14 ms·
Life of Brian (Krebs)
- yoha 13y ago> Let's say that these intimidation techniques make Brian give up journalism. Maybe he becomes too scared to write. Advocates against anonymity do not get this. I guess they think the bad guys get arrested and the good guys have nothing to hide (asymptotically). They do not consider that the world is not black-and-white and that you may need to protect against technically lawful people. Other than that, I did not know Krebs (but I had heard about this successful battle against spam) and it makes me want to know more. The website hackerfactor.com has a nice design and have potentially interesting content.
- michaelfdeberry 13y agoThat site looks like something from the 90's. Has design regressed that much that the 90's look is cool again?
- quarterto 13y ago> hit by a truly huge attack that averaged 200-400 Gbps I take it he's talking about that[1] DDoS attack? So whoever it was launched the biggest attack in history to to get at one guy? [1]: http://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack http://blog.cloudflare.com/technical-details-behind-a-400gbp...
- omh 13y agoNote that the resources required to launch that attack were relatively small. From the cloudflare article: it is possible that the attacker used only a single server running on a network that allowed source IP address spoofing So perhaps one technically adept attacker, which isn't quite so surprising.
- Wheen 13y ago>Technically adept attacker It was a 15 year old kid http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gbps-ddos-attacks/ http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb...
- culturestate 13y agoThat the attacker was 15 doesn't preclude them from being technically adept.
- sp332 13y agoNo, it's a different attack. The one on Krebs' site was about 200 gbps and lasted 10 minutes, it was done by some kid who wanted to impress a gang or something. The 400 gbps one was against an unnamed site and lasted a couple of days.
- zacinbusiness 13y agoBut wouldn't it be interesting if, in the dark of night, Brian Krebs actually was a serious cyber-crimnal. And he used his reputation and knowledge to frame himself from time to time, just to throw off the fuzz. He's certainly smart enough to pull it off. (no, I don't think that's true that he's a cyber-criminal :-) )
- beachstartup 13y agothe old school version of this conspiracy is the AV software makers were the ones funding the virus creators.
- zacinbusiness 13y agoI heard a rumor back in the day that the Chernobyl virus [1] (Also Win.CIH, I think) was released by Microsoft within pirated versions of Windows. At the time I was in high school and just believed it, because Microsoft was the big, evil corporation at the time. Now of course I'm more skeptical, though I still wouldn't be surprised. [1]: https://en.wikipedia.org/wiki/CIH_(computer_virus) https://en.wikipedia.org/wiki/CIH_(computer_virus)
- fuzzix 13y agoThanks for reminding me of that one. Some bogus design decisions by Packard Bell (no jumper/switch to lock out BIOS flash access) meant two of my machines were written off. No, they weren't running pirated Windows, though I was on day 204 of my 31 day Paint Shop Pro evaluation.
- zacinbusiness 13y agoA friend of mine had a pbell that was killed off by Chernobyl. I was on the phone with him when he booted it up. "I'm going to boot." "Don't do it man." "Nah I'm gonna boot. Here it goes. See it's fine." "Sweet" "Uh oh" "Uh oh?" "Uh oh" And that was the end of that machine lol
- fnordfnordfnord 13y agoThese Black Hats make their living off of companies and people with poorly implemented information security. Brian Krebs makes his living exposing Black Hats who themselves have poor information security. There is some delicious irony in the Black Hats' retaliation against Krebs.
- mosselman 13y agoTo make the article more interesting to read you should've put the ending at the beginning (Barking up the wrong tree). Now while reading what you wrote I am trying to guess where it is heading. If you'd have written it reversed it would be more compelling and convincing. Newspapers do the same thing; they write what is most important at the top and add details and examples further into the article. Good thought and interesting examples though. :)
- ghaff 13y ago>Newspapers do the same thing; they write what is most important at the top and add details and examples further into the article. Inverted pyramid (this style of newspaper writing) has historical roots. The idea was that a typeset story--often wire service copy--could be (literally) cut off at just about any arbitrary paragraph break to fit in the available space.
- rcthompson 13y agoInteresting. The writing style was dictated by the constraints of newspaper layout and the technology's limited ability to meet those constraints. Does that mean that this writing style is obsolete now, or are there other reasons to prefer it?
- Haul4ss 13y agoOne big reason is that it gives people the most important info they need up front. If they care about details, they can keep reading.
- mcguire 13y agoThe modern world is not so terribly different. Most modern readers probably won't make it past the first paragraph.
- shmageggy 13y agoNot the main point of the article, but I'm glad that he's going after malware authors. I don't think I've ever felt so simultaneously enraged and helpless as when I got infected.
- d23 13y agoMy only "beef" with him, as such, is that he stoops to their level and releases the home address and contact information of people -- frequently young people if I remember correctly. I don't think these people should be free from consequences, but it doesn't warrant vigilante justice. I'm sure given that he has been personally targeted his judgment might be clouded though, and it's hard to know what I would do in that situation.
- ehPReth 13y agoThere was a recent post in which he refused to release PII due to the person being a minor: http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gbps-ddos-attacks/ http://krebsonsecurity.com/2014/02/the-new-normal-200-400-gb... ``` “I don’t see what a wall of text can really tell you about what someone does in real life though,” said Rasbora, whose real-life identity is being withheld because he’s a minor. ```
- dllthomas 13y ago"If the only thing protecting your security is a lack of others knowing the secret, then you have no practical security." My understanding is that "security by obscurity" is a condemnation of making algorithms and code part of the secret. A system reliant on others not knowing your (say) private SSH key may lack defense in depth but isn't "security by obscurity".
- phaus 13y agoIts possible that "security by obscurity" has a different meaning in the programming world. When talking about computer or network security it is used to describe any mechanism that attempts to defend a system by hiding something. One of the classic examples of security by obscurity is when a person disables the broadcasting of the SSID on a wireless router.
- dllthomas 13y agoFor what it's worth, Wikipedia disagrees: "Security through obscurity is generally a pejorative term referring to a principle in security engineering, which attempts to use secrecy of design or implementation to provide security." http://en.wikipedia.org/wiki/Security_through_obscurity http://en.wikipedia.org/wiki/Security_through_obscurity "When talking about computer or network security it is used to describe any mechanism that attempts to defend a system by hiding something." That is again a definition which would include ssh keys, which is to say a useless definition. "One of the classic examples of security by obscurity is when a person disables the broadcasting of the SSID on a wireless router." I'm not sure that's an example at all, since hidden SSIDs can be readily sniffed from a publicly documented protocol.
- phaus 13y ago>That is again a definition which would include ssh keys, which is to say a useless definition. For those of us who work in security, its taken for granted that when we are talking about security through obscurity, we aren't talking about passwords and cryptographic keys. I should have been more clear. >"Security through obscurity is generally a pejorative term referring to a principle in security engineering, which attempts to use secrecy of design or implementation to provide security." That's the exact same thing that I said worded in a different way. >I'm not sure that's an example at all, since hidden SSIDs can be readily sniffed from a publicly documented protocol. And that's the entire point. Security through obscurity alone is not a good thing. Starting from the second sentence, and continuing through to the second and third paragraphs, the article elaborates on this. >A system relying on security through obscurity may have theoretical or actual security vulnerabilities, but its owners or designers believe that if the flaws are not known, then attackers will be unlikely to find them. >Security through obscurity has never achieved engineering acceptance as an approach to securing a system, as it contradicts the principle of simplicity. The United States National Institute of Standards and Technology (NIST) specifically recommends against security through obscurity in more than one document. Quoting from one, "System security should not depend on the secrecy of the implementation or its components."[1] >It is analogous to a homeowner leaving the rear door open, because it cannot be seen by a would-be burglar.
- jmileham 13y agoThe description of security by obscurity in this article reads a lot like Kerckhoff's principle, which when employed correctly is actually a virtue. Not to defend cybercrime, but completely covering your tracks (digitally or otherwise) is a very tricky problem - one that people have long tried to solve with both malicious and benevolent intent - and failings in that vein aren't necessarily of the level of amateurishness that the term implies.
- ojbyrne 13y agoModerators changed the title from "Life of Brian" to "Life of Brian Krebs." I honestly think its a poorer title, and they could try and acquire a sense of humor.
- Pxtl 13y agoI wonder how many times the heroin trick has worked?
- snowwrestler 13y agoThere's an undercurrent on the article that is somewhat dismissive of Krebs--i.e. that all his scoops come from tips, and he gets good tips because he's so well known. It even says that if it weren't Brian it would be someone else. The facts, are, though, that Brian started in the Washington Post mail room and has since worked his way into a column at the Post, and now success as an independent blogger. Neither of those were easy or assured for him. So I would argue that there is something about Brian and/or his work that is special or noteworthy.