FBI kicks some of the worst ‘DDoS for hire’ sites off the internet
techcrunch.com
techcrunch.com
You may think that’s what was going in the 60s lunch counter sit-ins, but the question there was the legality of racial discrimination in privately owned restaurants. The court never ruled on the exact issue, made moot by the Civil Rights Act. But there was never any suggestion that sitting-in somewhere where you had no right to be was legal.
I thought the objective of a sit-in was to gain service (not obstruct it)? My understanding is that people of color were not served when they were very willing to pay for and make use of it.
You might say that the long term objective of sit-ins was to gain service, but only inasmuch as "gaining service" fell under the umbrella of "equal rights".
Finally, as a possibly unwelcome aside, I find it somewhat irritating to see civil rights protestors referred to as "people of color". The Civil Rights Movement was about acknowleging shared humanity, not dividing people into groups based on privilege. Also, Americans, dark-skinned and otherwise, participated in these movements. Many sit-ins involved large groups of white people sitting down with at least one black person, so all of them would be refused service. The Civil Rights Movement of the 60s sought allies regardless of race, which is perhaps why it was so successful.
This is rather revisionist.
The term "privilege" in its contemporary usage hadn't been coined then, but if you go back to the writings of early civil rights leaders, it's pretty clear that the purpose was not about "acknowledging shared humanity". It was specifically about liberation of Black people, and the fight to secure equal rights for Black people. It was not uniformly welcoming to "allies" of other races, and in fact, many of its most successful leaders were skeptical at best of support from people who weren't black.
We've since whitewashed the legacy of its most famous leaders, such as Martin Luther King Jr., but even he was a lot less interested in "shared humanity" and non-black "allies". Yes, if you go by popular representation of him today, that's the impression you'll get of him, but as often is the case, the primary sources tell a very different story.
The statement "the Civil Rights Movement sought allies regardless of race, which is perhaps why it was so successful" is only correct if you are referring to the Civil Rights Movement as a retroactive construct: the way that contemporary society has essentially retconned the history of the real civil rights movement. Yes, that depiction of it has been very successful, because that depiction is more palatable and appealing to people who aren't black (specifically: less threatening to white people), and that's why we think of Martin Luther King, Jr. as a milquetoast nonviolent preacher who gave speeches but didn't really step on anyone's toes, instead of the revolutionary, armed radical man that he really was.
Remember though that if the business is unwilling to have you on premises you are trespassing and that is illegal. You can be arrested for sitting in a chair after you are told to leave.
OVH's anti-DDoS (GAME variant) is quite good in my experience for protecting non-web traffic.
The fact you've used computers to magnify the effect of the protest to your detriment is besides the point.
You set up the business, and arranged for automatic scaling ahead of time. This doesn't entitle you to some special protection because you never took into account something like that could happen.
That's the risk inherent to technology. It lets you.scale. Even when you'd rather you didn't.
techcrunch you mean
These DDoS services exist because we have an Internet full of devices that you can trivially take over by logging into them with admin/admin or other default credentials you can find in public lists. As long as these exist there will be people abusing them.
If you want to do something about DDoS the thing that needs to happen is that the number of trivially vulnerable devices needs to be reduced. That likely means thinking about device security regulations and minimum security requirements, probably also vendor liability.
The same approach is used with malware crypters or RATs (remote administration tools, heh).
The idea being that unless you have total domain control, you can't get that file where they want you to put it.
Maybe let some people know their router is f'd.
The World Wide Web was supposed to be a (to some extent) permissionless publishing platform, that means if you are already connected to the Internet via a commercial ISP, as long as the content is legal and the law of your jurisdiction protects the freedom of speech, you don't need anyone's particular approval to run a HTTP server. But now under the threats of DDoS attack, no independent webserver can survive, the only solution is utilizing a centralized CDN / reverse-proxy, and accepts EULA of their choice and theoretically they can modify and censor your traffic arbitrarily. I think decentralized systems such as ZeroNet or IPFS may be a solution, and I hope they can be integrated into a web browser one day.
I think the modern equivalent of gunboat diplomacy fit the term abuse of power rather well, wouldnt you agree?
If you think a country protection its own citizens is "abuse," well, then we'll have to agree to disagree.
I'm pretty sure they went through ICANN, which would absolutely (and should) support taking down criminals and criminal services from the internet, that they control. There are international laws and treaties. I don't think you'll find too many countries who would agree that it's ok to sell DDoS services. There is no legitimate use for them. Are you suggesting that that position is strictly an American one? I tend to think it's a global one...
Long term I expect decentralized domain name solutions to replace the currently vulnerable ones.
Anywhere in the world that these services could exist, they’d still be awful for everyone.
1. Seize servers via an IP address
2. Seize a domain record itself and redirect it
Both of these "attacks" are not possible with Tor hidden services, because a.) there is no IP associated with the hidden service (although Tor in theory is subject to traffic correlation) and b.) there is no domain record that can be redirected unless you actually have the corresponding private key since Tor hidden service addresses are the public component of that keypair.
It’s essentially the same reason you’re safe browsing it.
The issue, however, is that web sites always need to be hosted on a physical server somewhere, and all it takes is one social media account or email that gives away some aspect of your identity or location for them to find it - assuming you’re doing something illegal of course. There’s nothing inherently illegal with hosting TOR sites. :P
That doesn’t mean that shutdowns don’t happen, though. The FBI recently shut down a number of TOR sites with illegal content.
https://arstechnica.com/information-technology/2018/05/fbi-s...
> The takedown stems from an investigation that started no later than last August and culminated in a court order issued Wednesday directing domain registrar Verisign to turn over control of ToKnowAll.com.