main
Report a problem

Revealed: The Internet's Biggest Security Hole

Joel   via Wired Blog Network on 27 August 2008 - 22:10 · 17 comments & 10190 views

Advertisement (Why?)
Two security researchers have demonstrated a new technique to stealthily intercept internet traffic on a scale previously presumed to be unavailable to anyone outside of intelligence agencies like the National Security Agency.

The tactic exploits the internet routing protocol BGP (Border Gateway Protocol) to let an attacker surreptitiously monitor unencrypted internet traffic anywhere in the world, and even modify it before it reaches its destination.

The demonstration is only the latest attack to highlight fundamental security weaknesses in some of the internet's core protocols. Those protocols were largely developed in the 1970s with the assumption that every node on the then-nascent network would be trustworthy. The world was reminded of the quaintness of that assumption in July, when researcher Dan Kaminsky disclosed a serious vulnerability in the DNS system. Experts say the new demonstration targets a potentially larger weakness.

"It's a huge issue. It's at least as big an issue as the DNS issue, if not bigger," said Peiter "Mudge" Zatko, noted computer security expert and former member of the L0pht hacking group, who testified to Congress in 1998 that he could bring down the internet in 30 minutes using a similar BGP attack, and disclosed privately to government agents how BGP could also be exploited to eavesdrop. "I went around screaming my head about this about ten or twelve years ago.... We described this to intelligence agencies and to the National Security Council, in detail."

News source: More @ Wired Blog Network

Post a comment · Send to friend Comments · There are 17 additional comments
#1 Tikitiki on 27 Aug 2008 - 22:16
Perfect. :\

Last edited by Tikitiki on 27 Aug 2008 - 22:28
#2 ThaCrip on 27 Aug 2008 - 23:57
hell, that kinda sucks lol

but this is only for 'non-secure' stuff right? ... like they cant screw with your internet data as long as it's secure from what i can tell from reading that article.

seems like it's got to be standard non SSL related stuff for them to screw with you, right?
#3 zeta_immersion on 28 Aug 2008 - 00:21
someone get me a "hack the net for dummies in 30 mins" and some coffee
#4 toadeater on 28 Aug 2008 - 00:43
All traffic on the internet should be encrypted.
(1 reply) #5 noPCtoday on 28 Aug 2008 - 01:26
is this the end of the internet?
or is this the dawn of a new internet.
#5.1 |Rapture| on 28 Aug 2008 - 03:38
neither
#6 Sawyer12 on 28 Aug 2008 - 07:26
I doubt they could bring down the internet in 30minutes. Id like to see someone try. That would be rather cool.
#7 F7S on 28 Aug 2008 - 08:44
Yesh, from reading the article, I think they could bring it down in under 30minutes, if they so wished... your forgetting they are working on something developed over 30 years ago... time we get the Sinternet (Secure Internet)...
(1 reply) #8 +warwagon on 28 Aug 2008 - 13:55
Great lets make this public. Idiots.
#8.1 Airlink on 28 Aug 2008 - 16:43
It's not a secret, it never has been. Anyone could have discovered this and exploited this any time between the 1970's and now. It's always been there. They're going public with it now because the government has been repeatedly warned about it and yet they've done exactly nothing to close the hole. At least this puts some pressure on the ISPs to do something.
#9 m-p{3} on 28 Aug 2008 - 14:45
Hack the planet!
#10 hackncrap on 28 Aug 2008 - 17:02
no if the internet dies i will have no social life :'(
and it may force all you 40 year olds living in your mothers basment to find other means of ordering pizza and talking to you lvl 60 elf commander NOOOOOOOO how will you live how will your elf army stay together your mages will never downloiad the new spells and patches noooo!!!

LOL internet is internet yes i would cry if it went down after a massive attack but the internet is getting overloaded by all this stuff on there now anyway ... the internet is still young and what happens if you drop a brick on a baby? that right it hurts the poor git then you get attack by child services ....
(1 reply) #11 TC17 on 28 Aug 2008 - 23:47
If this even is actually possible, the poor fool who would be brainless enough to do something like this, would have the wrath of the world upon him.
#11.1 Blitzer on 29 Aug 2008 - 13:59
(TC17 said @ #11)
If this even is actually possible, the poor fool who would be brainless enough to do something like this, would have the wrath of the world upon him.

Never know...they might have better job offers. The best hackers...get paid the best.
#12 McDave on 29 Aug 2008 - 08:02
If you google BGP routers and read some of the articles about how they work they comment on how they are unsecure. I too was thinking oh poop when I seen the article but as some people have said the problem has been around for a long time.
#13 Laser_iCE on 31 Aug 2008 - 21:09
And who says it hasnt been happening since it was first discovered? Haha, you'd never know...
#14 LoquaciousOne on 05 Sep 2008 - 01:31
Yes, they're out to get you!

Know they're out to get me with all the WMD's in our garage.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)