{"id":6502,"date":"2017-02-03T13:17:44","date_gmt":"2017-02-03T21:17:44","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/02\/03\/news-331\/"},"modified":"2017-02-03T13:17:44","modified_gmt":"2017-02-03T21:17:44","slug":"news-331","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2017\/02\/03\/news-331\/","title":{"rendered":"How Google Took on Mirai, KrebsOnSecurity"},"content":{"rendered":"<p>The third week of September 2016 was a dark and stormy one for KrebsOnSecurity. Wave after wave of huge denial-of-service attacks\u00a0flooded this site, forcing me to pull the plug on it until I could secure protection from further assault. The site resurfaced\u00a0three days later under the aegis of <strong>Google&#8217;s Project Shield<\/strong>, an initiative which seeks to protect journalists and news sites from being <a href=\"https:\/\/krebsonsecurity.com\/2016\/09\/the-democratization-of-censorship\/\" target=\"_blank\">censored<\/a> by these crippling digital sieges.<\/p>\n<p><strong>Damian Menscher<\/strong>, a Google security engineer with whom I worked very closely on the migration to Project Shield, spoke this week about the unique challenges involved in protecting a small site like this one from very large, sustained and constantly morphing attacks.<\/p>\n<div id=\"attachment_37947\" style=\"width: 523px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-37947\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/02\/menscher-risher.png\" alt=\"Google Security Reliability Engineer Damian Menscher speaking at the Enigma conference this week. Photo: @mrisher\" width=\"513\" height=\"583\" \/><\/p>\n<p class=\"wp-caption-text\">Google Security Reliability Engineer Damian Menscher speaking at the Enigma conference this week. Photo: @mrisher<\/p>\n<\/div>\n<p>Addressing the <a href=\"https:\/\/www.usenix.org\/conference\/enigma2017\" target=\"_blank\">Enigma 2017 security conference<\/a> in Oakland, Calif., Menscher said his team only briefly considered whether it was such a good idea to invite a news site that takes <a href=\"https:\/\/krebsonsecurity.com\/?s=ddos-for-hire&amp;x=0&amp;y=0\" target=\"_blank\">frequent swings<\/a> at the DDoS-for-hire industry.<\/p>\n<p>&#8220;What happens if this botnet actually takes down google.com and we lose all of our revenue?&#8221; Menscher recalled. &#8220;But we considered [that] if the botnet can take us down, we&#8217;re probably already at risk anyway. There&#8217;s nothing stopping them from attacking us at any time. So we really had nothing to lose here.&#8221;<span id=\"more-37945\"><\/span><\/p>\n<p>Ars Technica&#8217;s <strong>Dan Goodin<\/strong> was at the Engima conference and filed this report:<\/p>\n<blockquote>\n<p>&#8220;It took only about an hour for Menscher&#8217;s team to arrive at the decision to help Krebs. A much more lengthy process involved actually admitting KrebsOnSecurity into Project Shield&#8230;A key requirement for admittance is that the person requesting service proves they have control over the site. Because KrebsOnSecurity was down at that moment, Krebs was unable to satisfy this requirement.<\/p>\n<p>Making matters worse, the domain-name system settings KrebsOnSecurity used had been locked to thwart the attempted domain hijacking attacks that regularly targeted the site. That prevented Krebs from showing he had control of the site&#8217;s DNS settings.<\/p>\n<p>Once Project Shield ultimately got KrebsOnSecurity back online, it took just 14 minutes for the attacks to resume.&#8221;<\/p>\n<\/blockquote>\n<p>For more, check out Dan Goodin&#8217;s excellent piece, <a href=\"https:\/\/arstechnica.com\/security\/2017\/02\/how-google-fought-back-against-a-crippling-iot-powered-botnet-and-won\/\" target=\"_blank\">How Google Fought Back Against a Crippling IoT-Powered Botnet and Won<\/a>. And a rolling thanks to Damian (a true mensch) and to Project Shield for deflecting the evil bits.<\/p>\n<p>For more background on the botnet\u00a0responsible for knocking\u00a0this site offline, see <a href=\"https:\/\/krebsonsecurity.com\/2017\/01\/who-is-anna-senpai-the-mirai-worm-author\/\" target=\"_blank\">Who is Anna-Senpai, the Mirai Worm Author?<\/a><\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2017\/02\/how-google-took-on-mirai-krebsonsecurity\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2017\/02\/menscher-risher.png\"\/><br \/>The third week of September 2016 was a dark and stormy one for KrebsOnSecurity. Wave after wave of huge denial-of-service attacks flooded this site, forcing me to pull the plug on it until I could secure protection from further assault. The site resurfaced three days later under the aegis of Google&#8217;s Project Shield, an initiative which seeks to protect journalists and news sites from being censored by these crippling digital sieges.    Damian Menscher, a Google security engineer with whom I worked very closely on the migration to Project Shield, spoke publicly for the first time this week about the unique challenges involved in protecting a small site like this one from very large, sustained and constantly morphing attacks.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[10705,11203,11204,11205,10514,11206,1670,10495,11207,10644,11208],"class_list":["post-6502","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-anna-senpai","tag-ars-technica","tag-damian-menscher","tag-dan-goodin","tag-ddos","tag-denial-of-service-attacks","tag-google","tag-iot","tag-mirai-worm","tag-other","tag-project-shield"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6502","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6502"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6502\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6502"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6502"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6502"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}