Hacker News new | ask | show | jobs
by doctorsher 3123 days ago
Hello Mr. Schneiderman,

Thank you for doing this AMA, for your investigation, and for your well spoken remarks at yesterday's press conference.

Will you also pursue whether the FCC legitimately experienced a distributed denial-of-service (DDoS) attack?

Personally, I think that one of these two scenarios is likely:

1. The signs of the reported DDoS are natural artifacts of heavy traffic load on the FCC's web application. Large groups may have submitted through mechanisms unintended by the FCC, and users may have created malformed requests. When large groups of people use your system, it can be in ways you didn't anticipate when the system was designed. If this is the case, the FCC falsely claimed there was a DDoS -- this could be due to incompetence (poorly written application) or malevolence (willfully ignoring authentic human input that overwhelmingly supported net neutrality). Either of these outcomes are contrary to the FCCs mission.

2. There was legitimate DDoS activity. In this case, we must find out who committed this DDoS. Furthermore, we need to analyze whether there is any correlation between the faked identities and the DDoS activity. For example, let's say there is a clever ISP against net neutrality. They conduct this DDoS against the FCCs commenting system to drown out the voices of real US citizens. However, they know the DDoS might be analyzed, so they conduct the DDoS with pro net neutrality comments -- the content of the comments doesn't matter to them, so much as the ability to point the finger elsewhere while knowingly suppressing authentic comments. If there is extreme overlap between IP addresses used for such a scheme and other anti net neutrality comments, the true intention is revealed. Again, this is just an example. For your investigation, you would likely be interested in this angle in order to rule out whether the entity that conducted the DDoS was also responsible for the massive case of identity theft you are pursuing.

Either way, if the state of New York could compel the FCC to release anonymized logs, our entire country would benefit.

Thank you! Remain steadfast.