The Mirai Botnet Was Part of a College Student Minecraft Scheme
wired.com
wired.com
This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this. What basis did he have for such an assumption?
I don’t understand why every single cyberattack is immediately blamed on Russia or China. It’s an intellectual embarrassment, and especially worse when it’s coming from experts within the community rather than politicians in congress.
But I’m sure the DNC hack was the work of an advanced nation state. Probably had nothing to do with sharing passwords like runner123 over email...
https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...
Schneier has been around for a long time, knows the industry well and has made significant contributions. Not everyone get's things right all the time including Schneier.
Credibility wise he ..
- has a master's degree in computer science
- was awarded an honorary Ph.D from the University of Westminster in London
- is chief technology officer of BT Managed Security Solutions
15 publications, 6 notable books -
- Applied Cryptograph
- Cryptography Engineering
- Secrets and Lies: Digital Security in a Networked World
- Beyond Fear: Thinking Sensibly About Security in an Uncertain World
- Liars and Outliers: Enabling the Trust that Society Needs to Thrive
- Data and Goliath: The Hidden Battles to Collect Your Data and Control Your World
Reference: https://en.wikipedia.org/wiki/Bruce_Schneier
>China or Russia would be my first guesses
Why? If this is just based on it being a massive attack, then there's no basis to automatically blame China/Russia. Have you not noticed this trend? Every time there's a big attack or new strain of malware, it's always China/Russia/North Korea, and that finger pointing is before any concrete evidence?
Honestly, it's xenophobic and will cloud judgement as you'll be looking for evidence that it is China/Russia/North Korea rather than looking for facts.
Even if there's a good chance it is them, should we not believe in innocent until proven guilty?
Occam's razor? If the majority of large, coordinated attacks and malware come from those countries it seems reasonable to suspect them initially, doesn't it? He said they were "guesses". He straight up told you he was speculating. That's not xenophobic, that's statistical probability.
> Even if there's a good chance it is them, should we not believe in innocent until proven guilty?
Yes, but if no speculation is allowed until after a conviction then how would anyone ever be investigated? We would never be able to accuse anyone of anything!
Not really, just because attacks come from a certain country domain does not mean that said countries government is sponsoring said attacks. Even the CIA/NSA use hijacked foreign servers for their operations, that's why attribution of this stuff is so difficult.
I'd also be interested in how you define "large and coordinated attacks" because if you track by something like Norse Attack Map [0] then your Occam's Razor would suddenly point at the US, at least right now.
> Yes, but if no speculation is allowed until after a conviction then how would anyone ever be investigated? We would never be able to accuse anyone of anything!
There's a difference between "speculation" and flat out misrepresenting the probabilities. At this point, it should be pretty clear, especially to any expert in the field, that the Internet is a massive force multiplier and the regular rules of "You need big influence to have big impact" have pretty much never applied to it.
People need to account for that in their attempts at attribution instead of going the lazy route of blaming "The axis of evil" for it, which this lazy China/Russia/NK attribution basically boils down to.
Companies seems to love to throw "state sponsored" around because it sounds better to imply that you were so secure that only North Korea, Russia or China had a chance and at that level of attack (by such a state that openly challenges USA so often) it's not your fault you got breached because it's implied everyone would be. Equifax ran outdated Apache Struts for a few days after a patch and information about the vulnerability was out and now China is being pointed at with really flimsy (IMO) evidence[0].
On the other hand no one probably wants to defend China, North Korea and Russia and it sounds much cooler to be fighting against their state hackers than script kiddies and saying that all these "high profile state attacks" were script kiddies is basically shitting on the security industry in a way.
[0] - http://www.dailymail.co.uk/news/article-4937010/Clues-sugges...
Somebody with his experience should know better than to throw guesswork attribution haphazardly around like that (at least not without a very big disclaimer), especially in a climate that was, and still is, pretty hawkish on "cyberwar turning hot".
Because it's exactly his experience and prestige which gives the uninformed the impression that his "Russia/China" attribution was based on something solid, and not just mere guesswork without any basis on evidence at all.
* He has a masters degree.
* He wrote a bunch of popular books, and reaped a lot of fame from them.
I work, part-time, in the cryptography space his best-known books cover. His most popular book, Applied Cryptography, is not well regarded in the field. Opinions differ on Cryptography Engineering --- I like it a lot --- but he's a coauthor on that book, alongside a practicing cryptographer of significant renown. The rest of those books are non-technical.
I've worked in security since the mid-1990s, and Schneier has been a presence in the industry that whole time. And his Mirai attribution is far from the dumbest thing he's had to say.
I want to be careful because I'm sure Schneier is very good at what he's good at. My concern is that in addition to that --- without intending to be --- he's also insidiously "famous for being famous", and that his takes on things like DDoS attribution are thus taken more seriously than they should be. There are HN commenters that I think have more reliable takes on what's happening in the computer underground than Schneier.
He should write HN comments rather than pieces that get syndicated into magazines. He'd be an excellent HN commenter. :)
† (You might add that he's a co-author of some well-known cipher and hash designs, and IIRC the sole author of Blowfish, his best-known design. [Don't use Blowfish.])
On the book front, would be keen to gain your perspective on the following crypto book that was recently published -
Can you name them?
That‘s nothing to be ashamed of, I‘m sure he didn‘t just do it for the fame, but because he wanted to make things better. I still think he‘s a better cryptographer than writer, but he really seems to enjoy writing.
But it feels uncomfortable when people misunderstand his role.
(And he lost some of my good-will and admiration when he ridiculed Randall Munroe‘s comic and didn‘t have it in him to post a correction for what was basically him not reading the comic, but projecting something he already had in mind. That happens to everyone, it‘s a bit embarassing and not really bad, but sticking to it when he knows full well that the masses trust him is inexcusable.)
Sure, but he wouldn’t get paid very well for that.
He has been working for IBM since they acquired Resilient Systems where Schneier was CTO.
> This looks especially foolish now. Schneier is a so-called expert who has testified in front of congress. He should be more careful when engaging in rampant speculation like this.
Perhaps by being not a native speaker of English and not living in the USA I miss some cultural subtleties, but I would call Bruce Schneier's statement really cautious:
- He clearly states he does not know who is the culprit (really cautious - as it should be!)
- He clearly states that his statement is based alone on feeling
- He rather clearly outlines that his guesses for China or Russia are based on the correctness of the assumption that a national state is behind it
Speculation without merit, only going by "first guess" should not be shared.
If you are an expert, your opinion (even offhand) carries weight.
I agree - and this is why Bruce Schneier (in my opinion) formulated his statements so cautiously and clearly pointed out the lack of evidence.
Of course people will take action - but this can mean anything:
- Doing undercover investigation to collect evidence whether China or Russia is really behind it or this was a red herring: I would consider this as a pretty good idea under the given circumstances.
- Accusing China or Russia on the world stage that they are behind these attacks: A really bad idea.
But both are plausible actions based on the "prediction" - and I would call the first one actually a good idea under the given circumstances.
Here's the source titled "Someone Is Learning How to Take Down the Internet", dated September 2016:
https://www.schneier.com/blog/archives/2016/09/someone_is_le...
The source paragraph does not mention Mirai at all (nor does the article):
> Over the past year or two, someone has been probing the defenses of the companies that run critical pieces of the Internet. These probes take the form of precisely calibrated attacks designed to determine exactly how well these companies can defend themselves, and what would be required to take them down. We don't know who is doing this, but it feels like a large nation state. China or Russia would be my first guesses.
You should actually read the whole article to get a sense of where he is coming from.
I see it as a minor concern, the major one being "Mirai is the definitive proof that your don't need the means and resources of a big hacking team financed by a government to cripple the internet. 3 kids who want to cheat on minecraft can do it". Sure, we already kinda knew that, but this proof is quite scary.
Do you have a better explanation? I'm all ears. I haven't heard one.
Also technically it's not illegal to leave your car door unlocked, Police just handles it that way. The law demands that the car cannot be misused.
Example here http://www.ahouseonarock.com/chesterfieldhomeinspector/doubl...
People have used these thinking "Someone could break the glass, reach in, and turn the deadbolt to open the door," but it's really not worth the trade-off of "My house is on fire and I can't get out."
By whom?
Where do you imagine these devices are made / manufactured?
>Where do you imagine these devices are made / manufactured?
It doesn't matter. If Chinese, Thai, US, Spanic or Russian company wants to sell their device in Europe they have to comply to CEER (Council of European Energy Regulators) regulations, we need similar regulating body for software. Since we have lamps and phone chargers that don't blow power sockets and don't burn houses, we need software that doesn't blow Internet and burn cables.
If your country does need a make work program, hiring many postal inspectors wouldn't be the worst make work program yet. I think the TSA wins that :P
You could probably hide DoS traffic from a single device by making it very low volume, but if the ISPs coordinate, they still know that the device recently sent packets to a victim of a DDoS attack, making it suspicious.
> The Mirai Botnet Was Part of a College Student Minecraft Scheme
How is this clickbait? All I can see is a summary of what happened. When people say "clickbait", I expect something like:
> Three Boys Sucked At Minecraft. You Won't Believe What Happened Next!
https://krebsonsecurity.com/2017/01/who-is-anna-senpai-the-m...
FBI indictments
> JIIA further participated in a Border Gateway Protocol (BGP) hijacking scheme in which JIIA and co-conspirators fraudulently gained control over IP addresses that were in legitimate use by third parties. JIIA conducted these activities to consolidate and maximize the power of the Mirai botnet. [1]
Uhh what?
[1] https://www.justice.gov/opa/press-release/file/1017581/downl...
The cybercrime hosts stole a ton of space, even impersonating dead people and falsifying documents. Served malware, etc off them
https://www.spamhaus.org/sbl/query/SBL180438
Also stole a ton for abuse/C&C/etc. https://www.spamhaus.org/sbl/query/SBL287709 (check whois names at bottom)
They also hijacked 1.3.3.0/24 to announce 1.3.3.7/32 (you can guess why).