• 33 Posts
  • 1.42K Comments
Joined 2 years ago
cake
Cake day: November 21st, 2023

help-circle

  • Here’s a fun story about Russia.

    Years ago I was the BlackBerry server manager. BES was unique in that it created a tunnel between the device and the BES, and the admin was in complete control of the encryption and authentication. The way it worked is you put your BES next to your email server and give BES an admin account so could read all of the mailbox info and sync what it needed to the device.

    As the company expanded into Russia we looked into putting a BES and email server there to improve things for them.

    That’s when we found out that BES was not allowed to be sold directly to companies in Russia. Instead you could buy it from their mobile phone providers , and you would give them that admin account.

    The only reason for this that I could come up with is that Russia could not break BlackBerry encryption, so instead they made it impossible to even use BES if you were a Russian company.

    We ended up letting the Russian employees travel to the us every few months and return home with 3-4 devices, powered off, with activeSIM cards we were paying for even though they weren’t being used. The roaming charges were impressive.

    Side note: Russia didn’t care about imap, active sync, android or iPhones. Only BlackBerry. I wonder if they had those hacked already.


















  • DDOS is a symptom. A DDOS can cause different failure scenarios at different points.

    Maybe the attack is causing the service to access a backend database that isn’t equipped to handle the traffic. The web server queues requests but they can’t be handled in a timely manner.

    Maybe the attack causes a firewall to spend too much time inspecting the traffic by sending a malformed packet.

    Maybe the attack simply overwhelms the bandwidth of the firewall or router. The Reddit “hug of death” is a common example.

    In short, lots of things can lead to a service interruption. A DDOS is just a description of a way to cause that interruption by using distributed source hosts.