[HN Gopher] FBI confirms it issued remote kill command to blow o...
       ___________________________________________________________________
        
       FBI confirms it issued remote kill command to blow out Volt
       Typhoon's botnet
        
       Author : galaxyLogic
       Score  : 40 points
       Date   : 2024-01-31 21:00 UTC (1 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | bsimpson wrote:
       | The headline makes it sound like they destroyed the equipment
       | somehow.
       | 
       | The article makes it sound like a bunch of consumer-grade routers
       | were infected with Chinese malware, and that the FBI hacked into
       | the hacked routers, logged the malware, and removed it.
        
         | nightpool wrote:
         | It really doesn't. The use of the word "blow out" might be a
         | little sensationalist but nobody would expect it to mean
         | destroying physical equipment, especially when that equipment
         | is in a _bot_ net (i.e. hacked devices that are presumably
         | legitimately owned by someone)
        
         | pimlottc wrote:
         | The Register tends to the hyperbolic, it's their style
        
       | mschuster91 wrote:
       | Disrupting the botnet is so far so good... but what actually
       | needs to be done is that the ISPs need to be notified and the
       | affected customers be disconnected from the Internet until they
       | replace the compromised/out-of-life devices.
       | 
       | Internet access is a privilege, and being a threat to others in
       | this shared space should lead to said privilege being revoked
       | until the threat is gone.
        
         | squigz wrote:
         | Because it's the customers fault manufacturers sell insecure
         | routers that go out of service 2 years later?
        
           | candiddevmike wrote:
           | At some point consumers need to become more computer savvy
           | and responsible netzens.
        
             | sgc wrote:
             | Sounds more like we need a minimum required period for
             | security updates after a device is sold, and other similar
             | measures. It is much, much easier to enforce this type of
             | thing with one manufacturer than with 100k customers, many
             | of whom are elderly and will never be able to do it
             | themselves no matter how much we preach.
        
               | mschuster91 wrote:
               | > It is much, much easier to enforce this type of thing
               | with one manufacturer than with 100k customers, many of
               | whom are elderly and will never be able to do it
               | themselves no matter how much we preach.
               | 
               | They all pay their ISP a hefty "rental" fee for their
               | crap modem. It's only fair to hold the ISPs responsible
               | in such cases.
        
               | sgc wrote:
               | That type of thing is why I threw in "and other similar
               | measures". Of course there needs to be a basic security
               | policy that is developed and enforced, and resellers /
               | lessors should be responsible. We already have plenty to
               | draw from, such as car/appliance recalls, large
               | organization security policies, etc. There is a ton of
               | low hanging fruit that could be easily dealt with quickly
               | if there were political will.
        
               | gunapologist99 wrote:
               | This is how you end up getting forced to be behind their
               | awful DNAT DPI "firewall", which will still be insecure,
               | and you won't have any access to it.
        
             | Arrath wrote:
             | Sounds like an empty feel good platitude for the
             | technically minded to feel superior to the rubes buying
             | crap from manufacturers who put out that insecure crap in
             | the first place.
             | 
             | Yes, everyone could be more responsible about their
             | consumption but why should that free the manufacturers from
             | the responsibility of making competent products to begin
             | with?
        
           | function_seven wrote:
           | No, but those devices are their responsibility.
           | 
           | Car analogies are always fun, so here's one: The catalytic
           | converter on my car is sawzalled off in the middle of the
           | night. I drive around with the missing cat for a couple
           | months. Then I fail a smog check, or get a ticket for loud
           | exhaust. Is it my fault the cat was stolen? No, but I still
           | have a responsibility to everyone else to not pollute (fumes
           | or noise).
           | 
           | If the ISP supplies the router, then of course they should
           | correct it. But if the subscriber brings their own equipment,
           | then they take on the responsibility of maintaining it.
           | Including replacement if it turns out not to be fit for
           | purpose.
        
         | kube-system wrote:
         | > what actually needs to be done is that the ISPs need to be
         | notified and the affected customers be disconnected from the
         | Internet until they replace the compromised/out-of-life
         | devices.
         | 
         | Yes, but a lot of the internet is on a shoe-string budget and
         | managed by someone who DGAF, and connected to an ISP who also
         | DGAF.
        
           | mschuster91 wrote:
           | Yeah, and these people don't deserve to be on the Internet.
           | We also don't let people run cars with bad exhaust stacks on
           | the road, and if police spot violators, they get issued
           | remediation orders.
        
             | kube-system wrote:
             | The world is a big place and a lot of it doesn't work like
             | that.
             | 
             | Global emissions enforcement is just about as good as
             | global internet security enforcement. That's why the
             | internet is full of malware and the earth is getting
             | warmer.
        
         | costco wrote:
         | What if a hospital was disconnected from the Internet because
         | it has some insecure IoT device in it? The truth is that this
         | "enforcement action" will make absolutely 0 difference because
         | these devices were just used as proxies to launch attacks.
         | There are a million other people offering this as a service.
         | 
         | And it was a botnet with "hundreds of devices." That is
         | literally nothing. People who want to live in this world where
         | abuse emails are king and a bunch of Spamhaus type people lord
         | over the Internet always weird me out.
        
           | 2OEH8eoCRo0 wrote:
           | Hundreds is plenty if your objective isn't DDoS.
           | 
           | https://www.justice.gov/opa/pr/us-government-disrupts-
           | botnet...
           | 
           | > China's hackers are targeting American civilian critical
           | infrastructure, pre-positioning to cause real-world harm to
           | American citizens and communities in the event of conflict
        
             | costco wrote:
             | I mean it's enough to make at the most a few thousand a
             | month selling residential proxy plans on crime forums. Not
             | really significant. There are orders of magnitude larger
             | botnets (some 100k, 400k+ in size) you can read about on
             | https://blog.netlab.360.com/.
             | 
             | Edit: I agree it is important to do takedowns. Qakbot,
             | GameOver Zeus, Emotet, Snake, etc all had actual espionage
             | risk / were cumulatively involved in billions of dollars of
             | theft. But this botnet seems sort of irrelevant.
        
           | mschuster91 wrote:
           | > What if a hospital was disconnected from the Internet
           | because it has some insecure IoT device in it?
           | 
           | Give them a remediation time of 24 hours. If that doesn't
           | help, cut them off anyway, as that's the only thing that will
           | force management to give their IT people actual staff and
           | budget. Hospital IT is almost always a shitshow and that
           | won't change until external pressure forces management's
           | hand.
        
         | mindslight wrote:
         | This is a terrible narrative, essentially grease on the path of
         | destroying the permissionless Internet in favor of an
         | environment where every communication is tracked and
         | "accountable". The basic reality is that Internet traffic
         | should be considered hostile noise and Internet nodes need to
         | be resistant to that. That's the crux of the seminal end to end
         | principle and cross-jurisdiction operation (the whole "Inter"
         | part).
         | 
         | Furthermore, taking it at face value, why shouldn't this
         | condemnation apply to the FBI _first_ ? They 've got
         | compromised devices with the out of life software that's
         | causing a _bigger_ problem. So by applying that standard, they
         | should be taken offline first. Which I 'd say highlights a deep
         | problematic assumption in reaching for the blame game, whereby
         | some nodes start to be considered "more equal" than others.
        
         | ahmeneeroe-v2 wrote:
         | As a society we've settled on collective security
         | (army/navy/police) to address outside physical threats. I
         | believe that as our institutions mature we will take analogous
         | steps towards addressing internet/computer security. It seems
         | more obvious to me than making unsophisticated users
         | responsible for their own individual security against highly
         | sophisticated and well-resourced adversaries.
        
           | molsongolden wrote:
           | "Cybersecurity today is like if we'd asked London building
           | owners to install their own anti-aircraft guns during the
           | Blitz."
           | 
           | Just a quote from a friend.
        
         | stonemetal12 wrote:
         | For most non-tech people the only router in the house is the
         | one the ISP provided, forcing ISPs to punish their customers
         | for the ISPs misdeeds is odd.
        
           | jareklupinski wrote:
           | just creating such a crazy situation though, would definitely
           | cause enough media coverage to get something done
        
         | rolph wrote:
         | the option to refuse or indefinately defer, any or all upgrades
         | or updates, should be preserved, until there is some basis to
         | believe, there will be no loss or ransom of function bundled
         | in.
        
         | willmadden wrote:
         | Internet access is not a "privilege". It is a service people
         | purchase.
        
       | sam1r wrote:
       | >>> the FBI sent specific KV Botnet commands to compromised
       | routers to collect "non-content information about those nodes.
       | 
       | This must've been so fun for whomever individual(s) working on
       | this from the FBI.
        
       | dikaio wrote:
       | Not exactly the same but should be mentioned. Chinese use real
       | people's personas for upwork, they contact people asking for them
       | to create profiles under their names and get paid a percentage of
       | income generated.
        
       ___________________________________________________________________
       (page generated 2024-01-31 23:00 UTC)