DDoS Letter to Chairman Wheeler
scribd.com
scribd.com
It's tough to defend the rights of citizens to have their internet-of-garbage devices stay online when those devices are turned into weapons of mass outage.
From the experience I have had with customer/technical support reps at cable companies for basic things like a service outage. I can't imagine them dealing with compromised devices and firmware upgrades or locating IoT devices in customer's home. I don't think they have either the staff capacity or sometimes even the technical skill to do so with any efficiency.
Then there's the potential for false positives or bad data where my connection get s null routed and I have to wait on hold for 45 minutes or an hour to talk to someone who may or many not know whats going on. Then I need to prove that there is no IoT device on my local LAN to a support person who might not even know what a mac address is. This just sounds like a mess.
Why do you say that? AFAIK the devices being infected by Mirai use UPnP to expose themselves so the router probably has no responsibility for the insecurity. It would be great if we could build some sort of immune system into home routers and force IOT companies to pay for it, but that doesn't seem likely.
Short of mass-bricking these devices, any solution is going to be incredibly labor-intensive and expensive.
A command and control connection for a botnet would still need an inbound NAT rule as would the ability to get the IoT device on the LAN in the first place compromise it right? Or am I missing something?
My feeling on this are somewhat mixed; on one hand virtually everyone who owns a modifiable device never makes any significant modifications and doesn't know how to properly secure it to boot. On the other hand, that means that even if manufacturers had no selfish reasons to put in such limitations of their own volition, the natural state for most consumer device markets is going to be to have no modifiable devices available for purchase just because making an unlocked version isn't worth it.
And ISPs often control the routers people are using, so going to ISPs make sense.
http://www.warner.senate.gov/public/index.cfm/2016/10/sen-ma...
Unfortunately it also links to scribd.
* Read all 4 pages of DDoS Letter to Chairman Wheeler.
-------
Their website cuts off the last page of the letter and tells you to download their app to read it.
Here's a starter list: http://www.dwheeler.com/essays/law-security.html . I'm sure that list can be improved on (I'd love to hear about improvements).
Reflection (UDP) and amplification are problems, sure - we could address those as well.
The point here is that “IoT” isn’t the problem. Thousands of traditional servers can do just as much damage (or more) than thousands of IoT devices in a DDoS. You want to stop attacks that bring down DNS? Fix DNS. You aren’t going to be able to legislate away compromise-likely devices and services. That’s an imaginary solution, and likely to exacerbate other issues (IoT privacy).
Look, if the purpose is to stop all DDoS, legislating IoT devices won't solve that problem either.
You seem to be disqualifying a solution to attacks on DNS because it doesn't solve a problem we aren't trying to solve.
I don't get it.
> Why that problem next? The recommendation to tackle this problem next is the topic of discussion. Namely, the DDoS letter to Chairman Wheeler.
The letter inappropriately confuses fixing this recent outage/attack on DNS with preventing IoT devices from being compromised. My proposal (the high level comment) is to fix the problem being discussed by fixing DNS (making it difficult, as a core internet service, from being DDoSed).