Skip to main content

The context you need, when you need it

When news breaks, you need to understand what actually matters — and what to do about it. At Vox, our mission to help you make sense of the world has never been more vital. But we can’t do it on our own.

We rely on readers like you to fund our journalism. Will you support our work and become a Vox Member today?

Join now

Friday’s huge internet outage, explained

Security expert Brian Krebs says the Internet of Things is to blame.

Giphy

For hours yesterday, a slew of major websites — including Reddit, Twitter and Amazon, not to mention multiple Vox Media sites — were inaccessible to much of the United States and parts of Europe.

You may have already heard that this was the result of a massive “denial of service” attack, a well-established practice where attackers flood a target with so much fake traffic that real people can’t get in. But what’s unusual here is that Friday’s attackers were not focused on those specific sites, but rather on Dyn, an organization that helps other companies reroute their web traffic.

And adding to the weirdness: Your home security camera might have been partially responsible.

Security expert Brian Krebs has an excellent detailed breakdown of the outage on his website, but here’s the short version: That fake traffic has to come from somewhere.

According to several security firms, the attackers were using a type of malware that enlists unsecured Internet of Things devices — reportedly, cameras and DVRs with components from the Chinese firm Xiongmai — to do their bidding. Those devices, Krebs writes, could be turned into a zombie army even if their users had supposedly set a custom password to protect them:

That’s because while many of these devices allow users to change the default usernames and passwords on a Web-based administration panel that ships with the products, those machines can still be reached via more obscure, less user-friendly communications services called “Telnet” and “SSH.”

Telnet and SSH are command-line, text-based interfaces that are typically accessed via a command prompt (e.g., in Microsoft Windows, a user could click Start, and in the search box type “cmd.exe” to launch a command prompt, and then type “telnet” to reach a username and password prompt at the target host).

Krebs concludes that the companies that manufacture these unsecured devices won’t address the issue unless a global recall happens. And this warning comes as the cost of stuffing web connectivity into all sorts of devices is getting cheaper by the day.

In other words, unless Xiongmai (and anyone else whose components may be at fault here) steps up, this could very well happen again.

This article originally appeared on Recode.net.

See More:

More in Technology

America, Actually
Inside the fight over America’s data centersInside the fight over America’s data centers
Podcast
America, Actually

“The ugliest thing I’ve ever seen”: How New Jersey residents feel about a data center in their backyard.

By Astead Herndon
Podcasts
Could you spot an AI-written book?Could you spot an AI-written book?
Podcast
Podcasts

An author set up an experiment to find out.

By Amina Al-Sadi and Noel King
Future Perfect
The 5 most unhinged revelations from Elon Musk’s lawsuit against OpenAIThe 5 most unhinged revelations from Elon Musk’s lawsuit against OpenAI
Future Perfect

The Musk v. OpenAI trial is over. Here are the receipts.

By Sara Herschander
Podcasts
Are humanoid robots all hype?Are humanoid robots all hype?
Podcast
Podcasts

AI is making them better — but they’re not going to be doing your chores anytime soon.

By Avishay Artsy and Sean Rameswaram
Future Perfect
The old tech that could help stop the next airborne pandemicThe old tech that could help stop the next airborne pandemic
Future Perfect

Glycol vapors, explained.

By Shayna Korol
Future Perfect
Elon Musk could lose his case against OpenAI — and still get what he wantsElon Musk could lose his case against OpenAI — and still get what he wants
Future Perfect

It’s not about who wins. It’s about the dirty laundry you air along the way.

By Sara Herschander