[192239] in North American Network Operators' Group
Re: Death of the Internet, Film at 11
daemon@ATHENA.MIT.EDU (Florian Weimer)
Sun Oct 23 06:16:23 2016
X-Original-To: nanog@nanog.org
From: Florian Weimer <fw@deneb.enyo.de>
To: Randy Bush <randy@psg.com>
Date: Sun, 23 Oct 2016 12:16:13 +0200
In-Reply-To: <m2d1ithygo.wl-randy@psg.com> (Randy Bush's message of "Sat, 22
Oct 2016 12:08:55 +0900")
Cc: nanog@nanog.org
Errors-To: nanog-bounces@nanog.org
* Randy Bush:
>> What does BCP38 have to do with this?
>
> nothing technical, as these iot attacks are not spoofed.
How do you know? Has anyone disclosed specifics?
I can understand that keeping details under wraps is sometimes
required for operational security, but if the attacks are clearly
succeeding, I would have expected those who posted =E2=80=9Cdo something,
now!=E2=80=9D messages at least some pointer to technical details of what w=
as
going on.
Not that the underlying threat will go away until we find a way to
clean up almost all of the compromised devices (and without breaking
the Internet along the way, forever).