Nine-year-old kids are launching DDoS attacks against schools
bitdefender.com
bitdefender.com
Because telling adolescents that they aren't allowed to learn about something has an astounding success rate.
Holy moley.
Even if that were possible, do they think child groomers will have an issue using an "illegal" E2EE service?
It's got an amazing success rate; at motivating them to learn the exact thing you don't want them to.
In reality, the school systems are likely just really old/awful and need to be updated with some basic protections before something bad does happen. The school children should be encouraged to perform responsible disclosure and to request permission before testing something.
The only "solution" for DDoS attacks is to buy a dedicated DDoS protection service or upgrade your bandwidth to the point that the strength of the attack cannot saturate it. This is very expensive and isn't where schools should be spending their money.
A decent ddos attack, even ones that you can buy for 20 dollars on the clearnet, is going to overwhelm the most optimized code base since it will disrupt most of the average data centers, regardless of the rate limiting that you try to make happen on the box itself.
at least in my experiences and from the things I was forced to learn on the fly for some time.
Nor is their mitigation.
I honestly wouldn't brag online about my software being vulnerable to… 9 years old script kiddies!
Not perfect but it would probably stop these kids.
The fact that it is not easy or cheap to mitigate DDOS on your own, while it's become surprisingly cheap and easy to launch such attacks, is much of the reason for that.
Most of the Web that's not megacorp owned or behind CloudFlare (or similar) only isn't constantly falling over because it's not being targeted, not because defending against DDOS is super-easy and cheap and so they're all well-protected.
If we're entirely honest, they say 'DDoS' but likely mean an application layer DoS. Half these websites run on Moodle [1] or similar, which can be super slow because everything run through a database. I know for example that Moodle can be easily overloaded by students refreshing their pages on exam results day [+]. All an attacker needs is wget/curl in an infinite loop and it can be enough to knock some of these servers offline.
> The only "solution" for DDoS attacks is to buy a dedicated DDoS protection service or upgrade your bandwidth to the point that the strength of the attack cannot saturate it.
Sure, but even then there is more that can be done is this space. Most of the UK's education internet runs via JANET [2] which even boasts DDoS protection.
> This is very expensive and isn't where schools should be spending their money.
Well this is where the likes of GCHQ should be helping to secure infrastructure/businesses rather than constantly trying to backdoor it.
[2] https://www.jisc.ac.uk/janet
[+] A workaround for the exam results day DoS was apparently to put people in a waiting queue. It worked, but felt quite hacky and would be easily overwhelmed.
This is akin to ripping down all the posters in the hallway. It's not a thing to be thankful for - it's a thing assholes do.
I love articles that warn about the dangers of doing something while also providing a helpful starting point for those just now realizing that this was an option.
I get that this is technically against the letter of the law, but I think the NCA's stance that this will lead to a life of crime is a gross overreaction. Investing more in the software would probably a better use of resources anyway.
ETA: Also, invest more in the kids! Likely, they're interested in programming and they have no way to learn about it except by becoming script kiddies. Don't tell them "NO!", offer CS classes or some such. I think I was lucky my high school offered AP computer science in this regard.
This seems to be part of the campaign too, based on the article.
"More than doubled" could be from 1 in 2019 to 3 in 2020. The "study" that it links to [0] doesn't mentionhow many there were in 2019 or 2020. I'm really curious how many there actually were to roll this out nationwide in primary and secondary schools?
[0] https://www.nationalcrimeagency.gov.uk/news/rise-in-school-c...
I don't think online games and mods are the gateway drug to a life of crime.
Those trojans sound iffy, but the article is somewhat light on details.
Personally I'd say we just leave kids free to do stupid shit, berate them for doing it and hope they learn something useful from it.
I'll also note that there was one kid who always knew the firewall's password, within a few days of it changing. Never did figure out how that kid knew it so rapidly.
$20 says that kid installed a keystroke logger.
The password was stored in plaintext in the config file on every machine. They kept changing it but couldn't figure out how we'd instantly find the new one.
And the Canadian government did nothing. Better to spend dollars going to court against kids I suppose.
Expect curious kids to try lots of things and push the limits. They do it all the time. In the overwhelming number of kids it does not lead to a life of crime.
My takeaway: Time to lock the gates.
After hacking the school IT systems Sam came to the attention of the police. As part of their engagement with the police, it was decided that Sam would benefit from education on the law through the Cyber Choices programme. They really engaged with the programme so they were offered work experience with a cybersecurity organisation. Whilst there they learnt how their skills could be put to good use and the type of damage their behaviour could have caused. At the end, Sam was offered a paid contract for 4 hours a week during the school term and up to 8 hours a week in school holidays.
https://nationalcrimeagency.gov.uk/what-we-do/crime-threats/...
We teach kids "you should not steal" but not "you should not launch DDoS." I think the latter should be equally educated.
As the person who has been woken up at 3am by a "giant vendor" (read: my employer, who was not giant, but would be considered a "giant vendor" by a 15 year old), it pretty much ruined my week when it happened to me.
Back then, if a school’s website went down (for whatever reason) it had basically zero impact on anything. Schools were offline-first and the website was basically a side project.
Now, everything revolves around the internet and websites. A school’s website going down could be a big deal for a large number of people, including interfering with the education of 100s or 1000s of students, as well as disrupting the lives of all of the parents who have to work around the disruptions.
A DDoS is never really okay or cool, but I’d say that the disruptions are much worse in 2022 than they were in the days when the internet was a novelty.
It would have been nicer if they had shown a bunch of kids of all races.
Note: I'm not black myself, just found that curious.
I bet you woldn't have commented if they showed a white kid. So why does it matter to you if they show a black or a white kid? Why does it make a difference to you?
That's an easy answer - majority vs minority.
If you show an image of a person from the majority then obviously it makes no difference. However, if you single out a minority, any minority, it seems like an obvious statement.
We got internet when I was 9. By the time I was 11 in the early 2000s, I was a full-blown script kiddie, scouring astalavista.box.sk for tools and scripts to hack anything that I could. I'd also hang on IRC. I thought hacking was the coolest thing ever, and took any opportunity to access anything forbidden or leave a silly signature anywhere. I didn't discriminate. It didn't matter that I had zero connection with any of these websites and services I 'hacked', I thought I was so cool.
Most of the stuff I did was simply following the instructions / tutorials, mostly Google dorking for strings in php files and using documented exploits. I never succeeded in any sort of targeted attack, and I lived in such a shithole that nothing important was online at the time, anyway. All of this was extremely low impact.
The only thing even remotely impressive about any of this was that I initially had very poor control of English. I was using a primitive, non-phraseological dictionary all the time, and somehow understood enough to actually apply some of the tutorials I read. People don't give kids enough credit for their determination and persistence, and kids have so much of free time to learn whatever they set their mind to.
Perhaps we should abandon some of the operations, engineering, and design practices that created said house of cards.
It's also rather amazing that there is apparently no warranty for clearly defective software, computing, or networking products and services, and that customers have no remedy when they are harmed by those defects.
David Lightman, a bright but unmotivated Seattle high school student and hacker, uses his IMSAI 8080 computer to access the school district's computer system and change his grades. He does the same for his friend and classmate Jennifer Mack.
The article really doesn't say.
I've heard it's cheaper and easier than ever before to buy a DDoS attack, and if the DDoS is at a rate of >1Gbps and the school has a 1Gbps connection, there isn't much you can do.
(For website protection, you can use CloudFlare etc. For your network, you pretty much have to wait it out.)
As it means that your service is interrupted.
Which in pandemic times can mean your teaching or tests might be interrupted.
Or just your ability to pass in your homework.
Or to know if your class is cancelled/shifted to remote.
Etc.
It's like saying someone should have "invested in home security and better locks" when someone chops your door down with an axe.
Like yeah you COULD have bought a solid metal door (and door frame) but thats not a normal ask for most people.
Its sometimes bad to a point where you can accidentally DDoS their system by doing completely normal things.
What it means to be a scholar is to engage in those things that are not supported at all by hardware acceleration in the brain but yield fruit at the end of the day. This is what separates scholars from everyone else, the scholars are so excited by the idea and the vision at the end of that boring tunnel that they can withstand the tedium. But the rest of us like to giggle at 9 year olds ddosing a school. Wow, how did they even do that? Amazing!
It’s so embarrassing to see someone who’s whole model of the world is basically built out surprising/clickbait headlines cobbled together… which is almost invariably a kind of teenage angst dystopian version of the world.