US airport websites under DoS attack
digital.abcaudio.com
digital.abcaudio.com
> "It's an inconvenience," the source said.
> The attacks have resulted in targeted "denial of public access" to public-facing web domains that report airport wait times and congestion.
> "It's an inconvenience," the source said.
How wildly irresponsible of the editor who came up with this headline.
> Jamming attacks like the one seen Monday morning are highly visible but largely superficial and often temporary
Gee, I wonder why these superficial attacks are so visible, ABC...
I think the last time I used one, it was to find out if there was an airport lounge in a specific terminal.
"Airport Websites Briefly Unavailable" is a much less exciting, but much more accurate headline.
Never assume malice etc
>Representing yourself as a professional while being ignorant is malice.
Being a professional just means you make a living doing it so you’re good enough to get paid. Nothing more, nothing less.
In short, there's no excuse for this from a source that has this level of impact.
The assumption isn't "malice", it's "profit"
Senior official from what agency / organization are making those claims?
> The attacks have resulted in targeted "denial of public access" to public-facing web domains that report airport wait times and congestion
Why would they be doing DDoS on this service?
> Hartsfield-Jackson Atlanta International Airport reported around 10:30 a.m. ET that its site is back up and running and that "at no time were operations at the airport impacted."
And operations are not being impacted...
I hear "Russia" is doing X and at this point I don't believe it without evidence being presented. Anonymous sources are equivalent to saying "some random person says X". Also why would they do anything with not negative impacts.
This isn't much of a story IMO
He also directly states that this group is Russian but not acting on behalf of the Russian government in this case:
> Hultquist said there is no evidence the Russian government was involved in directing this attack.
But more importantly, neither source said anything about the Russian government doing anything here; if you read carefully at most it's a group within the country of Russia, and that's it. In fact Mandiant directly states that there's no evidence the government of Russia directed the attackers.
> Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian[t], told ABC News. That type of attack essentially overloads sites by jamming them with artificial users.
>” Killnet," a pro-Russian hacker group, is believed to be behind the attack, according to Hultquist. While similar groups have been found to be fronts for state-backed actors, Hultquist said there is no evidence the Russian government was involved in directing this attack.
That's not a "senior official"; "official" implies government, that's a company.
Yes, I would like to know the government agency official providing this information.
>” Killnet," a pro-Russian hacker group, is believed to be behind the attack, according to Hultquist. While similar groups have been found to be fronts for state-backed actors, Hultquist said there is no evidence the Russian government was involved in directing this attack.
What evidence supports this? IMO it's coming from that unspecified official. And yes, I think evidence needs to be provided before claims are made. They're just saying "I think it's these guys" ... because?
Mandiants attribution methodology is trivially found on their website: https://www.mandiant.com/resources/blog/how-mandiant-tracks-...
There's mention of a "senior official"
> senior official briefed confirmed to ABC News.
So a source in government confirmed this to ABC (who's that?). Was it just a "could be russia" type comment.
There's a separate person, who's primarily sharing the story:
> Over a dozen airport websites were impacted by the "denial of service" attack, John Hultquist, head of intelligence analysis at cybersecurity firm Mandian, told ABC News.
ABC and many news outlets generally require multiple sources prior to publishing. There's been a lot of stories lately that have the same base source, but they decide to count as "multiple sources" because an official in the government leaks to two different people and those two people confirm. It's called "information laundering"
Anyway, i'd really out of genuine curiosity know how they know this is from Russia. Which agencies are confirming this?
IMO it seems petty and not something a government would do.
By https://news.ycombinator.com/user?id=citilife
Internet actor named "citilife" makes claims about "information laundering".
Who is this individual? Where is the evidence? There should be evidence before such claims are made. What is his name and affiliation? Where can I find this person in the real world? Maybe this actor is wearing a hat? Perhaps it made of sheets of metal? Perhaps tin foil?
To quote the actor to further this inquiry:
>And yes, I think evidence needs to be provided before claims are made. They're just saying "I think it's these guys" ... because?
I think evidence needs to be provided before claims are made. Before "citilife" is just saying "I think it's petty and information laundering". ... because?
I never claimed there was a case of "information laundering", I defined it.
I also am not asserting anything besides what was in that article and inquiring for additional details because the current story doesn't make a whole lot of sense (at least based on the assertion it's "Russia" / "Russian", "hacking" some airline websites via a DDoS attack lol).
No it doesn't, it means 'office-holder'; that may be a public or private office.
How do they know that? I assume killnet does not have a static IP address and doesn't leave it's return address
Killnet has claimed responsibility for similar attacks in the past [1]
The other identifying technique is correlation: if they’re using a network of hacked devices to create a flood of traffic, any previous attacks that saw traffic from those same devices are possibly from the same group. So it’s possible killnet has a public chronology here.
To my mind, the most likely explanation here is the simplest one: airport websites make good testing targets, and Russia doesn’t punish hackers who target non-military resources in the West.
Even then, using your own example: imagine you are testing a malicious system that you built that is hitting a public testing target. Wouldn't you want to link it to anyone other than yourself for when it is inevitably detected?
That said, the warnings about Russia interfering with US infrastructure were flowing a bit before the invasion of Ukraine. Russia would be the first suspect on the top of the list, even barring good threat intel.
They've also done similar attacks before so they were clearly under radar
Read the book This Is How They Tell Me the World Ends: The Cyberweapons Arms Race by Nicole Perlroth. It has a chapter that shows a lot of what has been going on in Ukraine. One quote that stuck with me was a Ukrainian saying you guys (US/West) are next, they are practicing on us.
Don't forget this goes bi-directional. We (the West) aren't idle recipients of what others do to our countries without response and even preventive measures. Granted the main danger is that we basically have a lot more to lose than our self-proclaimed adversaries but that doesn't mean we are helpless.
This has been the conventional wisdom, yes. Just like the conventional wisdom before February was that full scale land warfare between modern industrialized european nations was a thing of the past.
What we’ve seen over the last year invalidates all of that. If they could paralyze Ukraine with a cyberattack, they would have by now. That bodes pretty poorly for their ability to meaningfully impact the US.
Keep in mind, the common attribution of the supply chain attacks across a number of vendors was Russian actors.
Also keep in mind that large scale attacks have typically started with thoroughly unconvincing "Hey Bob check this out" emails with a malicious excel doc.
The point here isn't to say that the Russian government has mastermind hackers, but instead to understand that an actual and effectual attack doesn't need elite skills, just a few gullible people and known exploits on unpatched servers.
I find it far more likely that any world government has the traditional hacks playbook and still get over .500 in most environments they attack without a single novel zero-day.
The attack described in the article is to antagonize, no doubt, but I wouldn't be very fast to describe the abilities of someone based on how they troll people. This is not the same as an assertion of "they are the best hackers", it's more I just don't think this is representative of the actual capability of any state actor, the Russian military included.
This just just some random "senior official" from an unknown organization saying "must be russia"
However, yes, there doesn't seem to be a reason to assert that it is ordered by the Russian state (specific attributions e.g. to a particular agency or individuals have been made for certain operations, but generally it takes a lot of time and is done only in restrospective), it could be just a loose group of activists scattered around the world and sharing just a chat channel, this attack is unsophisticated enough to not require any specific resources or cooperation.
That theory sounds a lot like the argument of “why not just shoot their legs” applied to escalation of force.
That’s not how it works. When you make the decision to shoot, you shoot to kill. And similarly, revealing your cyberattack capabilities through a “warning” attack is highly unlikely from a state based actor.
Flip the incentives for a sec; the group that executed this hack can present it as an "attack on American infrastructure" to their superiors, even though we here in the US know it was 100% ineffective.
In other words, there are good and valid arguments to ( using your words ) shoot in the legs first.
But why? why are the western media doing it ? Are there any connections ?
> there is no indication that any airport operations were affected
[1] https://www.cnn.com/2022/10/10/us/airport-websites-russia-ha...
(My point being it's so easy it probably is 'worth it'? .. Especially after the first time this happens, even if only so you can tell media/bosses/whatever that mitigations have been put in place.)
Airports probably fall under Cloudflare’s “enterprise” tier, which has no billing ceiling (as far as I can tell), even if the bandwidth might be free.
Put another way: I would not want to be the underpaid airport IT guy who has to justify tripling my operational budget because of a DDoS attack that (1) almost never happens, and (2) doesn’t actually affect critical systems.
I've also heard (admittedly, from their competitors, but they turned out to be right about other things) that if your usage gets too crazy they'll encourage you to start paying.
And nb. that 100% of the "self-serve" plans (not the "call us" pricing) specify web traffic, like from a browser. If you're using it for e.g. delivering data to apps you might get away with it, but it's not technically permitted. Again, last I checked.
edit: Should have read the article before shit posting.