Showing posts with label us. Show all posts
Showing posts with label us. Show all posts

Saturday, October 22, 2016

US under cyber attack

SAN FRANCISCO — Eleven hours after a massive online attack that blocked access to many popular websites, the company under assault has finally restored its service. Dyn, a New Hampshire-based company that monitors and routes Internet traffic, was the victim of a massive attack that began at 7:10 a.m. ET Friday morning. The issue kept some users on the East Coast from accessing Twitter, Spotify, Netflix, Amazon, Tumblr, Reddit, PayPal and other sites.
At 6:17 p.m. ET Friday, Dyn updated its website to say it had resolved the large-scale distributed denial of service attack (DDoS) and service had been restored.

DDoS attacks flood servers with so many fake requests for information that they cannot respond to real ones, often crashing under the barrage. It's unclear who orchestrated the attack.
“It’s a very smart attack. We start to mitigate, they react. It keeps on happening every time. We’re learning, though” said Kyle York, Dyn’s chief strategy officer said on a conference call with reporters Friday afternoon.
Internet_outage_map_October_2016
Troubling to security experts was that the attackers relied on Mirai, an easy-to-use program that allows even unskilled hackers to take over online devices and use them to launch DDoS attacks. The software uses malware from phishing emails to first infect a computer or home network, then spreads to everything on it, taking over DVRs, cable set-top boxes, routers and even Internet-connected cameras used by stores and businesses for surveillance.
These devices are in turn used to create a robot network, or botnet, to send the millions of messages that knock the out victims' computer systems. The source code for Mirai was released on the so-called dark web, sites that operate as a sort of online underground for hackers, at the beginning of the month. The release led some security experts to suggest it would soon be widely used by hackers. That appears to have happened in this case.
Dyn is getting “tens of millions” of messages from around the globe sent by seemingly harmless but Internet-connected devices. “It could be your DVR, it could be a CCTV camera, a thermostat. I even saw an Internet-connected toaster on Kickstarter yesterday,"  said York. The complexity and breadth of the multiple attack points make it difficult to fight because it's hard to distinguish legitimate traffic from botnet traffic.
York said one bright spot for the company had been the tremendous outpouring of aid from its customers, competitors and law enforcement. “You guys wouldn’t believe the amount of support we’ve received,” he told reporters.


Effects felt nationwide - Dyn first  posted on its website at 7:10 a.m. ET that it "began monitoring and mitigating a DDoS attack against our Dyn Managed DNS infrastructure."
These resolved towards 9:30 a.m. Then more waves began. "It's been a hectic day," said York. The attack comes at a time of heightened public sensitivity and concern that the nation's institutions and infrastructure could face large-scale hacking attacks. The most recent example has been the release of emails stolen from the servers of the Democratic National Committee, which U.S. intelligence sources say was the work of Russia. The topic has come up frequently during the fall's hard-fought presidential campaign.
White House Press Secretary Josh Earnest said the Department of Homeland Security was “monitoring the situation" but that “at this point, I don’t have any information about who may be responsible for this malicious activity.”
So far Dyn has not been able to ascertain whether the attack is aimed at any specific customer. “We have no reason to believe it is at this point,” said Dave Allen, the company’s general counsel. The attack is “consistent with record-setting sized cyber attacks seen in the last few weeks,” said Carl Herberger, vice president of security at security company Radware.
Disruption - A post on Hacker News first identified the attack and named the sites that were affected. Several sites, including Spotify and GitHub, took to Twitter Friday morning to post status updates once the social network was back online.

Friday, October 21, 2016

US Hacker Attack

http://www.techtechnik.com/wp-content/uploads/2014/11/hacking.jpg

Several of the world's best-known websites were inaccessible across parts of the United States on Friday after hackers unleashed a series of attacks on a company that acts as a switchboard for the internet. The attacks affected access to Twitter, Paypal, Spotify and other customers of the infrastructure company in New Hampshire called Dyn, which processes large volumes of internet traffic.

"The attacks came in waves," Al Jazeera's Rob Reynolds, reporting from Los Angeles, said. "First targeting the East Coast of the United States, spreading then to the other parts of the country and even to Western Europe." "The websites that were disrupted were some of the top names in the internet: CNN and the New York Times, AirBnB, Reddit, HBO ... a whole variety of sites were attacked."

"Dyn is kind of a middle man that directs users to different websites and routes traffic from server to server in a complex way," said Reynolds. The attackers used hundreds of thousands of internet-connected devices that had previously been infected with a malicious code that allowed them to cause outages.

"This type of attack is known as a distributed denial of service attack [DDoS]," explained our correspondent. "They used affected computers to fire requests at the servers of Dyn simultaneously and essentially overwhelm it."

The US under cyber attack
"The complexity of the attacks is what's making it very challenging for us," Dyn's chief strategy officer, Kyle York, told Reuters news agency. York said that at least some of the malicious traffic was coming from connected devices, including webcams and digital video recorders, that had been infected with control software named Mirai.

Security researchers have previously raised concerns that such connected devices, sometimes referred to as the Internet of Things, lack proper security. The Mirai code was dumped on the internet about a month ago, and criminal groups are now charging to employ it in cyber attacks, said Allison Nixon, director of security research at Flashpoint, which was helping Dyn analyse the attack.

Wednesday, January 18, 2012

Stop Online Piracy Act (SOPA) and the PROTECT IP Act (PIPA).


Wikipedia and many other favorite websites were intentionally darkened to protest something called SOPA and PIPA?  Made it rather tough to do any research for your Allen School Online course work I imagine.  It did succeed in raising the awareness about these two pieces of legislation being considered in the US House of Representatives and Senate respectively.  Both bills are nominally intended to combat the very real problem of online piracy of intellectual property.

Through illegal downloads of music, movies, artwork and other copyrighted materials, producers of these items lose billions annually.  The opponents of these bills are not pro-piracy, but they point out that the legislation as written, would provide an unchecked power to industry and government to shut down any website that is even accused of hosting pirated materials.  Your mashup of Justin Bieber and Spongebob Squarepants on Youtube?  That’d be plenty enough for a complainant to get Youtube shut down.  Supporters of these bills, the Recording Industry of America and bigtime TV and movie studios suggest that this is not the case.   Here is a quick primer on the bills and the controversy courtesy of CBS News.  Have a look at it and then share with us in the comments your opinion on the matter.  As online denizens, this legislation has an absolute impact on your life.  Learn, form an opinion and be heard!

On January 18, 2012, a series of coordinated protests occurred against two proposed laws in the United States Congress—the Stop Online Piracy Act (SOPA) and the PROTECT IP Act (PIPA).

These followed smaller protests in late 2011. Protests were based on concerns that the bills, intended to provide more robust responses to copyright infringement (colloquially known as piracy) arising outside the United States, contained measures that could possibly infringe online freedom of speech, websites, and Internet communities. Protesters also argued that there were insufficient safeguards in place to protect sites based upon user-generated content.

Wikipedia
http://en.wikipedia.org/wiki/Main_Page
http://wikimediafoundation.org/wiki/English_Wikipedia_anti-SOPA_blackout

Google joinsthe SOPA movement
http://idealab.talkingpointsmemo.com/2012/01/google-joins-mass-online-protest-against-sopapipa.php

Monday, January 16, 2012

Imagine a World Without Free Knowledge Stop the US Congress!!!


Corporate supporters of Senate 968 (PIPA) and HR 3261 (SOPA) demand the ability to take down any web site (including craigslist, Wikipedia, or Google) that hurts their profits -- without prior judicial oversight or due process  -- in the name of combating "online piracy."
PIPA and SOPA authors and supporters insist they'd only go after foreign piracy sites, but Internet Engineers understand this is an attempt to impose "Big Brother" controls on our Internet, complete with DNS hijacking and censoring search results. Incredibly, many Congress Members favor this idea.
Try to imagine jack-booted thugs throttling free speech, poisoning the Internet (greatest of American inventions, the very pillar of modern democracy), and devastating one of the our most successful industries. Totalitarian, anti-American, massively-job-killing nonsense.
Tell Congress you OPPOSE Senate 968 "Protect IP Act" (PIPA) and H.R. 3261 "Stop Online Piracy Act" (SOPA):
Supporters of PIPA and SOPA: RIAA, MPAA, News Corp, TimeWarner, Walmart, Nike, Tiffany, Chanel, Rolex, Sony, Juicy Couture, Ralph Lauren, VISA, Mastercard, Comcast, ABC, Dow Chemical, Monster Cable, Teamsters, Rupert Murdoch, Lamar Smith (R-TX), John Conyers (D-MI)
Opponents of PIPA and SOPA: Google, Yahoo, Wikipedia, craigslist, Facebook, Twitter, LinkedIn, eBay, AOL, Mozilla, Reddit, Tumblr, Etsy, Zynga, EFF, ACLU, Human Rights Watch, Darrell Issa (R-CA), Ron Wyden (D-OR), Nancy Pelosi (D-CA), Ron Paul (R-TX)
Where does your Member of Congress stand on PIPA and SOPA? (Project SOPA Opera)
PIPA and SOPA Are Too Dangerous To Revise, They Must Be Killed Entirely 
Congress needs to hear from you, or these dangerous bills will pass - they have tremendous lobbying dollars behind them, from corporations experts say are attempting to prop up outdated, anti-consumer business models at the expense of the very fabric of the Internet -- recklessly unleashing a tsunami of take-down notices and litigation, and a Pandora's jar of "chilling effects" and other unintended (or perhaps intended?) consequences.
Don't believe it? Monster Cable has labeled craigslist a "rogue site," earmarked for blacklisting and full-takedown under PIPA -- resale of stereo cables by CL users reduces Monster 's new cable sales. (reddit).
There is still time to be heard. Congress is starting to backpedal on this job-killing, anti-American nonsense, and the Obama administration has weighed in against these bills as drafted, but SOPA/PIPA cannot be fixed or revised -- they must be killed altogether.
Sen Darrell Issa (R-CA) and Rep Ron Wyden (D-OR) are championing an alternative to SOPA/PIPA called Online Protection and Enforcement of Digital Trade Act (OPEN) that addresses foreign sites dedicated to piracy, without disrupting basic Internet protocols, or threatening mainstream US sites like craigslist.
Tim O'Reilly, a publisher who is himself subject to piracy, asks whether piracy is even a problem, and whether there is even a legitimate need for any of these bills.
Learn more about SOPA, Protect IP (PIPA), and Internet Blacklisting:

Sunday, January 15, 2012

US Congress supports SOPA and PIPA/PROTECT-IP.

cispa2



An onrush of condemnation and criticism kept the SOPA and PIPA acts from passing earlier this year, but US lawmakers have already authored another authoritarian bill that could give them free reign to creep the Web in the name of cybersecurity.

H.R. 3523, a piece of legislation dubbed the Cyber Intelligence Sharing and Protection Act (or CISPA for short), has been created under the guise of being a necessary implement in America’s war against cyberattacks. But the vague verbiage contained within the pages of the paper could allow Congress to circumvent existing exemptions to online privacy laws and essentially monitor, censor and stop any online communication that it considers disruptive to the government or private parties. Critics have already come after CISPA for the capabilities that it will give to seemingly any federal entity that claims it is threatened by online interactions, but unlike the Stop Online Piracy Act and the Protect IP Acts that were discarded on the Capitol Building floor after incredibly successful online campaigns to crush them, widespread recognition of what the latest would-be law will do has yet to surface to the same degree.


This link will send you to a website where you can lookup who is Supporting SOPA and PIPA/PROTECT-IP in Congress? http://adf.ly/1dwEei