When the Internet apocalypse comes, your smart thermostat may be to blame. That’s the lesson from last week’s epic Internet outage, in which attackers used Internet-connected devices inside people's homes to bring a large chunk of the Web to its knees.
The outage, which mainly affected the East Coast of the U.S., struck on Friday morning but was felt into the weekend. It was caused by a large distributed denial of service (DDoS) attack, leveled at the servers of the domain name system host Dyn, which overwhelmed servers with data requests and made it impossible for users to fetch the files of Web pages.
But according to staff at Dyn who spoke with the New York Times, the takedown was facilitated by hundreds of thousands of Internet-connected devices—from Web cameras to routers—that had been hacked to contribute to the attack. When mobilized together, these pieces of innocent hardware can be used to send Web page requests to servers at such a rate that genuine requests are completely ignored. Sometimes, servers even fail altogether.
Friday’s attack comes less than a month after the website of security expert Brian Krebs and servers of the French Web hosting provider OVH were taken offline by DDoS attacks. Those were also orchestrated using as many as one million Internet-connected devices, such as digital video recorders or printers.
Hackers have been installing malware on PCs for years in an attempt to control them to take down Web servers. But as we install ever more Internet-connected devices in our homes, we increase the number of potential tools available to people looking to turn them into weapons.
Last week’s assault was more significant. Security expert Bruce Schneier argued not long before Friday’s incident that someone, somewhere “is learning how to take down the Internet” using these kinds of attacks. He reckons that hackers are slowly evaluating servers around the globe to identify their weak spots and the best ways to bring them down.
Who’s behind the attacks remains unclear, though it could be a nation-state, such as China or Russia—because there’s little motivation for most criminals to bother. But what does seem certain is that it will happen again.
These weird virtual creatures evolve their bodies to solve problems
They show how intelligence and body plans are closely linked—and could unlock AI for robots.
Surgeons have successfully tested a pig’s kidney in a human patient
The test, in a brain-dead patient, was very short but represents a milestone in the long quest to use animal organs in human transplants.
A horrifying new AI app swaps women into porn videos with a click
Deepfake researchers have long feared the day this would arrive.
The covid tech that is intimately tied to China’s surveillance state
Heat-sensing cameras and face recognition systems may help fight covid-19—but they also make us complicit in the high-tech oppression of Uyghurs.
Get the latest updates from
MIT Technology Review
Discover special offers, top stories, upcoming events, and more.