2013-03-30

Sergey Brin writes an article on journalism in the Guardian

The übergeek co-founder of Google uses Comment is Free to call out the frequent misuse of hyperbole, bathos and litotes in modern journalism:

While the infrastructure of the internet might not be easy for reporters to understand, simply juxtaposing quotes from opposing sides isn't all there is to journalism. Yes, this was a big attack in terms of traffic directed against one website (approx 300Gbps), but the internet seemed to cope just fine.
Oh, I am sorry; that was actually professor of journalism Heather Brooke writing about distributed denial of service attacks. Easy mistake to make.

Was this actually a problem?

To be fair, Brooke relied substantially on Sam Biddle at Gizmodo for the scepticism. So let's tackle Biddle's questions, shall we?

Why wasn't my internet slow?
If you weren't looking at a CloudFlare-hosted site, you wouldn't have noticed. This attack was very focused in its target. Where it caused congestion was at one exchange, and even then the interruption was very limited.
Why didn't anyone notice this over the course of the past week, when it began?
What makes you think no-one noticed, Sam? Whom, exactly, were you asking? A sudden spike in DNS traffic like this (UDP port 53 packets) is very noticeable to anyone who cares about their networks. It's also not easy to filter until you've identified the IP(s) under attack.
Why isn't anyone without a financial stake in the attack saying the attack was this much of a disaster?
See above; whom are you asking? And your idea of "disaster" is immediate, whereas people acquainted with the daily DDoS attacks of the Net have a very different perspective that involves the potential for a well-resourced attacker to DDoS sites.
Why haven't there been any reports of Netflix outages, as the New York Times and BBC reported?
Probably because the level of any Netflix traffic degradation fell into the usual noise of ISP / Netflix unreliability. If the attacker had been targeting Netflix, it may have been a very different story.
Why do firms that do nothing but monitor the health of the web, like Internet Traffic Report, show zero evidence of this Dutch conflict spilling over into our online backyards?
The botnet controlled by whoever mounted this attack was relatively small. The frightening aspect of the attack was the effective amplification of the relatively small botnet outbound traffic capacity. A more substantial attack with a botnet an order of magnitude greater in membership is quite capable of causing an order of magnitude more of a problem. As more and more of India, Brazil and China come online, sourcing botnet members is only going to get easier.

The technical nitty-gritty

The Spamhaus/CloudFlare DDoS was not notable for the effect of its attack - CloudFlare successfully blocked the attack, mostly because it was relatively easy to identify the malicious traffic. If you're wondering "how so?" here's the detail.

If you imagine the Internet as a virtual version of the Post Office, every data packet on the Internet can be thought of as an envelope with a destination address and (usually) a return address. Envelopes are coloured according to what kind of information they carry. Regular web traffic (HTTP) could be white, email (SMTP) could be yellow, DNS queries could be red. The way that Internet traffic works is that at every sorting office (point in the network) there are rules ("routing tables") that determine how to move any envelope closer to its destination address. Normally these rules don't take account of the envelope's colour, but when sorting offices get very busy they have the ability to control what colour of envelopes they accept; they can for instance hold up deliver of non-time critical yellow envelopes in order to process time-critical white envelopes promptly.

Some bad guys (spammers) have the ability to generate vast quantities of yellow envelopes, threatening to drown the sorting offices in mail, but the sorting offices are given a list of return addresses by firms like Spamhaus which are known to be spam sources; they can choose to throw all mail from those addresses into the trash. Unfortunately, the spammers are wise to this and forge their return addresses to appear to be legitimate, regular folks. They don't care if their messages are returned to the wrong people.

Regular people under the threat of spam can change address to a magic PO Box number, provided by companies like CloudFlare. These PO Boxes are special because the same address exists in many places across the world (an "anycast" address); in the USA, in Europe, in Japan etc. Mail to PO Box 1 sent from the USA or Canada will go to a CloudFlare office in the USA as it's closest; mail to the same address sent from Germany will go to a CloudFlare office in France, and so on. That way, even if lots of spammers send mail to the PO Box 1 address, the mail will be less likely to be concentrated in one place.

CloudFlare's PO Box establishments have dedicated security systems that can be told to throw away certain kinds of envelope as they arrive. In this case, because they are aware that a DNS-based attack on Spamhaus is happening, any red (DNS) envelope sent to PO Box 555 (Spamhaus) which comes from certain sources (the open DNS resolvers) can safely be thrown away before it goes to the company mailboy. Note that this is only possible because CloudFlare knows that Spamhaus does not expect DNS traffic from those resolvers. CloudFlare can't throw away all red envelopes because one of the ways Spamhaus works relies on its clients sending red envelopes to Spamhaus asking for information about a domain ("DNSBL" - DNS Block list).

The threat

If I wanted to cause widespread disruption with an attack like this, my botnets would be targeting tens if not hundreds of IPs; say, the public IPs of UK online banking sites. Even if the open DNS resolvers had rate limiting implemented, they would have significant problems identifying legitimate traffic from botnet traffic since they would appear to be getting requests from many IPs, not just a single IP. I would switch targets frequently, making it harder to build a blacklist of source IPs. I would rent many bot computers on low-speed connections rather than fewer bots on high-speed connections, and aim for geographic diversity to make it harder to identify traffic spikes until the traffic was very close to its targets.

Spamhaus was able to avoid the attack by moving to CloudFlare, taking advantage of their much more robust and distributed hosting system, but this costs money - and even CloudFlare is not invulnerable, if the attack is sufficiently large, distributed and/or difficult to filter. Most online firms will be hosted on the cheapest hosting provider possible, and so will be ridiculously vulnerable to an attack like this. Anyone intent on large scale malice - and I'm thinking of state-level actors - could cause havoc by using a much larger target list selected for public impact.

The open DNS resolver issue is a worry for the Net, but it's a relatively manageable problem - we know where the high-capacity resolvers are, and have some way of being able to squash their traffic in an emergency by blacklisting their IPs, which will annoy a lot of users but at least save the Internet. The real worry is when more households get high-capacity outbound pipes to the Internet (BT Openreach Fibre to the premises, Google Fiber, Verizon FiOS etc.) and black-hat hackers are able to target these households to compromise their computers and turn them into a high-capacity DDoS attack machine. With the current rate of zero-day exploits discovery, and the relatively slow uptake of security patches on home computers, this is a very real and frightening problem. The Spamhaus DDoS is just a taste of what's coming down the pipe.

Stick to writing articles about journalism, Ms. Brooke.

Update: Ars Technica addresses these questions in more detail with similar conclusions - there was some hype, but this is a real problem and could have done serious damage.

2013-03-28

Be careful whom you shoot

Last year, a 15 year old schoolgirl from Swat in Pakistan was shot in the head while returning home from school on the school bus. It seems that certain people objected to the subversive messages she was spreading:

In early 2009, at the age of 11/12, Yousafzai wrote a blog under a pseudonym for the BBC detailing her life under Taliban rule, their attempts to take control of the valley, and her views on promoting education for girls.
Dear Lord, we can't have girls being educated. Who knows what thoughts might enter their heads? So a gentleman from the local Taliban franchise put a pistol to her head and pulled the trigger.

This is the story of Malala Yousafzai (the top Google hit for "malala") and if the Taliban spent any time educating their followers on human biology, the bullet would have killed her right there in October 2012. Unfortunately for their cause, the hitman was chosen more for his pseudo-Islamic zeal than actual shooting talent. Malala was hit in the head but survived, thanks (by my reading between the lines) to a combination of Heaven-sent fortune, personal will to survive, and some top-notch emergency care by the local and national medics. Flown to Britain for surgery to repair her skull, she recovered and is now attending school in Birmingham. I rather suspect that the school has surreptitiously taken additional security measures since unfortunately the UK is still home to too many misogynistic and violent gentlemen from South Asia who might take exception to Malala's very public survival.

Now, Malala has signed a $3M book deal to write about her life and her cause. Given the international outcry over the attack, and support for her cause, I fully expect it to hit the top of the autobiography bestseller charts. As a result, millions of people who would only have heard of Malala in a cursory news story about another fatal shooting in Pakistan will be reading about her life and the state of female education in Pakistan's Taliban-controlled areas. We can only expect more international support and money for such education as a result.

I'm somewhat hoping that the Taliban hitman avoided capture and will spend the next few months being slowly tortured to death by his compatriots for failing spectacularly in his assassination attempt.

2013-03-27

Public goods can also be public bads

Imagine a village in the middle of the woods. The villagers use wood for many of their needs - building houses, firewood etc. - but it's rather tedious carrying axes into the wood to find a suitable tree, and then axing down a tree is slow and error-prone. The village elders, mindful of this, buy a job lot of high-spec chainsaws and distribute them around the wood marked by big red flags. A villager can wander into the wood, spot a handy-looking tree, find the nearest chainsaw, drop the tree in no time and then leave the chainsaw by the flag before pulling his tree back home.

Unfortunately, some of the village youth have a nihilistic bent. One evening they go into the woods, get a chainsaw each, bring them back to the village and chop down the structural pillars of a number of houses before they can be caught and stopped. The village elders are embarrassed that their good intentions in improving village life have been turned on them to wreak industrial havoc. Perhaps leaving high-powered machinery around the woods for anyone to use has its downsides?

This is roughly the situation that the Internet finds itself in currently, as described in CloudFlare's account of the ongoing DDoS that nearly broke the Internet. Anyone with a technical bent should go read the original, for it is a very good (if frightening) piece. For those less technical or with less time, here's the short version.

Spamhaus is a long-existing Internet establishment that does its best to identify email spammers and the machines they use to spam, and feeds data to major Internet Service Providers and other entities enabling them to identify that spam and cut it off early before it overwhelms users' inboxes. They have been very successful at this; the email spam problem today is still substantial but much, much better than it used to be even a couple of years ago. Recently they identified a fairly "liberal" Dutch hosting company "Cyberbunker" as spammers and started including them in their blacklist. It would be safe to say that Cyberbunker did not appreciate this.

Last week Spamhaus was on the receiving end of a big Distributed Denial of Service (DDoS) attack, thousands of compromised computers being used to drown Spamhaus's website in a flood of requests. This was initially very successful. Spamhaus asked for help, and distributed hosting provider CloudFlare stepped in to host Spamhaus. Their defences and capacity could cope with the attack. But this did not stop the attackers, who have raised their game in recent days:

An engineer at one of the largest Internet communications firms said the attacks in recent days have been as many as five times larger than what was seen recently in attacks against major American banks. [my emphasis] He said the attacks were not large enough to saturate the company's largest routers, but they had overwhelmed important equipment.
The attacks have been so big (up to 300 gigabits per second - enough data every second to represent the text of 100,000 novels) that they have started to saturate some of the networking hardware of the Internet exchanges, the entities which "glue" the major parts of the Internet together. If you've been seeing slower-than-usual Internet speeds over the past few days, this may have been part of the problem.

What does this have to do with chainsaws in the woods? Well, the attackers have a lot of computers under their control, but those computers are mostly on regular home Internet connections and can't get near the upload rate they'd need to each 300Gbps. Instead they are sending forged requests to open DNS recursor hosts. These computers, which are the chainsaws in our example, are part of the Internet's naming system - "DNS", the Domain Name System - which translates human-readable names into the numeric addresses used by the Internet. As an example, www.dailymail.co.uk translates into the Internet (version 4) address 23.59.191.33.

Normally these computers are provided by ISPs and serve only that ISP's customers. However a number of them, either by misconfiguration or by design, accept requests from anyone. Worse, a) there are certain queries where a very small request can result in the DNS host returning a large amount of data (the "amplification" problem) and b) it is possible for the requesting computer to forge its sending address to pretend that it's a different computer. The result of this is that a single computer with a very slow link to the rest of the Net can command an open DNS host to send a much larger stream of data to any Internet address it chooses. This is a big problem, allowing distributed denial of service attacks of much more traffic than the compromised computers can send.

I expect that as a result of the Spamhaus attack more work will be done to lock down open DNS hosts, or at least get them to react much more slowly to unknown users. Still, this situation is a reminder that providing public goods can come with unexpected public costs.

Update: a sysadmin with an open DNS server confesses. Well, that's 0.0005 Gbit/s down, only 299.9995 Gbit/s to go.

Do not meddle in the affairs of cats

Technical kudos to Dave Evans for developing a GPS tracker device for his cat's collar:

Mr Evans, 41, said the weatherproof tracker, weighing just 15g, will cost £50 and can be used for cats and dogs. He said: 'My cat was getting fat even though I was feeding him less and I needed to know what was going on.
Now I know he travels a couple of miles each day, exactly where he goes every night and who's feeding him.'
Allowing owners to track where their cats go and from which houses they get additional food? I can't imagine the feline population standing for that kind of interference. I foresee Mr. Evans coming to a sticky end, mysteriously breaking his neck while walking down the stairs. Mr. Evans - move into a bungalow post-haste, and may I advise you to trade in your cat for one of the larger varieties of canine?

2013-03-26

If you wanted RAF SAR you should have bought better choppers

Much wailing in The Guardian today over the news that the RAF and Royal Navy will be handing over UK search and rescue to a private firm:

Bristow, a leading provider of helicopter services to the offshore energy industry, has won a £1.6bn contract to provide SAR (search and rescue) from 2016.
Everyone currently involved in the SAR industry promptly objects to the change. It's not surprising, the change is a very significant one since the RAF and RN have been providing SAR around the UK for 70 years. So why does the Government want to fix what (apparently) ain't broken?

Money is, of course, a primary driver for this - the contract is £1.6bn, for a duration apparently unspecified in the Government press release on the SAR handover. If private cover costs this much, you can bet that RAF/RN cover costs more. The real reason for this change though, and believe me it's a good reason, is buried down in the article:

However, the government has argued that it needs to act because the famous and much-loved Sea King helicopter fleet is approaching the end of its useful life.
The Sea Kings are ancient hardware. The licence-built UK design first flew in 1969 with updates such as the dedicated SAR variant HAR3 delivered in the late 1970s / early 1980s. It's being retired everywhere else in the world, and even in the UK the troop-carrying variant has bitten the dust. There's no way that the current Sea Kings can or should keep going much longer, getting increasingly expensive and difficult to maintain.

But the RAF and Navy have a much more modern medium- and heavy-lift helicopter - the EH101 aka Merlin in UK service. Why not use these for SAR? Well, where the 14,000lb empty-weight Sea King has a regular range of 764 miles and sea level cruise speed of 129mph, the Merlin is nearly 10,000lb heavier, with a 500 mile range albeit a faster cruise speed of 167mph. Cargo carrying capacity is not generally a big concern for SAR roles - as long as it can accommodate crew + around ten passengers this will cover the vast majority of rescue situations. The Merlin is too big compared to the Sea King, and it's really expensive - the RAF bought 44 aircraft for £4.65bn and even though a lot of that cost was set-up and infrastructure you're still looking at the thick end of £30M per bird.

But let's compare it against the replacements that Bristow will use: ten Sikorsky S92s and ten AW189s. The former is an up-rated civilian version of the tremendously successful and widely used UH-70 Blackhawk, weighs 15,500lb empty with a range of 600 miles and cruise speed of 174mph - a lot faster than Sea King or Merlin, slightly less range than the former but a comparable weight, and will set you back about £20M. Spares should be easy to find and running costs low. Specs on the latter are harder to find, but it looks to have a comparable speed and be slightly lighter; presumably there's something about the cost/range/speed tradeoff that makes it a more attractive option than the S92 for certain locations.

Bristow aren't exactly newcomers to the SAR role - they've been operating helicopters to the North Sea oil platforms for decades, which is a sufficiently challenging environment to prepare them well for UK SAR. It's still going to be an interesting hand-over, but there's no reason to think that Bristow will just let random yachting folks drown because of a clause in their contract.

The other nice thing about contracting out this service is that the contract should be very easy to spec out - the variables (weather, range, accidents) are very well known and well-established, and so unless the MoD Procurement idiots have been allowed to write the contract it's not unreasonable to think that they should cover all the major issues. This is not like tendering for a future fighter or helicopter where the requirements are hazy. We know exactly what SAR involves and what's reasonable to expect. If anything, I expect the contract to be too conservative and prevent Bristow from implementing innovations in kit or procedures that would let them reduce operational cost while preserving the same effective service.

2013-03-25

The USA doesn't have a spending problem

We can tell (pace the Democratic Party) that the USA doesn't have a spending problem because county supervisors get a salary of $410,000 and an identical pension:

[County Supervisor] Muranishi has been with the county for 38 years, and she’s 63. When retirement day comes, she’ll be getting a lot more than a gold watch.
That’s because, according to the county auditor's office, Muranishi's annual pension will be equal to the dollar total of her entire yearly package — $413,000. She also has a separate executive private pension plan, for which the county chips in $46,500 a year.
I particularly like that she gets $54,000 a year solely because she's been with the county more than 30 years. So this salary isn't paid to her as part of an active market in talent - it's a classic (if outrageous in scale) time-served formula. For reference, the Governor of the entire state of California is only paid $170,000 per year.

For a sense of scale, Alameda County in California has a population of about 1.5M people, which is a little larger than Birmingham or Bristol in the UK. Its major city is Oakland which is one of the most dangerous cities in the USA, having seen crime rise consistently for about 40 years. You'll note in the quote above that Muranishi has been with the county for nearly all that time, so at this point I'm assuming that Susan Muranishi is one of the primary contributors to a violent crime rate of 1682 per 100,000 residents. I don't know who's keeping her in her job, unless it's the supervisors of the other major US cities whose crime rates look much better when you compare them to Oakland.

I enjoyed reading a 2007 interview with Muranishi where she defined "success" as "making a positive difference." One can only imagine what salary she would have demanded had Oakland actually improved during her time in Alameda County. Her BA in Social Sciences from UC Berkeley led to a presumably unsuccessful retail executive position at Macy's department store before she burrowed into county administration and stayed there.

Muranishi's outrageous salary-for-failure tells us all we need to know about how money is spent in local government. When you're spending other people's money on your friends, it's not much different from spending it on yourself - you spend as much as you can get away with, and hang the value for money.

Cyprus evolves a solution - or revolution?

So Cyprus has decided to shaft the rich Russians in preference to the poor Cypriots, preserving deposits under €100K while completely screwing deposits in excess of that amount by setting up a "bad bank" which is going to return cents in the Euro to the large depositors. Apparently this will disproportionately affect rich Russians who bank in Cyprus, and one can only speculate about how well these gentlemen will take the asset confiscation. Belgian poet Herman van Rompuy brokered the deal on behalf of the EU, and so I assume that he doesn't plan to travel to Russia on vacation any time soon.

The Streetwise Professor points to Germany as the ultimate determinant of the direction of the Cyprus settlement and wonders:

So why is Germany so insistent on doing something that inflicts large losses on Russia-and elite Russians? Can the impending German election explain it? Or does Germany think that the fate of the Euro is on the line, and if saving the Euro p*sses off the Russians, so be it. Or is it something else? I wonder.
Now that spring has started in Europe, presumably the Germans aren't too worried about Russia cutting back on gas supplies in retaliation for taking a few €bn from Russian depositors in Cyprus. I do wonder, however, how wise it is for Germany to try playing a long-term strategy game against a country who a) control a significant proportion of the reliable fuel source for Germany and b) play international-level chess when they're in kindergarten. If Russia arranges for an unfortunate drop in gas supply to German in, say, late December, who's going to cover the power deficit?

2013-03-21

What needs fixing in UK education, in one tweet

THIS.

I hate the trend towards "creativity" in schools. It seemed to start with the introduction of the National Curriculum, which presaged a greater influence by the Department of Education and its favoured academics on what was taught in schools and exactly how it was taught. I'm all for children embracing their creativity, but it should be made very plain to them that there is a standard for grammar and spelling in written communication which they are expected to exceed before they can expect their creativity to be respected by readers.

I can do no better than quote Emily Postnews on the subject:

Q: I cant spell worth a dam. I hope your going too tell me what to do?
A: Don't worry about how your articles look. Remember it's the message that counts, not the way it's presented. Ignore the fact that sloppy spelling in a purely written forum sends out the same silent messages that soiled clothing would when addressing an audience.

CEO in favor of government penalising his competitors

Howard Schultz, CEO of Starbucks, is in favour of raising the Federal minimum wage. Quoted in the Huffington Post:

"On balance, I am a supporter of the minimum wage going up," he said. "We've got to be very careful what we wish for because some employers -- and there could be a lot of them -- will be scared away from hiring new people or creating incremental hours for part-time people as a result of that wage going up."
The Federal minimum wage is $7.25/hr and Obama is proposing to raise it to $9/hr. Since Starbucks baristas generally earn close to $9/hr, this change is unlikely to hurt Starbucks much. But smaller coffee chains that rely on minimum wage employees to undercut Starbucks and prevent their customers going next door for a banana latte and gluten-free cookie are going to be squeezed and forced to raise their prices, thus migrating more customers to Starbucks. I have to admire Schultz's business sense, but let's not fool ourself that his support for the minimum wage is anything but self-serving.

One point that's being lost among all the minimum wage discussion is that this pertains to the minimum wage set by the US Federal Government, not the states. Minimum wages can also be set in states and even cities. New York state is planning to raise the minimum wage from $7.25 to $8.75 for instance. The Federal minimum wage doesn't apply to small firms whose commerce doesn't cross state lines, but it looks like Burger King etc. are all exposed to this. So in a poor state where wages are low (often Republican-leaning states), the federal minimum wage hike is likely to leapfrog any state or city minimum wage setting. It's likely to have less of an effect in Democrat states like California and New York where wages and minimum wage levels are already high.

Interestingly, it's really going to hit employers of tipped workers (waitresses etc.) Since they are often employed on $2-$4/hr and rely on tips to hit $7.25, and the employer is responsible for paying the gap if tips fall short, and given that prices and hence tips are unlikely to rise, the employer may have to find another $1.75/hr - 50% or more of his current wage payments.

The Huff Post article has a slideshow of "People who hate the minimum wage", and first up is ex-Republican presidential candidate contender Herman Cain:

Though Republican presidential candidate Herman Cain never outright advocated abolishing the minimum wage, he did argue that minimum wage laws prevent workers at the margins from getting their first jobs. Cain was an executive in the restaurant industry, which is one of the largest employers of low-wage workers.
Sounds to me as if Herman Cain was ideally positioned to see the effect of minimum wage laws on low-wage workers. Why aren't we listening to what he has to say?

2013-03-20

A tale of two unlocks

Bypassing phone lock screens seems to be the story of the day: first, access to the phone book and photos of an up-to-date iPhone:

By locking the device and enabling the Voice Control feature, it is possible to circumvent the lock screen by ejecting the SIM card from its tray at the moment the device starts dialing.
From here, the phone application remains open, allowing access to recent call logs, contacts, and voicemail (if it isn't protected by a separate PIN code). But also from here, photos and video can also be accessed by creating a new contact. When a new contact is created, it opens up access to the photos application — including Camera Roll and Photo Stream.
Note that the iOS version tested (6.1.3) is the release which fixes the previous unlock screen exploit. One wonders how many more of these exploits are going to come around.

The impact of this bug is limited in frequency but severe in impact. Although all modern iOS devices appear to be vulnerable, the actual exploit does not (in general) give a thief much to work with. He can't apparently make calls or send texts with the device, which are the two potentially most expensive acts. Where it does have an impact is situations where the address book or photos data are regarded as valuable - generally, when the thief knows the iPhone owner or knows they are a friend of someone whose address, phone number or data he wishes to steal. Imagine, for instance, if someone got access to Pippa Middleton's iPhone and used this exploit to read contact information and photos of her family and friends.

But let's not just pile on Apple - Samsung is similarly vulnerable:

From the lock screen, an attacker can enter a fake emergency number to call which momentarily bypasses the lock screen, as before. But if these steps are repeated, the attacker has enough time to go into the Google Play application store and voice search for "no locking" apps, which then disables the lock screen altogether.
From there, the device is left wide open.
The interesting point here is that the vulnerability doesn't appear to be present on "stock" (Google-released) Android 4.1.2 phones - it appears to be peculiar to Samsung devices. That implies to me that in Samsung's effort to pile on their customisations to differentiate themselves from J. Random Other Android device provider, they may have sacrificed something in quality and security testing. Unlike Apple, however, I suspect Samsung don't particularly care. They will certainly care about this flaw (since it makes Samsung leading-edge phones even more attractive to tea leafs who wish to burn up their victims' phone bills) but I don't see them slowing down their development velocity. That's their primary differentiator over Apple - new features and innovation - and there's no way they're going to trade that for slightly improved security. Only if the flaws being discovered have substantial negative impact for the average user (phone crashing all the time, corruption of storage, inability to view videos of cats) will they impact sufficiently on Samsung to change their development direction.