15y agoSo if a bunch of hospital workers were protesting their pay and formed a picket line around a hospital, their purpose would be to 'instill terror?' Somehow this comes across as adding to the dilution of the word 'terrorism.' Do you really think that picketing a hospital is comparable to using guerilla tactics against a civilian population? I'm not agreeing that people should be allowed to prevent access to a hospital, but the idea that 'terrorism' is the best label for this sort of action seems ill-advised. Maybe I'm being naive, but I don't think that anyone would have called such actions 'terrorism' back in the 90's, why is it all of the sudden terrorism now? Seems like any deliberate action by a small group of people against a larger group of people that will have any sort of adverse affect on the larger group is being crammed into the 'terrorism' bucket these days...
- devnul3 15y agoif you're in the ambulance, or think you might be, and are refused access to life-saving medicine, you will be terrified. Terrorism is using force or the threat of force against a population to achieve political or economic goals. That is chapter and verse what Anon is doing with these threats. There are (obviously) degrees of terrorism. Hitting buildings with planes isn't the same as sending a few letters with anthrax in them. But both are terrorism.
- pyre 15y ago> Terrorism is using force or the threat of force > against a population to achieve political or economic > goals A bunch of people handcuffed in a circle around a hospital doesn't have anything to do with 'force.' Just sayin'.
- dedward 15y agookay, lets see..... so your kid is in the mbulNce on his way to the hospital. a bunch of people, by way of their sheer numbers, purposefully prevent your kid from receiving the medical attention he needs. kid dies. i agree terrorism is a strertch, to be sure.... . but lets not mix words. a picket line is one thing, they generally wont physically stop you from passing. there are plenty of countries in the workd, quite nice places otherwise, where such proteststurn into full blockades of highways, and they will not let an ambulance or anyone else past. the first time i saw this i wondered why they were not all arrested for blocking a critical transit route ( And this was no exaggeration or trumped up thing....f they blocked the highway for days. a few people died for kack of medical care)
- devnul3 15y agoInertia == force. Just sayin'
- devnul3 15y agoAnd to more directly address your first question, no, their goal wouldn't be to instil terror. That's never the goal, merely the method. This is why the subject gets clouded, terrorists _goals_ are to achieve change. Their _method_ is to do this by insilling terror.
- paulhauggis 15y agoIt's not just this. Every single time a new link is posted about Anonymous it's some form of digital terrorism. It has barely a purpose and only serves to disrupt the masses. They even have made threats that they would do X if Y isn't done. This is terrorism to me.
- marshray 15y agoThis is a serious question: Are you actually in a state of terror by this Pastebin entry, or are you just saying it's rhetorical 'terrorism'?
- mindslight 15y agooh to be an agent provocateur these days! post on pastebin and be home in time for dinner. tomorrow, enjoy the "news" articles calling for a more "secure" internet ...
- jsmcgd 15y agoDo you classify strike action by unions as terrorism? Unions threaten to do X if Y isn't done and end up disrupting the masses.
- noonespecial 15y agoYou'd have to be more clear on who "they" are. Some of them are no doubt 'digital terrorists', many are not. The they isn't the same they from campaign to campaign. Everyone who wants to be Anonymous, is.
- deleted 15y ago[deleted]
- fady 15y agodoes this mean, that even if we typed the IP address of a site, we would get an error? i'm not sure how all the protocols work, so any clarification would be great.
- kruhft 15y agoNo, you could still get to the site with just an IP address, if you have it.
- fady 15y agook, thanks for the clarification. what confused me was "thus, disabling the HTTP Internet" i'm kinda glad they're attempting this, IMO. i'm tired of ignorant people not understanding what the "web" really is, and how important it is to keep it free and open. sure, this might make "hackers" look bad, but honestly, if we sit back and do nothing, then we cannot complain when laws are passed, etc.. if they pull this off, it will be a historic day, no?
- devnul3 15y agoDid you seriously just ask how the web works, then complain about ignorant people who don't know how the web works...? What does hackers using DDoS to knock a service offline have to do with it being free/open? Everything isn't about SOPA/ACTA/et al...
- fady 15y agono. are you really trying to start an argument? clearly, you knew what i meant. there is a difference between a web developer who did not understand some specifics regarding a protocol and a "average joe" user who does not even know what a protocol is.
- devnul3 15y agoTry not to take this personally, but in this context there's apparently not as much difference as you seem to think. Neither of you (as evidenced by your question) knew enough about DNS to fully understand the implications of what the article was saying. At best you knew enough to know what question to ask. My point is actually that there's no reason average users need to know this stuff. Any more than there's a need for them to know what a CV boot is on their car. They know if the car makes a weird noise going around corners, call a mechanic. They know if they get errors on "teh Googlez", to call their ISP.
- hastur 15y agoGood luck, Onanymous. Big talk, like with Facebook, but nothing will happen.
- Hominem 15y agoI'm pretty sure every hacker group has gotten this idea at one point or another. Has anyone even come close to taking down all the root DNS servers at once?
- tristan_louis 15y agoIt has indeed been attempted in the past. If memory serves me well, the best hackers could do was take 3 of the 13 out at the same time.
- astrodust 15y agoWith Anycast DNS there's actually more than thirteen servers even if there's only thirteen IPs. It's going to be almost impossible to flood them all simultaneously. These are machines on multi-gigabit backbone connections, not some crappy back-water FBI or CIA web server.
- necenzurat 15y agoFBI and CIA have posters not websites
- icehawk 15y agoThe last major attack was in 2007, and only two servers were rendered unreachable: http://www.ripe.net/internet-coordination/news/industry-developments/global-root-server-system-stands-firm-against-ddos-attack http://www.ripe.net/internet-coordination/news/industry-deve... For anyone to actually notice, you have to take down all 13 for 48 hours, and it will be another 48 hours after that before there is a complete outage for everyone.
- r00fus 15y agoGiven the built-in resiliency of the DNS system, wouldn't creating an alternative system[1] be more effective in disrupting the status quo? [1] http://en.wikipedia.org/wiki/AlterNIC http://en.wikipedia.org/wiki/AlterNIC
- icebraining 15y ago
- worthlessgenius 15y agoThey should say the word "thus" more often...
- sylvinus 15y agoMost interesting bit : The principle is simple; a flaw that uses forged UDP packets is to be used to trigger a rush of DNS queries all redirected and reflected to those 13 IPs. The flaw is as follow; since the UDP protocol allows it, we can change the source IP of the sender to our target, thus spoofing the source of the DNS query. The DNS server will then respond to that query by sending the answer to the spoofed IP. Since the answer is always bigger than the query, the DNS answers will then flood the target ip. It is called an amplified because we can use small packets to generate large traffic. It is called reflective because we will not send the queries to the root name servers, instead, we will use a list of known vulnerable DNS servers which will attack the root servers for us.
- gabaix 15y agoWhere could we find more information about those 13 servers? Why are there only 13 of them?
- tomku 15y agohttp://en.wikipedia.org/wiki/Root_nameserver http://en.wikipedia.org/wiki/Root_nameserver should answer most of your questions.
- sespindola 15y agoHere.[1] Most of them are not single-box servers, but cluster with multisite redundancy. That's why all attacks were unsuccessful in the past. 1. http://en.wikipedia.org/wiki/Root_name_server http://en.wikipedia.org/wiki/Root_name_server
- jason_slack 15y agoSo could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?
- tptacek 15y ago
- mcritz 15y agoLet's assume they succeed. They take down the Internet at noon EDT (9AM PDT). What's the worst that could happen?
- tomjen3 15y agoWell that all depends. First most requests don't go to the root servers -- they are far too important, second there is caching on the isps servers. To have any effect other than to make sys admins dehydrate anon have to keep the attack up long enough to have the caches empty (if they are indeed configured to flush even if they cannot connect to the root. They may not) and there are several layer deep caching (your isp is but one. Your local computer may also have one). But assuming they can keep it running long enough for the DNS service to die(and they may very well, that flaw is pretty smart though they have to use the actual ip of the vulnerable DNS servers, which means that it can be filtered if the admins are smart enough)? Well goodbye internet -- you would just get an error, no matter which website you would try to access. A pretty grim situation, but not likely.
- icebraining 15y agoBittorrent will still work, though ;) Well, at least if using DHT. The trackers use a domain, of course.
- Macha 15y agoIsn't their example of google that won't be affected? I was under the impression that very few DNS queries actually go to the root nameservers as ISP's and so on have it all cached. And since I highly doubt there is any ISP that has not had a user visit google.com in the last 48 hours, Google will still function for people? In fact, the only people I can see this affecting (in the unlikely event it does happen) are people setting up new sites.
- amitparikh 15y agoThe pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)
- sespindola 15y agoMost ISP's dns cache servers honor the TTL defined in the authoritative SOA records, unless is 1 minute or less. I think the average TTL time for a dns zone would be measured in minutes. It needs to be that low in order to do SRV load-balancing, A/B testing, etc. In any case, in the highly unlikely event that they manage to overload the 13 servers, there's plenty of time for every domain to temporarily extend the TTL on March 31.
- nicksuan 15y agoIn my experience many ISPs do the exact opposite, and inflate cached TTLs up to a week. Makes migrations a pain in the ass.
- Deamos 15y agoNow, I'm thinking about the order of DNS requests.. Local Hosts -> Router -> ISP/OpenDNS/etc -> On out to the Root Servers. Now wouldn't make DNS caching make this attack only partially effective really...if it even worked?
- sp332 15y agoThe point is to be heard, not to destroy anything in particular. They're just trying to get attention.
- amatus 15y agoIs it just me or does it seem like this attack will be self-defeating? They are relying on DNS servers to serve responses in order to make DNS servers stop serving responses.
- aphyr 15y agoNo; the root nameservers have fixed IPs. Those IP addresses, and those of the vulnerable DNS servers to be used as reflectors, can be written down beforehand.
- sp332 15y agoThe problem is that, in the DNS spoof attack, the DNS reflectors have to have some data to send "back" to the spoofed IP. If the root servers are down, the reflectors won't have any data to send back, so the flood will stop as the reflectors' caches expire.
- amatus 15y agoSo it's not just me. Thanks.
- aphyr 15y agoPossibly. I haven't read the particular technique they're planning to use here, but I recall some old attacks against Bind relied on query reflection, which might work in the absence of cached data.
- icebraining 15y agoAs far as I know, they should still send a SERVFAIL response if they are unable to contact the authoritative servers.
- deleted 15y ago[deleted]
- eli 15y ago> Q: What if all root name serves would stop answering queries? > A: Now you are stretching it. How likely is that? The diversity in the system will prevent that from happening. But let's treat it as a hypothetical case: In that hypothetical case the Internet will not suddenly grind to a halt. If absolutely nothing is done to correct the situation every hour about 2% of all queries will not be answered, 2% at the end of the first hour, 4% at the end of the second hour and so forth until 48h after the root name servers stop answering queries no DNS names can be resolved anymore. However it is even more hypothetical to assume that nothing will be done to correct this hypothetical situation. > Even in the hypothetically hypothetical case that the root name server operators would do nothing to correct the situation, the IANA, TLD operators, ISPs and others would have the motivation and the means to take corrective action. > Again: this is very hypothetical. DNS failures outside the root name servers are much more likely. Name service for the vast majority of top-level domains is very much less redundant than that of the root name servers. Whole top-level domains and major corporations have been unreachable for significant amounts of time because of DNS failures. Name service for the root zone has always been available. http://www.isoc.org/briefings/020/ http://www.isoc.org/briefings/020/
- mfincham 15y agoMost of the "root servers" are big anycast clusters. L root has at least 50 locations worldwide...
- astrodust 15y agoI think the Anonymous "hackers" are still under the impression that one IP equals one server. Anycast works very well with UDP and they're in for a surprise as their attack is diffused across so many different links.
- jevinskie 15y agoAnd they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-08mar07_v1.1.pdf http://www.icann.org/en/announcements/factsheet-dns-attack-0...
- icehawk 15y agoAnycast in a DDoS situation would help, but if you throw enough traffic at it you end up with the original DDoS, plus a second DoS caused by cascade failure of the individual nodes going offline, causing BGP flap dampening. Not sure if Anonymous has those kinds of resources though.
- sp332 15y agoTFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).
- deleted 15y ago[deleted]
- icebraining 15y agoTOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much). TOR itself filters it: Also, remember that many of their more subtle communication mechanisms (like spoofed UDP packets) can't be used over Tor, because it only transports correctly-formed TCP connections. My guess is that they're just clueless.
- marshray 15y agoI suspect they were planning to use Tor for command and control. Odd that it was only a requirement for the Windows software though. Perhaps they script its installation on the Linux side.
- krelian 15y agoWhen is it Anonymous and when is it some random guy that decides that now he will become Anonymous?
- vidarh 15y agoI don't know if they're just simplifying things or are just clueless, but none of the 13 DNS roots are single servers. Most or all of them aren't even in a single physical site. There's somewhere around 240 root server sites each consisting of multiple physical servers, just served up on 13 IP's. Given that many of these sites are colocated at interchanges and with providers with tons of multi gigabit links, they have quite a challenge... Ripe last year had an incident where they reported a fivefold increase in queries to the K-root without any operational problems, for example. They successfully handled close to 70,000 queries per second at one point. I'll be surprised if they manage to even have a noticeable effect.
- chives 15y agoWe have no proof that this is even Anonymous. We have nothing that says that the author of this is even a hacker or knows hackers. Any person following the Anonymous attacks and statements could have easily written this file. Why is this on hacker news? This is not news, this is a poorly (tech wise) written short story.
- A1kmm 15y agoAnonymous isn't a group, it is a meme, and so it doesn't make sense to say that someone could be impersonating anonymous. I agree that non-credible claims under the Anonymous meme should be hidden here if they don't have a significant enough following to be newsworthy - the use of a particular meme does not automatically make something newsworthy.
- Retric 15y agoThey might be able to attack by doing something that takes more computation on the DNS servers part than a simple query. Still, DNS scales vary well for example Google's DNS servers Average 800,000 queries per second so I would not be surprised if they was ridiculous overkill at the root servers. PS: I suspect this is most likely just someones random trolling of the internet.
- brother 15y agoHow is load balancing accomplished with this?
- redthrowaway 15y agoLeaving aside the why, I'm highly doubtful they'd be able to pull it off. Back in the Conficker days, it was rumored that it could be used to shut down the Internet with a similar mechanism. Conficker, I can see. Anon? Hell no.
- feric 15y agoI think Anonymous doesn't really know how DNS works. The root nameservers don't serve zone data for most sites that people use anyways. DNS is a distributed hierarchy for serving requests. It's designed to be fault-tolerant because if every name resolution (google.com->8.8.8.8) performed by a browser had to reach 13 servers in the world, we'd still be using gopher and newsgroups instead of the web. DNS is distributed, hierarchical, redundant, and cached all over the place as much as possible. Even my laptop caches DNS queries until a reboot. Even if a DNS cache misses (which is infrequent), it goes to the nameserver hosting the zone, which isn't a root name server. Bottom line, it's probably just a joke designed to get some attention and to experiment and see what actually does happen if you hit those servers.
- mmaunder 15y agoPretty sure sending reply packets to root servers that ever asked for them will simply be ignored. The only impact will be a busy network. As another poster mentioned, anycast will be hard to dos.
- tapsboy 15y agoThe bankers will pack up for the day and play golf; no real impact.
- jsz0 15y agoWeren't they going to take down the New York Stock Exchange a couple months ago too?
- Craiggybear 15y agoSoooooo ... why are they telling everyone? Forewarned = forearmed and all, yo. Won't work. Unless they have something totally different planned and this is a simple misdirection.
- jeggers5 15y agoWhy do people always take these so seriously? It's far more likely that a bored teenager somewhere wrote this. Also, if we were to assume that Anonymous does actually exist in some semblance, they would never ship a notice like this with gramatical errors. They're small, but obvious. I'll eat my foot if they actually manage to make a noticeable affect on the DNS servers anyway.
- shingen 15y agoThe bottom line is simple: they can't do it, they won't be able to do it, and it makes the issue moot. Someone is desperate for attention. You would need to have complete control over the infrastructure of something equivalent to an Amazon, Microsoft, or Google to take down the whole DNS system - and it would require a permanently sustained and constantly evolving attack. I'm always amazed at the vast under-estimation of what would be faced in a real attempt of that sort. First, let's assume they made some progress and actually started harming the stability of the global Internet. 1) the number of interested parties (from hackers to corporations) that would immediately respond to the counter, in numerous ways, would resolve the issue in an extraordinarily short amount of time and 2) watch you don't have the US special forces black bagging you within 24 hours if you're involved, no matter where you're at on earth. The corporate money interest in the Internet being up is at least a hundred billion dollars per day. They will kill you over that, or at the least put you in an off grid terrorist prison.
- MPSimmons 15y agoUm, BGP?
- shareme 15y agoGuys, someone is pulling Internet's leg and right now I assure you that the pastebin post author is laughing his head off that its on HN Can we kind of bury this
- hybrid11 15y ago"To protest SOPA, Wallstreet, our irresponsible leaders and the beloved bankers who are starving the world for their own selfish needs out of sheer sadistic fun, On March 31, anonymous will shut the Internet down." What does taking down the internet have to do with that mission statement?
- techiferous 15y agoI, too, find this strange. This does not seem like an event with a specific objective in mind (beyond taking down DNS). It seems like a release of internal psychological tension onto the external world. Smacks of Jung's shadow: http://en.wikipedia.org/wiki/Shadow_(psychology) http://en.wikipedia.org/wiki/Shadow_(psychology)
- josscrowcroft 15y agoAnyone consider this might be a fake? Any verification?
- chris 15y ago9 of the 13 root servers were taken down via a DDoS back in 2002. http://c.root-servers.org/october21.txt http://c.root-servers.org/october21.txt Although the report states "2.4. There are no known reports of end-user visible error conditions during, and as a result of, this attack.", it's not entirely accurate. I personally experienced issues with name resolution shortly after the attack started, and had no idea what the cause was until afterward. If I recall correctly, my name resolution was handled by Qwest, as they were the T1 transit provider I was using at the time.
- meow 15y agoTalk about cutting off the branch you are sitting on...
- alFReD-NSH 15y agoI got a feeling this news will break pastebin and not DNS :P
- ccarnino 15y agoSurely this give you the impression about how powerful this team is. I don't know if this is too much borderline not to cause big consequences. Also if I don't if this is the best ways to protest, I support the cause.
- chewxy 15y agoJust curious if these root DNSes have low TTLs. What about servers that use squid-like caching tools for DNS records?