Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Salt Fish
Sep 11, 2003

Cybernetic Crumb
The idea that the US government would conduct cyber warfare from only it's own assigned arin registered addresses is so ridiculous that I'm having trouble even processing that someone could believe that.

Adbot
ADBOT LOVES YOU

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Salt Fish posted:

With all that we know about NSA's hardware and software capabilities this is a super naive assumption. It's extremely likely that there are entire IoT botnets out there that have compromised control servers ready to be used by a variety of nation states. I would bet both of my testicles against a sandwich that at least 3 nation states have enough ddos capacity to take out the root nameservers.

Part of what makes the NSA's capabilities so big is that they have way more stuff than just that Utah data center he mentioned. That's why the Utah datacenter would be of little use in attempting to run any sort of denial of service.

They don't have any magic hardware that would make using just their one big data center particularly useful for denial of service, or really even using it as part of a wider attack.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

Salt Fish posted:

The idea that the US government would conduct cyber warfare from only it's own assigned arin registered addresses is so ridiculous that I'm having trouble even processing that someone could believe that.

uh dude, that's exactly the sort of poo poo he was suggesting, by using the utah data center. and why i said "no, that wouldnt really work"

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

Captain Foo posted:

it does the same poo poo on ios, zdziarski was going through it on twitter earlier

ios doesn't allow all of those application rights and you have the ability to block it from accessing specific things when it attempts

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

android.

Wiggly Wayne DDS
Sep 11, 2010



BangersInMyKnickers posted:

ios doesn't allow all of those application rights and you have the ability to block it from accessing specific things when it attempts
undocumented apis still exist for shenanigans

Munkeymon
Aug 14, 2003

Motherfucker's got an
armor-piercing crowbar! Rigoddamndicu𝜆ous.



BangersInMyKnickers posted:

ios doesn't allow all of those application rights and you have the ability to block it from accessing specific things when it attempts

android kinda does that as of whenever they rolled out that material design stuff I think

idk if it still works that way if you ask for an old api layer because I bet older apps would just poo poo themselves because android

A Man With A Plan
Mar 29, 2010
Fallen Rib
If you have control of a large percentage of the world's fiber backbone and telecom capacity, as well as all kinds of other malicious capabilities to take out boxes, you probably don't need to ddos things.

E: more that there's no reason you need to be the biggest ddos'er

qntm
Jun 17, 2009

Salt Fish posted:

With all that we know about NSA's hardware and software capabilities this is a super naive assumption. It's extremely likely that there are entire IoT botnets out there that have compromised control servers ready to be used by a variety of nation states. I would bet both of my testicles against a sandwich that at least 3 nation states have enough ddos capacity to take out the root nameservers.

bruce schneier on this topic

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
yeah when you look at effective wizardwar stuff it's things like wrecking a whole nuclear enrichment plant while making the operators mistrust their computers and equipment

http://www.nytimes.com/2011/01/16/world/middleeast/16stuxnet.html posted:

But as Mr. Langner kept peeling back the layers, he found more — what he calls the “dual warhead.” One part of the program is designed to lie dormant for long periods, then speed up the machines so that the spinning rotors in the centrifuges wobble and then destroy themselves. Another part, called a “man in the middle” in the computer world, sends out those false sensor signals to make the system believe everything is running smoothly. That prevents a safety system from kicking in, which would shut down the plant before it could self-destruct.

“Code analysis makes it clear that Stuxnet is not about sending a message or proving a concept,” Mr. Langner later wrote. “It is about destroying its targets with utmost determination in military style.”

ddos is literally a tool for minecraft children, literally anything else is a better use of resources for wizard attacks

Shame Boy
Mar 2, 2010

fishmech posted:

uh dude, that's exactly the sort of poo poo he was suggesting, by using the utah data center. and why i said "no, that wouldnt really work"

i'm suggesting it because i was specifically responding to:

quote:

I'm not saying that it's necessarily smart or subtle, but as a ham-fisted way of putting pressure on someone I could kind of see the incoming administration looking at it as wizard gunboat diplomacy

ErIog
Jul 11, 2001

:nsacloud:

spankmeister posted:

Probably their account got hijacked because of easy to guess credentials. University email accounts are a popular target for spammers and scammers.

In my experience it's less "easy to guess" credentials and more likely they created an account somewhere random/shady using their uni mail account and the same password as their uni mail account.

edit: wow, forgot to refresh and the convo moved on to nation state DDOS, feel free to ignore this

ErIog fucked around with this message at 01:43 on Jan 20, 2017

Shaggar
Apr 26, 2006
stuxnet was so cool.

fishmech
Jul 16, 2006

by VideoGames
Salad Prong

ate all the Oreos posted:

i'm suggesting it because i was specifically responding to:

the point of doing a ddos is that you do it from all over the place to try to make it hard for your target to avoid.

the utah data center is pretty useless for that, having a bunch of storage and processing power doesn't do anything to improve effectiveness versus taking over 50,000 lightbulbs and 1 million unpatched windows xp installs in china and russia. and obviously the nsa or whoever has access to those sorts of botnets and/or can take some of them over with short notice.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Shaggar posted:

stuxnet was so cool.

Midjack
Dec 24, 2007



Shaggar posted:

stuxnet was so cool.

shaggar was right

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
https://twitter.com/stevebiddle/status/822190488505589760

30 TO 50 FERAL HOG
Mar 2, 2005




lol

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Control the weather with this one neat trick.

Meteorologists hate this!

dpkg chopra
Jun 9, 2007

Fast Food Fight

Grimey Drawer
cloudy with a chance of occasional broadcast storms

Phoenixan
Jan 16, 2010

Just Keep Cool-idge

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

Ur Getting Fatter posted:

cloudy with a chance of occasional broadcast storms

A Pinball Wizard
Mar 23, 2005

I know every trick, no freak's gonna beat my hands

College Slice

Cocoa Crispies posted:

yeah when you look at effective wizardwar stuff it's things like wrecking a whole nuclear enrichment plant while making the operators mistrust their computers and equipment


ddos is literally a tool for minecraft children, literally anything else is a better use of resources for wizard attacks

wizard attacks?

Volmarias
Dec 31, 2002

EMAIL... THE INTERNET... SEARCH ENGINES...

A Pinball Wizard posted:

wizard attacks?

Do you not have the cyber to wizard plugin?

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Cocoa Crispies posted:

yeah when you look at effective wizardwar stuff it's things like wrecking a whole nuclear enrichment plant while making the operators mistrust their computers and equipment


ddos is literally a tool for minecraft children, literally anything else is a better use of resources for wizard attacks

ddos attacks are flatly the most cost effective attack you can conduct, no matter who you are, and they have the bonus of being literally unstoppable if the attack is sufficiently large.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Ur Getting Fatter posted:

cloudy with a chance of occasional broadcast storms

FlapYoJacks
Feb 12, 2009

Ur Getting Fatter posted:

cloudy with a chance of occasional broadcast storms

mods

Trabisnikof
Dec 24, 2005

Salt Fish posted:

ddos attacks are flatly the most cost effective attack you can conduct, no matter who you are, and they have the bonus of being literally unstoppable if the attack is sufficiently large.

Physically cutting the cable is pretty cheap for 100% effectiveness

Midjack
Dec 24, 2007



Trabisnikof posted:

Physically cutting the cable is pretty cheap for 100% effectiveness

so is unplugging the power NOW WHAT BITHC

vOv
Feb 8, 2014

Ur Getting Fatter posted:

cloudy with a chance of occasional broadcast storms

a high of 802.11 degrees

Salt Fish
Sep 11, 2003

Cybernetic Crumb

Trabisnikof posted:

Physically cutting the cable is pretty cheap for 100% effectiveness

This isn't actually true because while the public internet requires open access, physical controls do not.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Salt Fish posted:

ddos attacks are flatly the most cost effective attack you can conduct, no matter who you are, and they have the bonus of being literally unstoppable if the attack is sufficiently large.

yes ddos is cheap, but only really effective against things that need to be on the internet

so minecraft servers, jeez wheat for enterprises, etc. can be ddos'd effectively

something like an nuclear industrial facility can't be effectively ddos'd into making the nation more amenable to a treaty forbidding nuclear capabilities long-term because it shouldn't've been online in the first place

crazysim
May 23, 2004
I AM SOOOOO GAY
wasn't there some use of the great firewall by china to perform a ddos on some undesirables or was that just proto-mirai? i'm probably just confusing something. it's not nuclear i guess.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

crazysim posted:

wasn't there some use of the great firewall by china to perform a ddos on some undesirables or was that just proto-mirai? i'm probably just confusing something. it's not nuclear i guess.

yeah i think it was blasting github and nytimes for having the temerity to let people in china read a particular newspaper?

Trabisnikof
Dec 24, 2005

Salt Fish posted:

This isn't actually true because while the public internet requires open access, physical controls do not.

True you have to rent a backhoe or be like the Bay Area snipper and just know when fiber is above ground

ate shit on live tv
Feb 15, 2004

by Azathoth

Trabisnikof posted:

True you have to rent a backhoe or be like the Bay Area snipper and just know when fiber is above ground

while those are more effective attacks. physical access is a hell of a lot harder then internet ddos.

Shame Boy
Mar 2, 2010

fishmech posted:

the point of doing a ddos is that you do it from all over the place to try to make it hard for your target to avoid.

the utah data center is pretty useless for that, having a bunch of storage and processing power doesn't do anything to improve effectiveness versus taking over 50,000 lightbulbs and 1 million unpatched windows xp installs in china and russia. and obviously the nsa or whoever has access to those sorts of botnets and/or can take some of them over with short notice.

yes i know you're kinda missing that but it's fine because it's dumb anyway whatever


I had a friend do this to an air force base once and he got a very scary visit from a super angry military guy within a week

Shame Boy
Mar 2, 2010

Cocoa Crispies posted:

something like an nuclear industrial facility ... it shouldn't've been online in the first place

787_aircraft_network_diagram.jpg

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Munkeymon posted:

android kinda does that as of whenever they rolled out that material design stuff I think

idk if it still works that way if you ask for an old api layer because I bet older apps would just poo poo themselves because android

can confirm that before it sent all my data to china, android asked for authorization first to access the photos, then to access the camera before i took a selfie to change into animu.

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

fishmech posted:

the point of doing a ddos is that you do it from all over the place to try to make it hard for your target to avoid.

it's so much the point that it's the first d of ddos.

  • Locked thread