Either that or the cost of attacks will remain lower than the benefit of being able to sell bits and bytes to your adversaries. I do not expect this to be the case, but maybe.
The open, global, semi-anonymous web is what's not going to survive this fight, I'm afraid. I give it 20 more years, tops, and maybe a lot less.
Also IP-level blocks will never be perfect. See Hong Kong proxies. Or people in traded IP ranges classified as coming from another country.
Yes, some relatively slow, difficult, and expensive attacks would of course still be viable. That does not mean that, "it wouldn't change anything in practice."
> escalation through residential connections, existing international botnets
Right—so how are you going to talk to your botnet from outside the target sub-Internet when it won't even route packets you send it, except maybe to some hardened commerce-and-propaganda-only subnet that may have limited or no connection to the rest of the target state/bloc's Internet (and again, even that part existing is a maybe)?
I don't believe a complete separation would ever be possible. We'd have to put banks on the commerce side. But that means every single business entity would also have to have access to them. But most businesses also need access to the other side and will not do perfect separation.
In malware research labs you can find rooms literally painted in two colours to separate the isolated part and prevent joining networks by accident. Normal companies do not care that much. Most single-person entities will just plug both ends into one computer and go on with their life.
Two things that are surprising me in this thread: 1) "there are ways to work around this, so it's completely useless" (yes, that's... any security), and 2) either not a lot of people are paying attention to future-Internet development, as in actual, technical development and research, or they're not seeing what I'm seeing in them, somehow, as, for example:
Even if you physically firewalled every connection into a country all it takes is one little node connected via RF (satellite, HF, etc) dropped near an open WiFi hotspot.
There is nothing that guarantees the Internet will keep working the way it does now, and if an open Internet causes enough problems, it will be reigned in. How it works now is a choice, not a law of nature. I'm not happy about it, but that's just how it is. Either these kinds of attacks won't get much worse, or they'll get a lot worse and something like that will be what happens.
Again, I reckon it's either that or this problem never gets much worse. Given trends, I expect we're gonna lose the open, global Internet.
The real problem is that here, like so many other places in modern society, we've allowed consolidation to proceed far beyond healthy levels - when a single company is responsible for 20% of beef supply, it's time for antitrust action! (Yes, I'm looking at you, too, Internet, Tech, Media, Pharma, Aerospace/Defense, etc. companies...)
Maybe just allow one merger per decade, only available to companies with less than 10% of their market?
I expect the problem to be addressed with technology, treaties, extraditions and putting a lot of people in prisons before the fragility of consolidation is addressed.
The primary problem here is criminals and criminal organizations parading as nation-states. The secondary problem is systems and networks that are insufficiently secured.
Or it will just be home grown criminals doing the same thing.
Further, I think states are likely to use this both to prevent beyond-their-reach nationals from attacking infrastructure and citizens, and to curtail foreign astroturf propaganda efforts.
The ID stuff is something I don't think all states will adopt, but some might, even in Democratic states. I think adjusting backbone routing to allow easy network-wide black holing based on verifiable origin, though, is very likely to become widely adopted over the next couple decades.
awaits with bated breath
Great marketing, Equifax - they created the problem and tried to sell you the fix.
No thanks.
The question is whether the pains we’re currently feeling are enough to cause a change in the industries affected.
That's not the case for cyberattacks. Solarwinds was attacked many months before it was detected, Stuxnet was hidden for years. We have attributed some attacks but not most and attribution often succeeds only years after detection. And the attackers aren't as vulnerable to cyberattacks simply because their economy is "less connected" - for example, North Korea is at the extreme end of that scale and they really don't care much about what exploits you have; you have a digital economy that's wealthy but vulnerable to attacks by those who don't have it.
Considering downthread there are honest suggestions to send special forces after the ransomware gangs, I’m gonna go with “probably not”. That type of denial is pervasive.
The F500 and companies like JBS just need to move essentially dataframes around from automation to automation, but somehow the software ecosystem is still building that with the same tools used to write Google. The next answer is usually “they don’t invest in a security team, clearly,” and I’m waiting for that subthread to kick off, too, to continue the denial.
Software complexity is the enemy, not the malicious actors exploiting it. Fix one, fix the other.
See the recent post on why the Uber app is so large: https://news.ycombinator.com/item?id=25376346
This is a 21st century hot war that we are losing badly.