HN user

pbear2k21

263 karma

pad

Posts11
Comments19
View on HN

you may be correct. the issue has been closed for further review. a scaled attack might only prevent new nodes from entering the network as existing connections would be spared even when the maximum limit of peers is reached.

however - and i mean this - you need to watch your mouth buddy. you've been unnecessarily rude. i have decided not to respond with force - so either stfu or press your luck

i don't guard my reputation. this isn't 48 laws of power. i'd never become a blockchain socialite to the extent of social climbing to become blockstream's cto. i answer to no one and don't try to mold how others perceive me. interesting insults though - though i can assure you wholeheartedly that you don't want to make it personal. just so you know where you stand, who i am and who pulls rank on who. i rce'd slack too. bitcoin is food now. there is a dos here regardless - but thanks for the motivation

Do your homework! You're not the first person who ever thought of attacking a bitcoin node. While I'm sure there are areas for improvement, you're not likely to be able to make useful suggestions from a position of almost total ignorance.

again, i've successfully found remote crashes and dos issues in 25 - 30 blockchains. i don't care if you're a biased developer who takes this to heart. i'm going to see to brutalizing bitcoind and making it clear to you what happens when i attack nodes. cocky academics like you motivate me. he who laughs last etc.

i've popped 25 - 30+ blockchains. from anecdotal experience i suspect that there could be something here and need to see it through with a sync'd node and more firepower. you seem overconfident.

inaccessible to external machines that are not participating in the attack. it's yet to be seen what happens to a node that's sync'd with active peers and whether a node under attack is kicked out of the network for timeouts or how bitcoind behaves in general while tcp/8333 is under fire.

i considered this and needed clarification. i didn't know whether the p2p connections remained open or made frequent disconnect/reconnects. what happens to sync'd nodes with active peers is yet to be seen. it's too early, at least for me, to know whether peers would drop a node under attack over timeouts, how bitcoind behaves with peers while tcp/8333 is experiencing stress, etc.

node operators can implement their own throttling - sure - but how many bitcoin node operators are doing that to deflect a p2p ddos attack? even if some are, most aren't - and finality in the network could potentially suffer as a result of a massively scaled botnet attack.

edit: interesting child comment here. not pushing a patch just leaves the bulk of the network vulnerable to being ddos'd by a botnet - potentially resulting in severely lagged finality at best. ip throttling can/should be implemented by being baked into bitcoind.

bitcoind not having ip associated throttling edit: BUILT IN* is questionable. this attack shouldn't work on out-of-the-box installs of bitcoin. as i mentioned earlier - there is no rationale behind a single machine making 1k handshake requests per second.

50k sockets looping requests make the p2p port entirely inaccessible at times. with more attacking machines it is reasonable to suspect that the target node(s) could be held down in perpetuity.

edit: re: child comment / syn flood; sure. bitcoind needs ip associated throttling baked in. there is no rationale behind a single machine attempting 1k handshakes a second. the attack shouldn't work at all.

yes - testing his own node. that is how pen testing blockchain nodes works. from there you can make projections of scaled attacks.

it's not an rpc port - and the computer in the screen shot using telnet is an external machine that isn't participating in the attack.

Yeah livejournal is pretty bad. I only use it because of the 1 character username "g" I cracked 20+ years ago. It's an ad trap.

dear admins,

this guy is baiting me

dear readers,

that is what gaslighting looks like

this guy wasn't even around yet when whaops was hacked by dime. that's how new he is. i've been chatting with dime and he confirmed his friend didn't "help him code" anything

"null" here is slandering me over a personal beef spanning 15 years, and on reddit he was doing it in conjunction with xyrix and/or virus - due to the same 15+ year personal beef i have with that whole crew - or they have with me, rather. they follow me around the internet and attack like hyenas when i write or do anything public facing. these dudes are factually obsessed with me and i'm still not entirely sure why. it's flattering at least

null, you're not an authority on some shit you weren't even around for. calling me a groupie spectator to aol hacking, or to imply i didn't surf lan and wreck 500 - 1,000+ ints throughout my ao-career. you're out of your mind. nobody actually in the know would make the claim that pad wasn't deeply involved in ao-hacking. i was there in 1997 loading up punters for aol 2.5 - whereas you didn't come around until 2004. an authority. ha

as far as what's written about me - none of it was planted, or because i was caught for ridiculous bullshit like bothering celebrities and people with lexnex xs

Disclaimer: The person I am replying to is an unhinged, imaginative drug addict and confidence man. He crafted his post to look like he didn't already know I wrote the blog post.

Let's clarify everything since you are a liar.

We (dfntsc) hacked Cris,Merlin, Gandalf, and whaops.

You hacked CRIS and Merlin like everyone else. You never popped WHAOPS. Ever. I'd need a more reliable source than you - you're a known liar and you've only publicly proven it ITT.

The author is kevin/pad. A groupie from conferences with no technical apitutde.

I rarely if ever hung out in SE/phreaker conferences with you skids. After my time. You mean to imply that the second you popped up I was a groupie? You were brand new, and you've never left that category in my mind because your skills haven't progressed. I have no technical aptitude? The same week I turned in a Slack RCE you were bragging about simple XSS on Twitter. You've always been a charlatan.

Anyway, read this article like it was written by a groupie and not an authority on the subject /active participant.

A groupie? Not an authority on the subject? I've been in contact with Dime about the post. Since you "know" him - ask him yourself. Then ask him whether he sent me his Delphi browser for my own personal use around the time WHAOPS got popped.

When cryptome.org got defaced and hacked we were monitoring pad snitching in jya@earthlink.net emails from pad@yayo.org.

You dumbasses used my website as a launchpad to claim the defacement.

Nobody ratted on you.

Someone, other than me, e.g. not "pad@yayo.org" emailed the cryptome guy a URL to your thread. I had to shut down yayo.org with a disclaimer saying we didn't endorse illegal activity. Nobody wanted skid heat from a website defacement. You idiots were barely allowed to hang out with us as is and cryptome only sealed the deal. Never change Justin. Apologies to the rest of you for the AODrama - but I felt obligated to reply to this disgruntled lunatic and his readers with some unbiased clarification based in reality. You've always been a pain in my ass, dude. Get off my jock once and for all. The cognitive dissonance involved in you calling me a groupie.

Yikes.

and not for nothin' we're in our thirties null - but i'll happily go back and forth with you if you want brokeboi