worldwide internet threat map

Oct 02, 2018 166 Replies

Conceivable. But what happens when the "AI" magic mis-classifies your computer as a hazard. And nobody, /nobody/, can explain the reason for the classification nor correct it.

I first heard of that in the mid 80s, where a tank/car fiscriminator worked well in the lab but failed dismally in the field. After a lot of thought they realised that it was actually discriminating sunny pictures (car adverts) from cloudy pictures (tanks in N Germany).

Modern examples of that are already becoming problematic, to the point that lawsuits are being filed. The usual response is "we can't divulge that for commercial confidentiality reasons".

Be careful what you wish for, you might get it.

The Chinese government uses that capability. Anything with the word "Tianamen" is classified as bad, and replaced with "404 error". or similar.

It is at complete variance with the whole concept of the net, viz dumb pipes and all the intelligence at the periphery.

n
e

ne.

real

e

up

are

not only the Chinese also several other mostly middle eastern regimes

Yes.

Install a Javascript blocker in a browser, see how many different companies are involved when a page is loaded. Much of the crap is in the form of JavaScript.

Sensible, but if completely applied, it would completely f*ck a lot of software. Think of JITting, HotSpot in the Java runtime and similar. Or the REPL loop in the Python runtime!

In other words, all you have done is move a boundary - from inside the processor (e.g. where the ISA defined instructions are interpreted and executed as many internal proprietary micro-ops) - to inside the software runtime (where proprietary bytecodes are interpreted and executed as many ISA defined instructions).

So nothing would really change.

Trust me, you don't want that. Your favourite compiler/linker emits data, which is then executed.

To get around that some God has to say "trust that data and execute it". You can gameplay what malefactors will do next!

Yes, indeed.

They all hate "Fake News", and are in a position to prevent it harming their citizens.

an

ire

sane.

le

o real

y
t

ere

roup

e are

ly

.

that is one way of putting it ..

The halting problem is a stronger argument, as yet there is no proof of conservation of energy. (there's a perponderance of experimantal evidence, but no proof)

Notsodium is mined on the banks of denial.

The network level has no access to your email content. or the content of many web pages because they are encrypted during transport.

yeah, and sometimes it works.

Notsodium is mined on the banks of denial.

Tom Gardner obviously has, but John Larkin only pays attention to people who post stuff that flatters him, so he hasn't noticed.

And John Larkin's are all in the dust-bin of history.

We don't flatter John Larkin's re-inventions of the wheel with the enthusiasm he feels to be appropriate. He interprets this as "hostility to ideas" rather than disdain for old ideas.

Brainstorming is a way of getting new ideas out of people who aren't used to looking for them. I've got three patents while John Larkin has just one to his name, as a co-inventor.

I didn't need brainstorming to come up with any of the ideas that got turned into my three patents - nor the one that turned out to have been already patented by the guy who had edited the article that had inspired me.

Brainstorming ought to be fun too. If it isn't you aren't doing it right.

Bill Sloman, Sydney

That's because you don't know what it is, nor appreciate it's significance.

formatting link

Alan Turing got famous in 1936 for proving that it is an insoluble problem.

What's special about multicore processors for secure application?

This is the second time that John Larkin has made this claim, and the second time I've asked him to explain himself. Multicore processors can obviously crunch more bits in a given time than a single core, but where's the security advantage?

Anybody who could write in assembler could get around the restrictions imposed by a compiler.

Bill Sloman, Sydney

Those old guys had clearly understood that something had changed. Giving up electronics mightn't have been a constructive reaction to that change, but it did recognise its existence.

I don't think that anybody here - with the possible exception of krw - thinks that "nothing will ever change".

There is quite a lot of resistance to the idea that John Larkin is any kind of reliable prophet for the way things will change, but that has more to do with the fact that most of us can do critical thinking, and John Larkin can't.

John Larkin thinks that Anthony Watts and the rest of climate change denial propaganda machine are presenting reliable evidence that the climate won't change, so he would be an obvious example of a guy who posts here who thinks that things won't change.

Bill Sloman, Sydney

He might be, but he takes himself much too seriously for this to be likely.

Bill Sloman, Sydney

You haven't heard of deep packet inspection, have you?

Basically every "innovative" idea that has been suggested here is in everyday use in corporate firewalls, and has been for decades. It really is laughable watching the presumption of competence of the participants in this discussion.

The network provides DNS. That means it can send every connection where it wants, and create fake SSL certificates for every new secure site you visit. It requires a compromised root in the browser, but there are so many roots and almost certainly some are in control of bad players (including governments). SSL interception is also common and standard practise in corporate firewalls, where they insist on installing their own root cert into every browser - else you can't get out using SSL.

John Larkin wrote

It is from the crypto crowd, I must confess that usually within a few hours you can find a security hole in a 'secure' system, as you often state: just by 'thinking out of the box'.

I did, well there is a story behind it, of course when I figured out how that worked and wrote that code I had an idea, connected to my ISP (company no longer exists today) and tried it out. It put them offline for a long time, no it was not intentional, just that the router designers had the same idea. Then (that was deliberate) tried to kill existing ... well, yes it worked. I still have that old code maybe from 5 1/2 inch floppies... Anyways later did an UDP stack in PIC asm (you do not want to write that stuff in snake language or BASIC) and it is in use in several projects here, now for several years. Is it safe? No way, but then writing all that code also clearly gives some understanding and you see 'possibilities' Specs are available, so it is just coding fun.

Yes, been doing that with FPGA, wrote a simple video standard converter from NTSC to PAL too. In the old days that was half a room full of equipment (BBC had one).

Bit scary, I like temperature sensors.. on critical points, even if it is just 'clicsons'. Software can fail, hardware can fail... Real fuses.. When working on those marine vessel electronics somebody told me that in case of combat some power fuses get bridged. Not sure things are still that way, but indeed if you cannot fire or move your guns because of a blown fuse..

But then they used Microsoft to control their stuff, and a whole warship was disabled. Maybe blue screen, rebooting?

IIRC the Russians once did an EMP attack on a US warship while flying past it, and the ships electronics shut down, even causing some to quit the service. YMMV.

But every analog-computer-like Spice deck causes Spice to execute data. The definitions of these things would disallow LOTS of your normal computing, but won't be effective against malware slightly outside the box.

And, hackers are always more than slightly outside the box.

Precisely.

There is a fine balance between "crushing ideas" and pointing out an example of the Dunning Kruger effect. Delicacy is my preferred initial technique.

Yes, and there have been very visible (by mistake) examples of that, usually by incompetent state authorities pissing around with the BGP.

It enables potentially lethal MITM attacks.

Unfortunately there are simpler ways.

The one that I don't know how to defend against is a malefactor modifying the DNS lookup in a home router or cable modem. Yes, that has been done.

And "be careful what you wish for, you might get it".

Here's an example of your wishes being applied in practice to GPS Disciplined Oscillator software...

"I have had a LOT of requests for the Windows version of the latest version (v6.05 Beta) of Lady Heather for Windows. Unfortunately aggressive blocking of .exe files by ISPs makes it very hard to email the .exe file (even password protected .zip files get blocked). Also very few Windows users seem to be able to compile the code."

formatting link

Just to add to this, a buddy of mine was a marketing manager for a division of HP, figuring out how to sell testing platforms (against competing testing products!) for routers that perform deep packet inspection. This was more than ten years ago, and there was already a well-developed *market* for such things as a specialist *testing* products even then. How many companies were buyers in this market? The actual technology being tested was widely implemented over a decade before that.

But yeah, I'm sure the world will beat a path to John Larkin's door, now that *he* has suggested such things.

Clifford Heath.

So how is that applicable to this problem?

"One processor to rule them all"

John isn't interested in learning anything. He already knows all about it.

Rick C.

It's just an example of data string with a guaranteed unpredictable effect.

You can inspect the contents of packets as much as you like, but you can't predict what they are going to do.

Rather like krw, if at higher level.

Bill Sloman, Sydney

My guy asked me if I'd mind if he put our bare-metal c/ARM TCP/UDP stack up on github, and I said OK. I'll see if it's there.

Not scary! We measure heat sink temperature and mosfet voltage and current. A couple of thousand times a second, we run a dynamic thermal model of Tj. That's a lot better protection than a current limit or a foldback limit. We can push fets harder than some dumb electrical limit, but be safer.

Here's an analog circuit that does sort of the same thing, compute fet power.

formatting link

Add a time constant to approximate junction mass, roughly 100 ms, and sum in heat sink temp, and then hit a comparator.

Software doesn't fail is it's bug-free.

But they would have to be replaced.

John Larkin Highland Technology, Inc lunatic fringe electronics

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required