Skip to content

Comment on Understanding the recent DDoS attack against Read the Docs

Comments

I'd like to see more of a legal response.

First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, harassment, Computer Fraud and Abuse act violation... Maybe a restraining order prohibiting the sale of "smart TV" known to be able to host attacks. Have imports seized by Customs and Border Protection. That would get a manufacturer's attention.

The manufacturer's EULA will not help the manufacturer, because the plaintiff, the party being attacked, is not a party to the EULA at all.

I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort.

Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I think it was in the GamerNexus investigation on the whole LG Tv spying on people IIRC.

That's why GP mentioned "Smart TV".

A random Internet-connected smart plug made by KOCKJAKD and sold on Aliexpress? Almost impossible to catch.

A major brand like LG, with US presence and sold in brick-and-mortar stores? Much more possible. It also makes a much juicier target for lawyers, thus making it much more likely to get sued. And once there is a precedent, other manufactures would be in danger too. Hopefully after losing a whole bunch of money, the manufacturers will start cracking down on those residential proxies.

(Except that discovery is going to be painful. "Use discovery to find out what's on the other end" is easy to write, but in practice it means regular people dealing with bailiffs just because they happen to buy wrong brand of smart TV)

It's much less hard than you think, we just think it's hard because we are engineers not lawyers.

Proxies have limited and expensive bandwidth and couldn't launch a DDoS anyway because incoming traffic equals outgoing traffic. They are innocent here. You need a DDoS software module to make a DDoS.

Fortunately you only need to find a one of the many possible devices to sue. Just winning a couple of these will send a message. The goal isn't the $$$ directly (the lawyers are the only ones who win) it is to send a message that you are forever responsible for your vulnerable devices and so you better make them secure.

The hard part is if any of the devices are from someplace that doesn't have a US (or whatever country they are in) presence. That country my ignore the lawsuit.

If you found, say, four LG TVs running as a DDOS node, you'd have a pretty good case.

  > I agree they they should, but that would be hard before, ... seems like a herculean effort.

  | We choose to go to the Moon in this decade and do the other things, not because they are easy, but because they are hard; because that goal will serve to organize and measure the best of our energies and skills, because that challenge is one that we are willing to accept, one we are unwilling to postpone, and one we intend to win, and the others, too.
So what, they are hard. So are so many of humanity's greatest achievements.

Honestly, these companies win when we buy into the belief that these things are too hard. They're lazy and are just like any of us that make excuses to not do chores or other things that we should. But the reality is that for pursing our civilization forward we should pursue the toughest problems. It is just about will. It'll be tiring. Some will kick and scream, throwing tantrums. But we aren't just any animal, we're humans. We can do literally anything if we decide it's worthwhile.

Importantly, we shouldn't just jump onto the next hype train, we should be passionate, nuanced, and pursue for the sake of pursuit. We don't have to put all our eggs in one basket. We shouldn't. We have enough time, resources, and energy to pursue so much. But as soon as at pretend we live in a finite world we tend to self destruct and fight over constraints we've made up. The universe is limitless, as are our minds.

AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.

Doesn't matter from the point of view of a lawsuit from an outside attacked party.

IANAL, but a harmed party outside of the 'binding arbitration' nonsense might be a way work around arbitration and drag the company into a court.

Exactly, the harmed party is not subject to binding arbitration. The harmed party isn't going to bring someone to court for their bad devices - nobody has enough assets to be worth suing (other than perhaps to compel them cooperate with the discovery process) . However the company that made those devices is worth suing.

Alibaba is an interesting question though - if the device is from China (or some such) it isn't clear what the courts can do...

What do they do that you think is prohibited by a residential ISP contract?

Running a proxy server and running a botnet, at least.

The problem is most of the botnet zombies are in places with very little rule of law like eastern europe/russia/south america/china. It is an exercise in futility and the richest customers just opt to just spend money on more protection than shutting down the zombies.

If the zombie is in the US, hosts like Google or Amazon will take 1+ month to respond.

Then IP-range block those places until they get their affairs in order.

Author here. This attack was extremely broad. I saw parts of this attack come from my own home ISP's ASN, though not my IP thankfully. If we just "blocked those places" there would be a lot of collateral damage. As it stood, we did temporarily bump up rate limiting for the biggest attack ASNs and we absolutely heard from real, regular users about it (Sorry to those affected).

Either it's coming from certain places and you can block those places, or it's coming from everywhere including some that are within your legal jurisdiction.

I'd love to see China and Russia sued for hammering my personal websites for the past 20 years... will it ever happen? Hell no, LOL.

Man, it wasn't until reading this that I realised I could get sexually aroused by the mere prospect of legal / governmental competence.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.