Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Claude Code now reads AGENTS.md if there is no Claude.md(claude.com ↗)
    125comments
  2. Android 17 is the first since 3.x to add new APIs without releasing to the AOSP(grapheneos.social ↗)
    176comments
  3. Saving another 100TB of RAM(cloudflare.com ↗)
    33comments
  4. Cloudflare Quick Tunnels(cloudflare.com ↗)
    218comments
  5. Xcode 27.1 Beta Release Notes(developer.apple.com ↗)
    57comments
  6. Cache-to-Cache: Direct Semantic Communication Between LLMs (2025)(arxiv.org ↗)
    11comments
  7. Photon-Emission-Guided Laser Fault Injection Enables RP2350 Secure Debug(ledger.com ↗)
    43comments
  8. Show HN: Cactus Needle 3: 8-29MB automation models can match DeepSeek V4 Flash(cactuscompute.com ↗)
    71comments
  9. How to Write with an LLM(sockpuppet.org ↗)
    237comments
  10. US troop deaths during Iran war exceed Pentagon count by at least four(reuters.com ↗)
    3comments
  11. OpenJev(openjev.com ↗)
    235comments
  12. The first new cat species discovered in 100 years(nationalgeographic.com ↗)
    34comments
  13. Cyclomatic Complexity in C#(ndepend.com ↗)
    8comments
  14. Two parallel neural ectoderm progenitors contribute to the developing brain(newscientist.com ↗)
    50comments
  15. The Implications of Linguistic Illegibility for LLM Security(arxiv.org ↗)
    16comments
  16. From Geometry to Algebra and Back Again: 4000 Years of Papers (2023) [video](youtube.com ↗)
    discuss
  17. C++26: Trivial infinite loops are no longer undefined behaviour(sandordargo.com ↗)
    166comments
  18. Size-Specialized Memory Allocation(go.dev ↗)
    3comments
  19. Minimal Phone 2(minimalcompany.com ↗)
    141comments
  20. How SpaceX streamlined the Raptor engine(construction-physics.com ↗)
    23comments
  21. Warez: The Infrastructure and Aesthetics of Piracy (2021)(archive.org ↗)
    12comments
  22. I vibed a proof of Conway's conjecture(overreacted.io ↗)
    174comments
  23. Inside ZCode: Silently uploading your Git history to the cloud(ferstar.org ↗)
    89comments
  24. A search-and-inference database from scratch in pure Zig(antfly.io ↗)
    16comments
  25. Korea raises data breach fines to 10% of revenue(koreajoongangdaily.com ↗)
    70comments
  26. Cekura (YC F24) Is Hiring(ycombinator.com ↗)
    discuss
  27. Border agents can search cellphones without a warrant or reasonable suspicion(lawandcrime.com ↗)
    130comments
  28. US Military had close call after using AI for hallucinated intelligence report(cnn.com ↗)
    275comments
  29. Mathematicians Build Long-Awaited Graph Sandwich(quantamagazine.org ↗)
    15comments
  30. North Korean nuclear test sets off years of earthquakes(science.org ↗)
    147comments

The Democratization of Censorship

182 pointsby 10y agokrebsonsecurity.com
58 comments
10y agoHN ↗

Ha. I swear this comment was on another post to begin with.

10y agoHN ↗

That's exactly what I'm thinking of. And actually, that's where I meant to leave this comment. I must have had both open in two tabs for copy/pasting the URL and picked the wrong one.

Much less consequential tab-tastrophe than the time I dropped a table in production because I thought I was in my Dev tab. Backups saved my job that day. And I never kept two SQL servers up at once after that day. :-D

10y agoHN ↗

Something very weird is going on - krebsonsecurity.com is resolving to 127.0.0.1 . Could this be an attempt by someone's DNS servers to make the machines in the original attacking botnet DoS themselves?

10y agoHN ↗

I'm seeing the same thing. IIRC it was a mitigation measure by Akamai, perhaps to prevent new bots from joining the attack.

10y agoHN ↗

In the article he mentions that was done before moving from Akamai to Google Project Shield.

10y agoHN ↗

From the post:

I asked Akamai to redirect my site to 127.0.0.1 — effectively relegating all traffic destined for KrebsOnSecurity.com into a giant black hole.

Since Akamai was going to drop the "shields" on the site, instead of smashing the hosting provider with the attack, DNS was pointed at localhost.

10y agoHN ↗

This seems like an ineffectual measure. Instead of giving the domain to the individual nodes in the DDoS. I'd resolve it once and pound the IP until it changes.

With a simple script curling the page and looking at the content to check if it's pointed to the right server. Ignoring unroutable or inane IPs returned by the DNS.

10y agoHN ↗

You still have the "old" (1 day old) DNS records. Try to flush your DNS cache.

10y agoHN ↗

My ISP's resolver has them too. Apparently it's somewhat common for ISP-run resolvers to impose minimum TTLs (the nominal TTL on the record I get is 5 minutes).

10y agoHN ↗

He mentions:

"There is every indication that this attack was launched with the help of a botnet that has enslaved a large number of hacked so-called “Internet of Things,” (IoT) devices — mainly routers, IP cameras and digital video recorders (DVRs) that are exposed to the Internet and protected with weak or hard-coded passwords."

How was the source being compromised IoT ascertained? The only way I could imagine being able to determine that is by looking at the vendor bits on the MAC addresses of the source. But being that IoT devices are generally on a LAN on with some RFC 1918 address you wouldn't have that information. You wouldn't even have the MAC address of the default gateway that routed it.

Can anyone comment on this?

10y agoHN ↗

The only way I could imagine being able to determine that is by looking at the vendor bits on the MAC addresses of the source. But being that IoT devices are generally on a LAN on with some RFC 1918 address you wouldn't have that information.

Your not going to have that even if the device has a public IP unless it is a public IPv6 address on a device not using privacy extensions.

MAC addresses are link local only and are not transmitted beyond their local layer 2 network.

There is device finger printing that you can do on the peculiarities of individual IP stack implementations, but honestly without solid proof or explanations from Krebs, they way he is holding himself out as a martyr over this leads me to not believing sensational claims he's making over the event.

10y agoHN ↗

Yes, and this is old news, actually. We observed the rise of DDoS as a form of censorship in Russia roughly 10 years ago. People usually think that DDoS attacks are mostly used for extortion purposes, but in Russia it was routinely used to suppress some independent news outlets since 2006. Of course, now (since 2014) they have full-blown Internet censorship in Russia, so they don't need it anymore.

10y agoHN ↗

Are DDoS attacks really a problem for journalists getting out information to the public, or are they more so just a problem for journalists who want to distribute content via their own website? Wanting to run a website is reasonable, as it enables journalists to make money on ads as well, but does the inability to run your own website truly hamper free speech?

This seems more like an architecture problem to me, not with regards to the Internet, but with regards to how articles are distributed: by contacting a server who responds with the article. If I really wanted to get some information out, I would upload it to: Google Drive, Dropbox, Amazon S3 and any other free/cheap hosting service I know, and spread the links out on Twitter, Facebook, HN, Reddit, etc. Would it really be possible for any attacker to take down all these services, thus preventing the information from getting out? Or is this more about distributing articles via a web app?

10y agoHN ↗

To be protected against DDoS it sounds like you need to be hosted by Google, CloudFlare, or Akamai. Yet these companies are so influential and critical to the Internet that journalists need to feel that they are free to criticize them.

AFAIK Google Drive, Dropbox, Amazon S3 etc. will drop you in a second with a "we're not getting paid enough to deal with this" error message if you bring a DDoS down on them.

10y agoHN ↗

This is such an important point. And it is exactly why, when we launched Project Galileo, CloudFlare's initiative to protect politically or artistically important work online, we decided it was critical that CloudFlare wasn't the one deciding what was "politically or artistically important." Instead we rely on the input of civil society organizations like the EFF, CDT, ACLU, Access, etc. If one of the partner organizations says something meets the criteria then we have committed to protecting it, for free and no questions asked.

https://www.cloudflare.com/galileo/

We offered to protect Brian's site under Galileo for free. Had he taken us up on our offer, which remains open, I would hope he would continue to be as critical of CloudFlare as he always has been.

And I hope we've established some credibility in not abusing the position of trust we occupy. For instance, when we protected Spamhaus from a large DDoS attack years ago we specifically made it clear we'd never ask them to treat us any differently than any other organization they monitor. And we haven't. And, to this day, Spamhaus remains one of our biggest critics. And they remain a CloudFlare customer.

Here's a talk I gave last year at Blackhat about the risks of ideas being suppressed on an Internet that is increasingly controlled by a small handful of providers:

https://youtu.be/V-Pj0lrr168

It's something we worry about all the time and I'm glad more people are beginning to discuss the risks it poses.

10y agoHN ↗

Does Project Galileo cover political expression you consider problematic though? It's easy to support free speech with which you agree. The real test is whether you support it when it's reprehensible

10y agoHN ↗

This is kind of an oblivious response to

we decided it was critical that CloudFlare wasn't the one deciding what was "politically or artistically important." Instead we rely on the input of civil society organizations like the EFF, CDT, ACLU, Access, etc. If one of the partner organizations says something meets the criteria then we have committed to protecting it

which is in the first paragraph of the comment you're "responding" to.

10y agoHN ↗

Yes. There are lots of things that I personally believe are incredibly abhorrent that use our network. I'm not proud of them, but I am proud that we don't censor them.

10y agoHN ↗

It seems to me that a vast majority of the for-profit DDoS attack sites (https://www.google.com/#q=ddos+booter) use Cloudflare to protect the component of their operations that take the payments to attack people like Brian Krebs, including the one he wrote about that triggered this entire thing (http://krebsonsecurity.com/tag/cloudflare/).

Forget "state sponsored actors", people executing these attacks are just as likely teenagers with a spare $20 that can use these DDoS attack services to execute a serious DDoS attack in minutes, just for the hell of it.

The point Brian is trying to make in this article is that DDoS attackers have become the true censors of the web. By protecting their ability to profit from DDoS attacks, are you protecting their "free speech rights", or are you instead protecting the real censors of consequence here?

I know you take action on malware and phishing attacks being propagated from your service. A lot of us out here in the NOC world struggling to keep the internet running (and now starting to fail at it) would really appreciate it if you added "DDoS attack sites" to that list.

10y agoHN ↗

Would you host openly racist white supremacist content? (E.g., an American Renaissance mirror?) I understand that you believe you're promoting free speech, but I'm curious where your limits actually are.

10y agoHN ↗

The particulars matter, but I don't think you are under any ethical obligation to host 'incredibly abhorrent' content.

While I realize that having an expansive policy regarding acceptable content is laudible what is the argument for being expansive enough to include 'incredibly abhorrent' content?

10y agoHN ↗

That's incredibly impressive, and well done. I'm glad there is at least one organisation out there protecting even the speech they don't like.

10y agoHN ↗

Is that the 'real test'? I think this is an example where the use of the term 'free speech' confuses the discussion.

Free speech can mean 'limited interference by government' (i.e. U.S. First Amendment rationale) and then there is another meaning, 'hands-off editorial policy'.

The two things are related but are not at all the same and I often see the rationale for one being applied to the other. In this case you are suggesting that a non-governmental actor should have a hands-off editorial policy with regard to 'reprehensible content'. To me this is an attempt to apply a 1st Amendment rationale to a private actor, and it doesn't make sense.

I have no problem at all with private entities crafting their own editorial/business policies such that they don't facilitate or participate in enabling 'reprehensible' content/activities. Down thread someone asked if 'openly racist white supremacist content' would be hosted. I hope not and I would not think less of a hosting company that refused to host that content.

It is a mistake to insist that private entities must engage in the same hands-off behavior regarding content and free-speech that we rightly expect of the government.

10y agoHN ↗

When your views are very radical or nonconformist, conservative policies would choose to reject it. Why would a company risk reputation loss for no real gain?

But this argument is the very cause of censorship. If there's a policy of non editorial interference, the problem won't occur, and the conservative company have an argument to fall back on: "it's our policy not to hinder free speech".

10y agoHN ↗

I could also ask why companies would risk reputation loss for hosting 'reprehensible' or 'abhorrent' content.

Your comment also illustrates the confusing notion that a restrictive editorial policy is 'censorship'. The term 'censorship' was once reserved for government restrictions but now is unfortunately wielded as a weapon against the editorial policies of private entities. By neutering the term it makes it much more difficult to talk with clarity about the two different concepts. Government censorship is much more problematic.

Obviously the marketplace ultimately decides if a private entity is making wise editorial decisions. Public discussion of those policies is reasonable but that discussion can't be founded on the unqualified notion that 'censorship' is bad otherwise there would be no room for editorial decisions at all -- which is an absurd outcome.

10y agoHN ↗

Instead we rely on the input of civil society organizations like the EFF, CDT, ACLU, Access, etc.

You still decided implicitly what's politically or artistically important, by hand-picking these groups as authorities. Even more so if you just rely on their input and have the final word yourselves. Not that I personally have anything against these organizations, but ceding power isn't as easy as that.

10y agoHN ↗

Judging by the earlier HN commentary, Krebs was hosted by Akamai.

10y agoHN ↗

Is it common for the hosting company to know which client is being targetted by the DDoS?

10y agoHN ↗

The decentralized nature of the web is critical to it's power for free speech. The whole point is that you shouldn't have to be dependent on a handful of media giants in order to publish.

10y agoHN ↗

I'm not saying free speech isn't important, I'm only saying that perhaps it's not reasonable to expect that distributing information, that is highly damaging to certain parties, can be done free of charge.

The web exponentially decreases the cost of distributing information, but can we reasonably expect it to be zero, always, for any type of information?

Historically, free speech has meant that you can say whatever you want without fear of violence. It has never been synonymous with the right to have your opinions made available to everyone, free of charge.

I think free speech is immensely important, which is why I think it we shouldn't confuse it with the ability to cheaply serve damaging information from a website with 100% uptime.

10y agoHN ↗

The only way to make it not-free in a way that isn't censorship is to make it equally not-free for all information. Otherwise it's a content-based restriction, i.e. censorship.

Historically, free speech has meant that you can say whatever you want without fear of violence.

That is untrue. For example, the government can't tax Democratic magazines and not Republican magazines (or vice versa).

10y agoHN ↗

This is really where I think p2p things like torrents can be a big help. There are obvious drawbacks such as verifying your getting the original version, for example. But if we give up the idea that the creator's website should be the gateway to that information, we have the methods to work around ddos attacks.

10y agoHN ↗

A torrent with one million public keys of the most prominent journalists wouldn't be big (32 MB if we use Ed25519), and would allow them to host their content from torrents with few seeders, without fear of being over-crowded by malicious nodes with wrong data. Of course, we'd have to make sure that this particular public key-torrent is not taken over either, but it's a lot easier to secure a single torrent than to secure the torrents containing all articles of all journalists.

krebsonsecurity.com basically works as Brian Krebs' public key: any information you get from that domain via HTTPS is considered signed by Brian Krebs. But it constitutes a fairly crude PKI system, where the public key is tied to a domain that simultaneously has the job of distributing the signed information. The solution requires a separation of public key and information distribution: information must not be tied to a location, and the location of the public key should differ from that of the signed information.

All in all, I would say that (D)DoS is a problem of the transport protocol, not of the internet. Distributing information of high negative value to certain parties requires a different protocol than serving cat pictures does, which is why the BitTorrent protocol appeared in the first place: to counter the takedown of information (copyrighted content) whose publication is deemed of negative value to certain parties (copyright holders).

10y agoHN ↗

krebsonsecurity.com doesn't use Brian Krebs' public key, it uses Google's public key (and before that, Akamai).

10y agoHN ↗

Democracy isn't separate groups of individuals having —here— total power to take a website, datacentre, even CDN offline. What's actually happened is the consumerisation of weapons of mass destruction.

Glamourising stuff like this isn't useful. Everybody involved is doing something wrong. We should be doing more at network level to remove botnets by removing (reporting then blocking) infected computers and servers. Continuing to ignore them isn't working.

10y agoHN ↗

Seconded. "Super-powered individuals" are the opposite of democracy, whether they are in that position because of jockeying and electioneering, or by buying malware services.

10y agoHN ↗

BCP38 is designed to filter such spoofed traffic, so that it never even traverses the network of an ISP that’s adopted the anti-spoofing measures. However, there are non-trivial economic reasons that many ISPs fail to adopt this best practice.

So, it costs too much to run clean internet pipes.

As the internet is a major part of the economy, as well as access to government (as well as government access to surveillance), it's probably time to regulate ISPs and related players for healthy operation, like water utilities.

10y agoHN ↗

No No No. There are probably ~100K of ISPs, many of them in judicially-weak countries. This will never work. ISPs are not the problem. Its fundamental oversight in routing architecture of internet.

BCP38 is Best Current Practice. Not a protocol requirement. Once it becomes a requirement this will be solved in a week.

The 5 RIRs[1] are the non-profit organizations that allocates IPs and regulates ASNs. I dont know how but we (or the big internet boys) should petition them to force ASNs to fix their routers.

[1]: https://en.wikipedia.org/wiki/Regional_Internet_registry

10y agoHN ↗

No No No. There are probably ~100K of ISPs,

Good point. I was thinking in a US-centric way.

Still, I'd like my ISPs in the US to be the internet equivalent of lead-free water.

10y agoHN ↗

In the current lobbying environment you're more likely to end up with a statutory minimum of lead in your ISP (surveillance, filtering, anti-competitive measures, anti-net-neutrality, etc)

10y agoHN ↗

Kudos to Google for stepping up here! Krebs is a valuable voice of the free internet.

10y agoHN ↗

In other news we now know it at least ~700Gbps to shut down companies hiding behind Akamai.

10y agoHN ↗

When I first saw the headline I thought this was going to be about YouTube Heroes.

10y agoHN ↗

Your migration is interesting, since it now censors me out because I live in Iran. So I can not read your article. Here is my browser capture, for your article, tab 2 for twitter, tab 3 for blogspot, tab 4 is sourceforge, and tab 5 is Nvidia! https://my.cloudme.com/d358b17/Capture