Here's a "philosophical" question with regards to the internet, and perhaps even it's future. Given that a currently anonymous attacker, and likely not a "state" player (i.e. not a governmental entity with almost unlimited resources) has managed to DDoS a single website, does this portend that unless there are significant changes to the way the internet infrastructure works, we are seeing the demise of the WWW?
Kind of like a reverse wild-wild-west evolution, where the previously carefully cultivated academic and company site presence, gradually degenerates into misclick-hell? And the non-technical, non-IT savvy masses, in a bid to escape this all, end up in a facebook-style future where media is curated and presented for consumption (or perhaps in future, facebook-type entities end up with their own wild-wild-west hell)?
I have a strange feeling that we are seeing the decline of a city/civilisation; once you used to feel safe walking out at night, knew everybody in the neighbourhood, could leave your doors unlocked... and now, you don't dare to go down the lane to the left in case you pick up a nasty virus, and if you hear a knock on the door at night/email from DHL, you don't dare to even look through the peephole/preview the JPG!
You are not the first to come up with this idea. This same thought has been posted every year for the past 20 or so years in mailing lists, forums or Usenet (thought lately, not too often to Usenet).
I think prevention should be emphasized. If there wasn't so much garbage plugged into the Internet, there wouldn't be huge botnets to send DDoSes. There are few groups that scan the Internet for vulnerable systems, and rather than compromise them, send notices to the ISPs. In Canada, the CCIRC does this. But they only check IP blocks assigned to Canadian ISPs and enterprises.
Plus, why do so many ISPs still allow spoofing of IPs? It isn't 1999 anymore.
We should start a grass roots group to talk to everyone they meet, and get people to update their OSes, devices, and get rid of crap.
The quickest way to do achieve that would be to hold ISPs legally responsible for any damage caused by their failure to block spoofed traffic from their own network.
I'm not sure how well this would work outside of the U.S. though. Not everyone is as litigious as Americans are.
The latest attack wasn't using spoofed traffic, from my understanding. Hacked devices were directly sending traffic.
And I ask you this, how is an ISP supposed to know if a device is hacked, or for example, is a webcam uploading a stream to a redistribution site. It can take days to chase down all the IPs, even in the US, and get the ISPs to deal with them.
Should not a router be able to this filtering ? Making Internet Exchange Points do it would be even more quicker. Once big IXPs do it smaller would follow suite for the fear being cut-off and eventually ISPs.
Filtering can only be enforced at boundaries where an operator can say "Link N will only/never have traffic for net range foo/16." And it isn't always possible to make strong blanket statements like that.
Netadmins can make those kinds of statements about traffic originating from with their own networks because they set the rules. But at an interconnection the types of networks connecting, and the purpose of the connection might mean there is little meaningful anti-spoofing protection that can be done.
For example: I send a packet to google, it passes from AS 123 through AS 456 to AS 789. How is AS 789 going to tell the difference between a packet from me, and a forgery originating from AS 456?
It cant. One solution would be blackholing AS 456 from AS 789 at the requrest of its members. Hopefully this will teach 456 to stop misbehaving.
Though we do assume that AS wont itself misbehave and send a spoofed packet to one of its member peer and most of time its true.
We have to worry about misbehaving ISPs for which previously mentioned filtering works.
> Netadmins can make those kinds of statements about traffic originating from with their own networks because they set the rules. But at an interconnection the types of networks connecting, and the purpose of the connection might mean there is little meaningful anti-spoofing protection that can be done.
I dont think so. IXP can force peers to provide their IP Space even if its whole internet. At least they wont be able to spoof IP outside of their space. If they do spoof ddos from their own space the above solution would probably suffice.
EDIT: I just realized peer already has to give destination ip ranges. So IXP dont have to force anyone.
Perhaps its the government? Lots of people think all these NSA programs are evil surveillance, could be it's just the glue that has saved us from just this.
I'm personally amazed that people don't get hacked more often TBH... I can't think of any instances where non-technical people have been pwned in my own life.
I personally have a pa55word that I use for sites I don't trust, but the accounts never seem to fall or even falter. It's amazing really.
"Here's a "philosophical" question with regards to the internet, and perhaps even it's future. Given that a currently anonymous attacker, and likely not a "state" player (i.e. not a governmental entity with almost unlimited resources) has managed to DDoS a single website, does this portend that unless there are significant changes to the way the internet infrastructure works, we are seeing the demise of the WWW?"
Kind of like a reverse wild-wild-west evolution, where the previously carefully cultivated academic and company site presence, gradually degenerates into misclick-hell? And the non-technical, non-IT savvy masses, in a bid to escape this all, end up in a facebook-style future where media is curated and presented for consumption (or perhaps in future, facebook-type entities end up with their own wild-wild-west hell)?
I have a strange feeling that we are seeing the decline of a city/civilisation; once you used to feel safe walking out at night, knew everybody in the neighbourhood, could leave your doors unlocked... and now, you don't dare to go down the lane to the left in case you pick up a nasty virus, and if you hear a knock on the door at night/email from DHL, you don't dare to even look through the peephole/preview the JPG!