18 ms·
IRC Networks Under Systematic Attack From Governments
- fintler 13y agoDoes anyone have a mobile friendly mirror? The site isn't readable on iOS 7 Safari.
- paraboul 13y agohttps://gist.github.com/paraboul/8844618 https://gist.github.com/paraboul/8844618
- PavlovsCat 13y agoThat's lacking linebreaks, so: http://pastebin.com/LPdkh5R5 http://pastebin.com/LPdkh5R5
- a3n 13y agoIt's sort of not readable on my desktop, the lines extend off the browser. In Firefox I View/PageStyle/NoStyle. Is anything like that implemented on mobile browsers?
- slipstream- 13y agoAs an oper of a small IRC network, I agree with this blog post. Not that i've really ever used quakenet myself.
- valarauca1 13y agoTrying to shut down IRC on the internet feels a bit like the government is running around attempting to cut telephone wires in the hopes it'll get enemy agents to stop communicating, when all it'll really do is annoy a bunch of innocent bystanders.
- dan1234 13y agoIRC is also used as command and control for a lot of malware. Bot-net owners can be disrupted if they can't access the channels their compromised machines are connecting to.
- valarauca1 13y agoTelephone networks can be used to command and control spies too. Does that mean everyone who uses a public platform uses it for bad? No a subset of all users do. I don't see what your comment adds to this discussion other then trying to justify their actions. I can use your logic for a few other examples: Most terrorist enter the country by air travel, we need better airport screening. Some people who cross the boarder illegally don't do so to find a better life, but to run drugs in america. We need better board protection and patrol. Email is very useful to set up worm command and control networks, we should monitor or DDoS public email servers. Your logic can be used to justify basically anything. Its a logically fallacy, the Strawman argument.
- drjesusphd 13y agoThat's actually not an example of a strawman. It's certainly a ridiculous position (X could be used for crime, therefore ban X), but I'm not sure what you'd call it.
- anigbrowl 13y agoIt's called a fallacy of composition.
- drjesusphd 13y agoYou made his point for him...
- Istof 13y agoThis isn't much different then many other things governments do, like the war on drugs for example.
- simias 13y agoTo what end would the GCHQ DDoS IRC servers? What would they gain from that?
- meebi 13y agoAccording to the leaked documents, denial of the targeted users to communicate with each other.
- zecho 13y agoDDoS has also been used to cause netsplits, which can then be exploited to gain access to private rooms.
- meebi 13y agoOn any sensible IRCd this won't happen. Users sneaking in during netsplits will be booted as netriders when the split closes.
- Cthulhu_ 13y agoBasically, jamming communications between internet terrorists / freedom fighters (depending on your stance on the matter)
- ersii 13y agoAnd/or just regular people who chat with each other.
- valarauca1 13y agoEMP'ing the telephone exchange hopping to cut off the bad guys phone calls to each other.
- phusion 13y agoThey wanted to stop AnonOps from enabling the planning and execution of Anonymous operations. They bragged that a month after "rolling thunder" that the same nicknames/operations weren't there anymore. It's hardly effective, mostly childish.
- ahf 13y agoAlbeit unrelated, I wonder when Quakenet is going to realise that SSL for IRC, both server-to-server, but also client-to-server, is a must have in the year 2014, if you are truly care about your users privacy.
- csmithuk 13y agoIt's unfortunately also very CPU intensive which is a big problem for IRC networks which handle stupid numbers of connections at the same time.
- meebi 13y agoCPU load is not the primary issue. SSL on IRC networks for client connections cannot assert that the communication is secure (for example, that all clients in a channel actually bothered to verify the SSL certificate properly). This issue will remain until client verification techniques such as DANE and DNSSEC are widely adopted on for IRC usage.
- ahf 13y agoIt's not true that this is up to the clients authors alone to do this work, and it's not fair for the users to tell them that you are awaiting client adoption of various technology, when the current Quakenet ircd implementation is currently incapable of even accepting SSL connections. Or at least it was, last time I checked. Also, the DANE support in Irssi was announced in September last year and I have only heard of one network where some of its servers have adopted to this technology. Even though there is only one client that currently supports DANE+DNSSEC verification, we still need the (big) networks to start preparing for the support of it, and help us reaching the point where we can secure our user connections even better :-) Having SSL on IRC, even without DANE+DNSSEC, is still better than having no SSL at all.
- pferde 13y agoThis is why I am disappointed that SILC[1] never got off the ground in the mainstream. It could have been an elegant successor to IRC. 1. http://silcnet.org http://silcnet.org
- acd 13y agoI think the government is behaving wrong when it doing the same thing as organized crime that is to run DDOS attacks in order to bring down servers. So when the government attacks platforms of free speech they have a problem with running against the core values of democracy.
- n2j3 13y agoI don't really understand the point of bringing age into their argument ("overly eager teenagers"), but I tend to agree that DDoSing IRC servers is the lowest form of low. Let us idle in peace!
- jerf 13y agoIt is unlikely that "overly eager teenagers" are doing anything other than playing around or engaging in raw, unbacked braggadocio, as is especially the way of the male teenager. It is unlikely that targeting these users, shutting them down, or prosecuting and convicting them will do anything to enhance security, but it will cost the government money, incur an opportunity cost as these resources are wasted while more reasonable (if less sexy) things that might actually have a positive effect are left undone, and, oh, last and most assuredly least from the government's point of view, it may destroy young lives which were quite likely on a track to be otherwise quite productive, computer-savvy citizens. (How many people here can tell tales of early, somewhat-less-than-legal activities before they became productive members of the computer world?) I've phrased it with "probably"s on purpose; every once in a while a teenager will manage to escalate to the "true threat" level. However I think it is likely such a teen will either A: tend to show up by other, more practical measures or B: slip through a crack regardless; it doesn't justify harassing relatively innocent and frankly naive users, for what is probably little more than the purpose of padding numbers to make your enforcement look good by going for cheap, easy targets, regardless of whether that's good for anybody else.
- Cthulhu_ 13y agoIt's more of a play on 'juvenile behavior', as in, Anonymous DDOSes whoever they don't agree with under the pretense of 'FREEDOM!11ONE' or whatever. Speaking of low.
- rcfox 13y agoFreenode has very recently been under DDoS attack[1] and has been dealing with them for at least a year or more[2]. It seems likely that they're getting the same government treatment as Quakenet. Given that Freenode hosts channels for many open source projects, these attacks aren't just annoying bystanders, they're potentially affecting the progress of our technology. [1] http://blog.freenode.net/2014/02/turbulence/ http://blog.freenode.net/2014/02/turbulence/ [2] http://blog.freenode.net/2013/05/the-good-the-bad-and-the-ugly/ http://blog.freenode.net/2013/05/the-good-the-bad-and-the-ug...
- meebi 13y agoMost DDoS attacks directed at IRC networks are not government related. IRC networks have a long and proud history of being one of the most DDoS-prone targets on the internet.
- wcummings 13y agoFor this reason many hosts disallow IRC in their ToS
- baldfat 13y agoTo my understanding to take down an IRC server doesn't even need to be a DDOS (Distrubuted Denial of Service) AKA multiple of computers and connections. One good DoS (Denial of Service) AKA one computer one connection, is all it takes to take it down.
- forgottenpass 13y agoIt's a matter of bandwidth. If a single malicious actor can clog the the IRC server's uplink on the internet facing side of their firewall yes, otherwise no.
- pixl97 13y agoThose are easy to block with a firewall policy. DDOS is the only way to sustain an attack.
- 13y ago
- mschuster91 13y agoI wonder, why DDoS the IRC servers, if you can find out the IP addresses of the "offending" users via /WHOIS and then inject TCP FIN packets to disrupt their connections. After all the NSA has the capability to do very deep going traffic manipulation as proven with Quantum Insert, so why not use it here?
- dewey 13y ago/whois doesn't work if you are cloaking your hostname or just connect via tor/vpn or just some random place. Probably easier to just target the central node.
- mschuster91 13y agoYeah, but how many scriptkiddies use a VPN or apply for cloaks? Next to zero for most of them. Also, I bet my behind that the NSA has epxloits for the most popular IRCd's, so that only tor/vpn are a real problem for them (and besides, even these connections can be shot with TCP FIN injections).
- dmix 13y agoActually the vast majority of script kiddies and "cyber criminals" use VPNs. The problem is that they have a habit of accidentally connecting to servers without always turning on their VPNs. They lack professional discipline, not toolsets.
- corin_ 13y agoOn plenty of networks (it's been years since I was on IRC, so unsure which IRCd's support it, but iirc both Quakenet and Freenode do in slightly different ways) even support host-masking as long as you are auth'd on the network - of course, IRCops could still find out, so a subpoena (or hacking into the servers) could see it, but prevents /whois from telling you at least. (I think some networks even partially hide your IP by default anyway)
- baldfat 13y ago
- dmix 13y ago> Many of the charges being thrown at IRC users associated with the Anonymous movement are now clear to be identical to the actions of the agency itself. The state not only has a monopoly on violence, but also apparently on hacktivism.
- lucb1e 13y agoMeanwhile they censor anyone running Tor internal relays on the same IP by g-line banning them.
- afreak 13y agoTor allows for rampant abuse and is problematic to prevent. Many IRC networks ban it due to this. However, the solution is to make it so if you want to use Tor on an existing that you instead connect via a hidden service address, allowing the IRCd to mark you as a Tor user and then allow channels to stem abuse.
- lucb1e 13y agoI said an internal Tor relay, not an exit node. My IP cannot be abused for irc spam. These Quakenet guys are just against tor. I am also on some blacklist, and while I can still connect to most channels, some don't work anymore. Because of this blacklist I cannot join #help, which is the channel I must connect to if I want to ask them anything, such as which blacklist I'm on. Finally I got a friend of mine to ask them for me and a #help operator /queried me (private chat), but they won't disclose which blacklists they use. Meanwhile I haven't been able to find any, and if I'm on something, I wouldn't know what for. So that's my experience with Quakenet, censorship and non-disclosure of blacklists. Then they publish this and reach #1 on Hackernews? Come on. Bullshit. They don't give a flying fuck about freedom of speech.
- mst 13y agoirc.perl.org doesn't disclose its BOPM config either. This is because when we're getting attacked we want to force the attackers to go to the trouble of trying to connect, rather than being able to filter their set of available client nodes to the ones not blacklisted before attempting to connect. Makes attacks more obvious and makes attackers work harder. Free, volunteer run services sometimes have to make decisions that prioritise being able to deal with problems within the available resources over the well being of the occasional individual user who ends up being caught as a false positive. After all, if the network just got taken down entirely, it can't transmit any speech at all.
- Duhveed 13y ago"We urge the British government to initiate an immediate and thorough public investigation..." And now, for another caricature of British victim speak: "Pardon me, Mr. Assailant, would you be a good chap and ask your right hand to stop beating me thus about the face? It's rather painful and I fear it might ruin my good humor."
- GunlogAlm 13y agohumour* ;)
- jlgaddis 13y agoElsewhere in this thread, blibble linked to a (nearly five-year-old) blog post on quakenet.org entitled "Trust is not transitive: or why IRC over SSL is pointless" [0]. The article presents arguments that I've heard over and over again in the months since the Snowden leaks began. The argument essentially boils down to "we can't achieve 100% security even with SSL, so SSL is useless" and is completely wrong. It also misses the point. The argument in the blog post is that, paraphrasing, since Carol can be MITM'd without her knowledge, everything is compromised. It shouldn't be necessary to utter the phrase "defense in depth" here on HN as I would hope that everyone here is familiar with it. As I commented just six days ago: > I have locks on my doors but that doesn't mean I don't have a pistol next to my bed. Let me say that I'm not familiar with QuakeNet. (For the last several years I've only hung out on Freenode and two private IRC networks -- and I use SSL when connecting to each of them.) Freenode, however, has "NickServ" and the two private networks I use have similar functionality. At the very least, SSL protects my credentials from being "sniffed" when I authenticate to NickServ. Anyone else on IRC can verify that the user with the nickname "jlgaddis" is authenticated and is really me. Since sensitive information is sometimes discussed, that authentication as well as the encryption is critical. Without SSL, it would be much easier to sniff my credentials, authenticate to NickServ using them, and impersonate me on the networks, possibly gaining access to sensitive information that would otherwise not be possible. IRC over SSL is not pointless. If QuakeNet can't understand that and implement basic security precautions, I don't think they have much room to complain about being attacked. [0]: https://www.quakenet.org/articles/99-trust-is-not-transitive-or-why-irc-over-ssl-is-pointless https://www.quakenet.org/articles/99-trust-is-not-transitive...
- blibble 13y agoso we've had a solution to the credential sniffing for 10+ years: our services support AUTH via something very similar to CRAM-MD5. with that out of the way: you've missed the main point, and that is that it's really really hard (I would use the word impossible but I'm not 100% certain) to secure multiuser chat. the sheer number of places that could be compromised is so high, that offering a 'secure connection' (which users associate with actually secure online commerce) is dangerously misleading. we understand the threat model very well, and we recommend that you shouldn't trust us to secure your communications, and suggest something like fish instead.
- TrainedMonkey 13y agoI thought it was clear that those attacks are happening ever since LulzSec was taken down by embedding operative wannabe on IRC.
- vehementi 13y agoIt's pretty disingenuous to downplay attacks vs Anonymous as motivated by them "engaging in such topics with an opinion contrary to that of the intelligence agencies". No, that's not agencies go after Anon. Agencies go after anon because of the actual criminal activity. edit: I'm receiving disagreement downvotes. What's up?
- fnordfnordfnord 13y ago>Agencies go after anon because of the actual criminal activity. Where is the due process? There isn't any. Please tell me which actual crimes that some Anons have committed whose consequences are so critical that it justifies the abandonment of longstanding principles of fair governance, and military action to sabotage IRC operations in order to halt the occurrence of said crimes.
- vehementi 13y agoI mostly agree with you, but my point is this article is misrepresenting the motive behind those attacks as "these people disagree with the government - quick, silence them" which is obviously not what's going on.
- fit2rule 13y agoIsn't it? Where is the evidence that the targets of the government attack have been given due course to defend themselves in an open court of law, with due process, based on widely acknowledged and agreed upon state law? There isn't any. That's why this is a politically motivated attack on speech and little else. If you can't see the fascism from here, maybe you're standing too close.
- vehementi 13y agoEvidence of them being given due process is off topic. We are talking about the motives behind the unlawful attacks on Anon. It is not up for debate that a lot of illegal shit is being done and taken credit for by anonymous members of Anon. That is the reason for the actions, not because of Anon's politics. You can't just say since they haven't located specific Anon members to prosecute for those crimes, therefor there cannot possibly be a reason except "rrrr I need to silence you". That doesn't follow. The DEA raided the known drug den, but since they hadn't conducted court trials first, it could only be because the drug dealers espoused anti establishment political messages!
- adeptus 13y agoWhy the F* don't we have popular encrypted IRC systems yet? This should/could have existed as of 10 years ago..at least. This is a serious question.
- Crito 13y agoServer-Server and Servier-Client SSL is a thing for IRC. Of course if you operate one of the servers then you naturally see everything that goes through it. Any anybody in the same channel sees everything in that channel, since that is the point of IRC. IRC clients typically also support DCC, though I am unaware of what the encryption options there are. There are are other forms of encrypted "IMing" however, if you want secure peer-to-peer text chat you should probably look outside what irssi has to offer.
- stinkytaco 13y agoI'm not really clear how you would encrypt an IRC network? Its very nature is one of wide dissemination. You can use FiSH, but that's really mostly for one to one communication in which both parties are trusted. I suppose you could use it for group chat, but it would become harder and harder the more people that were added (what happens if you trust all of them, but two of them don't trust each other and so on). There are plenty of good options for encrypting real time communication. Encrypting group chat is a much more challenging issue and one could argue it goes against the whole spirit of IRC.
- driverdan 13y agoIs there any actual evidence that QuakeNet is being attacked by governments? Just because they did it in 2012 doesn't mean that's what's happening now.
- ahf 13y agoNo, nobody can easily know this - Quakenet's probably still the target of DDoS. Aren't we getting to the point where we more or less must assume that these kind of things happens? I mean, taking into account all the news we have seen during the past, err, year :-)
- deleted 13y ago[deleted]
- cobookman 13y agoCould we leverage a VPN tunnel over short band radio waves? This would allow us to detect a Man in the middle attack, as well as provide decentralized access. The speeds would be slow, and the network could be 'jammed' but it could work for medium distance messaging.
- jostmey 13y agoWho would work for a government agency like the NSA or GCHQ? Anyone who is intelligent and well-minded must realize that these government agencies stomp on people's liberties in the name of security. I am sure that employees of these agencies come to work every day telling themselves that they are keeping the world safe. But their reassurances to themselves must sound hollow to themselves. I hope everyone working at these agencies realizes that. At least Edward Snowden did.
- shocks 13y agoIt saddens me to think that I once applied and actually wanted to work for GCHQ. Fortunately they told me to "come back when you've graduated" and that was enough time for me to come to my senses.
- beedogs 13y ago> Who would work for a government agency like the NSA or GCHQ? At this point, I think they only hire psychopaths.
- nsxwolf 13y agoWhat's the point of governments attacking IRC? It's wide open for spying.
- diminoten 13y agoI don't understand - is QuakeNet saying it has unique evidence that it specifically has been targeted by DoS attacks perpetrated by GCHQ, or are they guessing it's the GCHQ based on the report done by NBC? Specifically, this line: > as well as wholesale attacks on the IRC servers hosting the network. What is this?
- Datsundere 13y agoSo, these guys are extending on the irc protocol: http://ircv3.org/ http://ircv3.org/