Project Shield
jigsaw.google.com
jigsaw.google.com
I didn't know about Project Shield and I think it's an interesting initiative. However, for some reason it leaves me a bit unease (not as much as the idea of being taken down by a 650Gbps DDoS at will!) - not sure what it is, but we might be moving towards an Internet where only the "approved" would have "free" speech.
I really hope ISP naming and shaming takes over, so we can make DDoS a little bit more difficult.
I think naming and shaming would have little impact and whatever impact it did have would be short lived. Consumers tend to have short attention spans and zero long term memory. Take the banking/finance industry for example, were egregious, predatory and at times criminal tactics are par for the course. Banking institutions are named and shamed all the time, yet the Bank of Americas, Wells Fargos and Goldman Sachs of the world still exist.
Also changing a service provider often can be a huge inconvenience for one. For instance, if I were to learn today that my ISP makes DDoS very easy and doesn't care about the issue, I'd have a choice between one or two random small providers I don't know, and two big telecom operators that are already on my "do no ISP-related business with" list due to their annoying telemarketing.
Also, regular consumers have little recourse against large banks for many reasons (e.g many consumers have little direct contact or influence with investment banks), which is who it is up to governments and regulators. ISPs are similar in some ways, but are way more consumer controlled.
"Secure" and "Internet-connected" are generally understood to be mutually exclusive.
They're mainly mutually exclusive in the common case due to lack of adoption of high-assurance techniques for security. Hell, even medium that knocks out low-hanging fruit doesn't usually get adopted. So, the problems we see were an inevitable result for all the mainstream stacks and security tech.
https://krebsonsecurity.com/2016/09/the-democratization-of-c...
503 Service Temporarily Unavailable
shield
So it seems to be running shield, but at least part of the attacks are still getting through? :(
Would be very nice to know what kind of attacks Shield doesn't shield against etc.
https://twitter.com/briankrebs/status/780018241401974784?lan...
I flushed my DNS and it didn't work, then I just hardcoded 130.211.45.45 krebsonsecurity.com in my hosts file and it is working fine.
I may need to retract my comments about Akamai. Apparently 680gbps (or whatever it's at now) is the total amount of traffic the busiest site on the internet can be hosed with before the internet itself poops the bed.
So, you know, we did learn something from this whole saga.
I saw them report a cannon with 1.5tbps capacity (based on multiple sources), wasn't clear they were getting hit by that load though (it looked like 991gbps from what I could gather, which still I didn't know of and is mind-blowing!)
Good...except Google doesn't protect you from such attacks once the US gov deems it illegal. We need a safe, anonymous protocol not the network of X corporation.
IMHO, focusing on Google's actions is not productive. All large corporations need to be watched carefully, and Google is no exception, but their motives are fairly transparent.
The real culprit here is government overreach. This is the core problem that we should be focusing on.
Google along with other parties can contribute to technologies(i.e. end to end encryption) that protect our liberties but this friendship/network sharing proposal seems just wrong to me. They can't stand to MPAA requests, let alone NSA or its friends(i.e. UK's GCHQ).
In live threatening situations you can't trust a corporation not to give your data to the local governmental authorities. I'm not even considering that their network could be hacked or they are simply a rough actor. `Fairly transparent` is not enough. The latest revelations just proved it.
If you can't publish sensitive information there can't be a debate/case for government overreach/abuse in the first place thus the reason why technology became so important.
It shouldn't be impossible to design a distributed network that has a positive feedback loop that makes a DDOS counterproductive, by actually boosting the targeted materials.
Self censorship.
If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. It also makes sense that material one person is spending resource trying to suppress is extremely likely to be interesting to others, so it's not necessarily a bad experience for someone using the Google news.
Obviously, in the short term it's also useful if they can link to a cached copy that is still working. A systemic Streisand effect.
That would actually be a strong incentive to DDOS yourself!
Perhaps sites uprated for having been DDOSed could be marked as such. We already have to make many decisions about the trustworthiness of news sources, so maybe it's just another factor.
I can also see why Google would just like to make DDOSing very hard and make the whole problem go away, rather than the mechanism I'm proposing.
That said, I think there's something gratifying about using an attacker's willingness and ability to commit resource to removing information as a signal about the value of that information. Judo chop!
Then I'll DDoS your already highly-ranked site just to trigger the "untrustworthy" mark for it in the results.
The problem with going social is the infinite capability of humans to game things like that. I strongly sympathize with the desire to "make the whole problem go away" instead.
there's always a social solution if you're enough of a utopian idealist. why do we go to war? isn't there a social solution? can't we all just get along?
technology steps in and makes the ground truth of the situation something incontrovertible and not subject to social disagreement. we need it specifically because we cannot rely on social solutions.
Another mitigation (and there are many DDOS mitigations I'm leaving out here) is duplicating the content at several different locations, which already have their DDOS mitigations in place. So if you really want to be heard, hit Google Plus, Blogger, Twitter, Pastebin, etc. Just copy and paste your message all over the Internet, and it can prove nearly impossible to censor. Bonus points for multiple 'backup TLDs' so you could have:
krebsonsecurity.org
krebsonsecurity.net
krebsonsecurity.io
krebsonsecurity.biz
You only use these in special circumstances like sharing a blogpost with your friend via email.More bonus points for mirroring static posts with Varnish cache on multiple sub-domains like
wwa.krebsonsecurity.org
wwb.krebsonsecurity.org
ww3.krebsonsecurity.org
Even more bonus points for putting resources on CoralCDN:That's how you defeat HTTPS.
Plus, I mean, Google Analytics and various Google-owned ads are already present on tons of HTTPS sites. That's enough to nullify HTTPS due to the XSS potential.
How are you getting Google = American State, though?
> 'End repressive censorship'
These are at odds. One person's (politician's? corporation's?) "propaganda" is another's "Declaration of Independence." How will can you possibly tell the difference?
Every organization has a bunch of people who support the open web.This could be their voice from within Google. PS: I am not from google or a fan boy.Just that never judge a book by its cover.Let this unfurl before we pass the judgement.
Now this is an interesting proposal. A 501(c)3 would need to be unbiased, and also require a large amount of starting capital. On the other hand, a non-profit that strives to protect internet free speech is pretty alluring. I wonder if something like this could be in the next YC fund.
i think Schneier likes this analogy, he has used it before:
https://www.schneier.com/blog/archives/2012/12/feudal_sec.ht...
He then calls for the state and the law to protect us from our overlords; now that was all written before Snowden (the presnowdonian period)
Still nice that google does this hosting + ddos protection work; they could have chosen not to do it.
It's fairly easy to evade attribution, let alone apprehension, if you're a ne'er-do-weller with a broadband connection. You have no option left but to hide inside rich people's castles.
John Gilmore, an American entrepreneur and civil libertarian, once famously quipped that “the Internet interprets censorship as damage and routes around it.” This notion undoubtedly rings true for those who see national governments as the principal threats to free speech.
However, events of the past week have convinced me that one of the fastest-growing censorship threats on the Internet today comes not from nation-states, but from super-empowered individuals who have been quietly building extremely potent cyber weapons with transnational reach.[1]
and also:
But as my friend and mentor Roland Dobbins at Arbor Networks eloquently put it, “When it comes to DDoS attacks, nation-states are just another player.”
[1] https://krebsonsecurity.com/2016/09/the-democratization-of-c...
As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289
* Cloudflare has a growing number of competitors, like Incapsula.
* These services only protect the front-end of the booter websites. These are barebones CRUD apps for managing accounts and typing the IPs you want DDoS'd. It'd be pretty easy to throw that template up on any other server or domain. Most of that whole workflow could be replaced by IRC, Slack, Discord, Skype along with Bitcoin or similar payment methods. As proof, booter sites do still regularly get DDoS'd (usually by exposing their origin server IP or otherwise fucking up configuration) and breached (often exposing the entire user DB and source code) yet pop back up within a few days and still retain most of their customer base.
* They could just move everything to a Tor hidden service, or the equivalent to I2P.
It's the botnet and/or list of IPs and URLs (scripts and shells on compromised servers they planted or paid for access to) that serves the foundation of booter services. If that remains untouched, then the booter can stick around indefinitely.
Cloudflare's CEO reiterates the same points here: https://news.ycombinator.com/item?id=12577690
As for whether they have a moral obligation to stop reverse proxying these sites... I think he makes a pretty good argument for why they should be considered a common carrier. They do forward all abuse reports to the respective hosting providers.
Sure, chase down how they do payment. But ultimately a web front end isn't the thing that makes the payment happen.
The "brochure" argument makes 100% sense to me for something like the distributed web, but not for a dynamic web application. Brochures just sit there and look at you. Brochures don't take payments and process callbacks, and send commands to attack.
In the end you always end up with some sort of a cable or router between you and the website that you want to visit. And these companies provide you with protection of that cable / router.
This opens more doors than the ones that it closes.
And sure, you can just detach from CloudFlare and own your traffic, but overall the benefits of using their service are more than the downsides.
Better security models for internet connected devices is ultimately needed so people can't build these kind of botnets in the first place.
Good. Host a mirror of wikileaks and let's talk.
What are some of the recent examples of this?
So CloudFlare is a service you pay for, and they seem to be hosting every despicable backwater of the internet so presumably they take no stance of the 'goodness' of the site they protect.
Whereas Shield is a free service, but only extended to those who Google deem righteous enough to protect?
I think there's room for both. There could also be room for Google extending it to a paying service, although I'd be surprised if Google would take the brand risk of extending their protection to porn sites etc irregardless of fees.
And of course every time Google stand up and protect sites like KrebsOnSecurity for free, the tech world loves them that little bit more and its a massive PR opportunity miss for CloudFlare.
Of course, every time Google stand up and protect sites like KrebsOnSecurity for free, its a massive PR loss for Akamai who wouldn't/couldn't.
But this site is broken at even modest levels of zoom.
Content hanging off the left of the window and no scroll bar :-(
Ideally, we should use some kind of P2P network against censorship, but such networks aren't mature enough.
BUT, if you consider the other way: China's attack on western sites, then this "shield" is valuable.
I remember no long ago China uses GFW to inject malicious code in some analytics javascript. Then all of a sudden millions of internet users started ddosing Github. It was probably because someone put something Chinese gov didn't like on Github. Github for some reason is not banned in China , but China was using this kind of ddos to force Github to take down the pages it didn't like.
A reverse proxy that connects from the internet to the internet does not need to be neutral. Free hosting does not need to be neutral. Net neutrality is about packets getting between an end user and the core of the internet fairly. This service is in a different area entirely.
As far as private fiber, global search traffic, cached pages, maps, mail and advertising goes, Google already is the core of the internet.