[00:55.300 --> 00:57.820] Welcome, I'm Maximillian Dornseif. [00:57.960 --> 01:02.160] I'm a PhD student at the University of Bonn. [01:02.420 --> 01:10.100] Excuse me, can you do your further conversation outside or in a little lower volume? [01:10.820 --> 01:13.320] Can you be quiet or go out? [01:18.660 --> 01:27.220] I'm talking about digital demonstrations or virtual sit-ins, but at the moment I'm experiencing macOS problems. [01:28.120 --> 01:33.280] Is somebody here who can share me a notebook with an internet connection for now? [01:33.280 --> 01:40.620] Okay, so nobody saw you go without presentation for the next few minutes. [01:44.720 --> 01:46.070] What isn't... [01:47.100 --> 01:50.070] Yeah, but you can't browse the web? [01:50.760 --> 01:52.220] Yeah, okay. [01:53.620 --> 01:55.570] So, what is the demonstration? [01:55.940 --> 01:57.940] I tried to spare you all the stuff. [01:57.940 --> 02:01.540] It's a Greek word and so... Oh, great. [02:02.440 --> 02:04.940] We'll just get video output. [02:42.370 --> 02:43.050] Great. [02:58.230 --> 03:00.530] So, this now looks horrible. [03:01.710 --> 03:03.470] But it needs to be on the slide. [03:34.420 --> 03:36.780] So, I think you can't read this. [03:38.040 --> 03:39.020] I'll just go. [03:40.080 --> 03:44.400] A demonstration we can define as a gathering of people to get attention. [03:44.700 --> 03:45.280] Very simple. [03:46.540 --> 03:49.020] That's what I will talk about here. [03:50.860 --> 03:53.360] Expressing your political opinion by gathering. [03:56.040 --> 03:59.160] Demonstrations are actually a very, very old thing. [03:59.580 --> 04:06.540] Several thousand years, even the Greek people had them at a basic part of the political society. [04:06.540 --> 04:16.300] And every democracy nowadays accepts demonstrations as a very, very important part of political expression. [04:20.320 --> 04:25.340] So, we have to see how we can take this in the digital world. [04:30.660 --> 04:43.020] Demonstration offline, I will call it, or in real life, the classical way, is normally done to get the attention of other citizens. [04:43.760 --> 04:48.460] First of all, if you gather with a few thousand people, other people will see you. [04:48.460 --> 04:54.720] Of the media, for sure, if there's something happening, there's always some media around. [04:54.900 --> 04:56.540] And of the decision makers. [04:56.760 --> 05:04.140] You usually go to demonstrate at a place where the decision makers have to see you, have to recognize you. [05:04.380 --> 05:09.520] As far as I understand, the sidewalk at the White House is always occupied by some demonstrants. [05:10.560 --> 05:16.160] And in front of all parliaments worldwide, the people are trying to demonstrate. [05:16.980 --> 05:29.580] In fact, many parliaments prohibit demonstrations directly on their buildings or in front of their buildings to keep pressure away from the members of parliament, but you go to demonstrate near there. [05:31.080 --> 05:33.060] So, why demonstrate online? [05:33.500 --> 05:36.260] To get the attention of administrators. [05:36.420 --> 05:43.340] You first get, whatever you do online, the attention of people running the services you are affecting. [05:43.660 --> 05:45.820] To get the attention of the media. [05:46.820 --> 05:49.520] And perhaps to get the attention of other citizens. [05:49.780 --> 06:01.520] You usually can't get the direct attention of decision makers, because decision makers don't use the internet or don't use the internet at places where you can affect them. [06:02.260 --> 06:09.960] You can get their indirect attention by getting the attention of the media and so on. [06:11.220 --> 06:15.280] So, why move to demonstrating online? [06:16.580 --> 06:19.000] Because the targets are moving online. [06:19.400 --> 06:23.000] So, the things you want to demonstrate again. [06:23.000 --> 06:27.280] And maybe the targets are more vulnerable online. [06:29.220 --> 06:37.660] Physical demonstrations or offline demonstrations are a thing known for thousands of years and people know how to handle them and how to guard against them. [06:39.180 --> 06:44.380] And some people at least saying the public attendance is moving online. [06:44.740 --> 06:50.000] So, if I want to make news, I have to do something online. [06:51.180 --> 06:57.620] I am not sure if this is really true nowadays, but it might be in five years or ten years. [07:06.150 --> 07:12.070] So, the next slide, when it arrives, will show the characteristics of an offline demonstration. [07:13.150 --> 07:15.390] The first thing is you have to go there. [07:16.050 --> 07:19.470] You have to get out of your chair and go to demonstrate. [07:20.910 --> 07:30.010] That means, usually, you are just going to demonstrate if the demonstration is near you or if you are really, really set up. [07:30.610 --> 07:39.850] But, usually, nobody comes from, say, Germany to demonstrate in Brazil against tax spending problems. [07:42.610 --> 07:45.190] And, if you go there, you will be seen there. [07:46.090 --> 07:50.950] That means, on the one hand, you are not anonymous in any way. [07:51.530 --> 07:57.170] You are a little bit anonymous, but people can find out who you are and make pictures of you. [07:57.510 --> 08:02.170] And, your presence is directly sensible by others. [08:02.170 --> 08:06.770] So, if there are 2,000 people, you go there and see there are 2,000 people. [08:07.350 --> 08:12.550] Everybody can understand how many people are participating in a demonstration. [08:15.010 --> 08:21.710] Okay, usually, the people organizing a demonstration say, Oh, there have been 100,000 people. [08:21.890 --> 08:25.110] And, the police says, Oh, there have been just 50,000 people. [08:25.110 --> 08:28.350] But, not about, you can sense how many people are there. [08:31.190 --> 08:33.290] Oh, that's another slide. [08:34.130 --> 08:40.150] I will stay with the characteristics of an online demonstration. [08:49.270 --> 08:52.670] Other things are on an offline demonstration. [08:53.050 --> 08:54.390] Sorry, could I break in briefly? [08:54.570 --> 08:58.750] Could you drop the resolution to 810 by 610 that we performed there at one time? [08:58.750 --> 09:05.170] I think, I think I will just stop using slides, because it will take us half an hour. [09:07.870 --> 09:09.670] Could I use the slides for myself? [09:10.170 --> 09:11.210] No, it won't work. [09:13.610 --> 09:14.210] Okay. [09:15.090 --> 09:24.030] Another characteristic is that the number of people attending a demonstration is somewhere linear to the effect. [09:28.070 --> 09:43.130] Okay, if you are with 100 people and blocking strategical places on roads and so on, you will have a higher effect as if you go with a thousand people, gather peacefully in a park or something like that. [09:43.650 --> 09:49.010] But, in general, the number of people attending is linear to the effect. [09:52.070 --> 09:55.070] Blocking things usually is considered unlawful. [09:56.270 --> 10:08.230] So, most societies, democratic societies at least, have a constitutional right sometimes, or at least they tolerate gathering for political expression. [10:08.230 --> 10:15.290] But, if you block a nuclear facility or something like this, you usually get into trouble. [10:18.980 --> 10:19.100] Okay. [10:19.360 --> 10:21.820] Offline demonstrations... [10:21.820 --> 10:25.440] Online demonstrations are different in some key aspects. [10:25.600 --> 10:27.140] First thing, you don't have to go there. [10:27.660 --> 10:37.220] You can stay in your chair, use your web browser and say, oh, I'm against this bad thing and that bad thing and take part in this demonstration. [10:39.840 --> 10:45.080] You have... or you normally don't have to stay there. [10:45.440 --> 10:49.940] You start the online demonstration software or whatever and go for lunch. [10:50.540 --> 10:56.280] So, it's... you don't have to go there and you don't have to spend much time for your demonstration. [10:56.280 --> 10:57.500] That's a key difference. [10:58.580 --> 11:00.980] Other differences, you can't be seen there. [11:03.500 --> 11:12.560] For the general public or most people at all, it's really, really difficult to sense how many people are actually attending an online demonstration. [11:15.000 --> 11:23.280] And the effect of the demonstration is in no way linear to the number of people attending. [11:23.280 --> 11:35.340] If I use powerful distributed denial of service attack tools, I can have the same effect as 100,000 people reloading a single page all the time. [11:36.760 --> 11:42.160] And on online demonstrations, I will always hit bystanders. [11:43.880 --> 11:54.400] While offline, in real life, I usually block something and people have to spend time and the demonstrations are in the way. [11:55.520 --> 12:00.800] The effects on online demonstrations can be much bigger. [12:01.160 --> 12:08.320] If a website I protest against is hosted on a virtual server, I will hit all the other virtual presences. [12:11.220 --> 12:22.320] And if not, if it's a dedicated server, I at least hit the other sites hosted at the same hosting center, provider, whatever, on the same internet connection. [12:22.800 --> 12:26.300] And on the big view, I will hit the internet as a whole. [12:29.600 --> 12:34.260] So, what are the ways to do online demonstrations? [12:36.060 --> 12:44.000] I will focus in this talk on slowing down websites, I will call it. [12:45.080 --> 12:51.580] There are a lot of other ways, might be better ways, like putting banners on your page. [12:52.720 --> 13:02.720] There have been attempts to ask many people to change their homepage to a black page at a certain day. [13:03.020 --> 13:10.740] There have been an attempt in Germany to protest against the high fees for internet surfing to stop a day surfing. [13:11.700 --> 13:13.900] You can write e-mail, petitions. [13:14.900 --> 13:23.820] What seems to have a really high impact is filling out forms on websites that have to be processed by humans. [13:24.740 --> 13:32.740] The Zapatista movement, as far as I understand, did a lot of this on some military institutions in the US. [13:32.740 --> 13:38.600] And there were requests for information forms or such a thing and they filled out thousands of them. [13:39.660 --> 13:48.560] And the government had to check them all if there is something of real people or just was by demonstrants. [13:50.020 --> 13:52.880] But we will focus on slowing down websites now. [13:56.180 --> 14:01.180] There have been some noteworthy demonstrations of this kind. [14:02.760 --> 14:10.600] The most well-known is possible the Zapatista support demonstrations. [14:11.160 --> 14:17.000] There have been some against the World Trade Organization, WTO. [14:18.700 --> 14:23.800] And we have a very interesting case in Germany, demonstration against the Lufthansa. [14:28.300 --> 14:37.880] The Zapatista demonstrations, the idea came from people in Italy who had the thought that you can go on the website. [14:37.880 --> 14:45.080] I think they tried the President of Mexico and just hit reload on this page. [14:45.380 --> 14:50.360] And they were accepting that the page would go a lot slower then. [14:50.540 --> 14:51.760] And people should recognize that. [14:51.840 --> 14:53.440] They called this a literal sit-in. [14:55.460 --> 15:02.560] This thought was perfected by the Electronic Disturbance Theatre, who wrote a software they called FlatNet. [15:02.800 --> 15:16.480] And it was basically a JavaScript script, or later a Java outlet, which reloaded automatically every three seconds the attack page in... [15:16.480 --> 15:18.180] I think they did it in six frames. [15:20.100 --> 15:28.320] These people cited that virtual sit-ins, like they called it, are always symbolic actions. [15:28.920 --> 15:35.120] And the goal is not to take down service, but to set a symbol. [15:35.340 --> 15:38.560] And it had to be connected with street actions. [15:38.760 --> 15:40.960] I think this is a very important point. [15:42.660 --> 15:51.520] Then there was this demonstration against the World Trade Organization, which were very similar, used mostly the same software. [15:52.860 --> 15:59.180] But it's told that in one case there were half a million people participating. [15:59.640 --> 16:00.780] I can tell. [16:01.520 --> 16:08.020] Which shows that the World Trade Organization has much more enemies than the Mexican government. [16:10.000 --> 16:18.520] The people at the Electronic Disturbance Theatre developed some key points an online demonstration should have. [16:18.520 --> 16:20.720] It should be transparent. [16:21.360 --> 16:23.800] It should link virtual and street actions. [16:24.040 --> 16:28.440] They are very serious that just virtual action doesn't change anything. [16:28.820 --> 16:30.280] It should be non-violent. [16:30.660 --> 16:34.740] But I'm not sure what non-violence in a digital way can mean. [16:35.620 --> 16:37.880] It should use open source code. [16:38.000 --> 16:39.780] And it should use simple tools. [16:39.780 --> 16:42.060] So everybody understands what's happening. [16:42.060 --> 16:44.380] That's the main problem. [16:46.080 --> 16:50.520] Usually nobody understands what's happening on the internet except us. [16:50.780 --> 16:51.920] And no media understands. [16:52.320 --> 16:53.980] And no decision maker understands. [16:55.520 --> 16:58.660] And I think even with simple tools we have this problem. [16:59.720 --> 17:01.600] Then there was this Lufthansa demonstration. [17:02.700 --> 17:11.160] Lufthansa is flying for the German government, and illegal immigrants to foreign states. [17:12.200 --> 17:16.680] And in the last ten years two immigrants died on the flights. [17:17.380 --> 17:26.420] And people try to make Lufthansa stop doing that in the hope that the government would change its policy on illegal immigrants. [17:29.740 --> 17:35.820] They did a lot of work offline or outside virtual sit-ins. [17:36.100 --> 17:41.120] They called their action deportation class. [17:41.940 --> 17:48.820] And they did a lot of graphic and design and posters and so on and demonstrations on the streets. [17:49.920 --> 17:56.320] This deportation class demonstration developed an own demonstration client. [17:56.320 --> 18:00.760] That was a software which was accessing the Lufthansa website. [18:01.020 --> 18:03.200] And it had some very special features. [18:04.200 --> 18:18.240] First, it checked the date headers of some big e-commerce websites to ensure that the demonstration was just taking place at the timeframe they tried to demonstrate. [18:18.240 --> 18:21.640] And then it was using SSL or TLS. [18:21.940 --> 18:26.960] So it used encrypted connections to the Lufthansa web server. [18:27.320 --> 18:32.340] And all the time set up for every request a new encrypted session. [18:34.080 --> 18:39.120] Since encryption is the thing which hits most web servers hardest. [18:39.800 --> 18:46.200] And that's the reason why the crypto accelerator people can sell this really cool stuff for really a lot of money. [18:47.260 --> 18:50.640] This was a really interesting way to attack the web servers. [18:51.600 --> 19:06.460] While you can tune a web server to handle several thousand hits in a second, it is really, really difficult to get it to handle several thousand encrypted connection sets up per second. [19:08.660 --> 19:12.920] It's very difficult to say if this demonstration was a success. [19:12.920 --> 19:19.180] Some people claimed they can't, or they won't be able to reach Lufthansa. [19:19.760 --> 19:22.120] Lufthansa claimed their services were unaffected. [19:22.940 --> 19:24.400] Other claims the site worked. [19:24.600 --> 19:30.040] But everything more sophisticated like booking, flight tickets or so, didn't work. [19:32.460 --> 19:39.940] And it is told that Lufthansa completely disconnected from the German research network. [19:40.320 --> 19:48.320] Where they were thinking, I guess, that there are all these long-haired students which were trying to bring them down for the time of the demonstration. [19:49.760 --> 19:59.580] The interesting thing, another interesting thing is that Lufthansa claims there was no success at all the demonstration, but just were terroristic hacker attacks. [20:00.200 --> 20:03.060] Mind you, they just were reloading pages. [20:04.020 --> 20:10.660] And they filled a lawsuit in which they claimed damages of 1.2 million euros. [20:10.660 --> 20:15.060] So, let's say 1.15 million dollars. [20:16.160 --> 20:25.120] And in October last year, there were raids on several people who were organizing this online demonstration. [20:25.520 --> 20:28.160] As usual, they took all the computers they could find. [20:28.560 --> 20:29.700] I think 10 at all. [20:30.940 --> 20:37.500] They searched all offices in the building where the organization which organized the demonstration was. [20:38.160 --> 20:40.400] And up to now, nothing happened at all. [20:41.000 --> 20:47.240] Most people guessed they won't be prosecuted, but they will keep their computers for two years. [20:47.560 --> 20:49.740] And just let them wait. [20:53.320 --> 21:05.800] The ugly thing is because we have this running trial on this Lufthansa stuff, I can't show the details which sites or which parts of the website they accessed. [21:05.800 --> 21:15.660] They were very clever about it and tried to use parts of the website, which involved a lot of database processing on the Lufthansa site. [21:16.940 --> 21:17.540] Okay. [21:19.940 --> 21:22.940] So, let's move more to the technical part. [21:23.860 --> 21:37.000] Before doing an online demonstration, you just should think, if you want to do it and should do it, you could be sure that you will hit bystanders. [21:38.320 --> 21:40.360] And you might be prosecuted. [21:40.560 --> 21:43.560] If you are not willing to take this risk, you shouldn't do it. [21:45.340 --> 21:52.600] And you have to draw for yourself at this point a line between a denial of service attack and a demonstration. [21:55.980 --> 22:01.920] My hint is to stay as close as possible to the properties of an offline demonstration. [22:02.160 --> 22:14.400] Make it as much as you can, the same way people would demonstrate on the streets and you have a good chance explaining to the media and to a judge what you are doing there. [22:20.330 --> 22:22.950] So, what slows down a web server? [22:25.750 --> 22:26.790] Bandwidth consumption. [22:27.970 --> 22:41.030] In fact, it won't slow down the web server, but just the access to the web server so you can compare to filling up the streets to a location you want to demonstrate against. [22:41.530 --> 22:45.770] Processing time, because the web server needs a certain time to handle your request. [22:46.690 --> 22:50.730] System resources, that is PIDs and so on. [22:50.850 --> 22:58.770] The web server needs for every answer you send out to a request some resources. [22:59.210 --> 23:02.250] And systems resources on the operating system. [23:02.450 --> 23:07.430] That means the operating system needs some resources for every TCP connection and so on. [23:09.070 --> 23:18.510] All the... or most of the virtual sit-ins on the demonstrations up to now were based on the bandwidth consumption paradigm. [23:19.350 --> 23:23.430] So, it was more or less just hit reload as fast as you can. [23:24.870 --> 23:27.870] The flat net software was doing that automatically. [23:29.070 --> 23:37.870] The Lufthansa demonstration people tried to not only base the demonstration on that, but also involve some processing on the server side. [23:39.650 --> 23:43.470] But more or less it's all about bandwidth consumption today. [23:44.830 --> 23:52.090] The interesting thing about bandwidth consumption is that it may... might cost the target of the demonstrations. [23:52.110 --> 23:53.430] Really a lot of money. [23:53.430 --> 24:20.490] If the target site is a small site that pays its traffic by the gigabyte, and normally has several hundred hits a day and that's all, and you are starting to reload that page thousands of times per hour, they usually will get a hefty bill at the end of the month for that traffic. [24:20.490 --> 24:26.870] On the other hand, the small sites are usually not the right target to demonstrate against. [24:28.210 --> 24:39.270] I think usually it's not a good idea to hit the website of mom-and-pup's fishing shop to demonstrate against the Palestinian intifada or whatever. [24:40.770 --> 24:50.670] If you do this bandwidth consumption type of demonstration, users usually get a timeout, regular users, users who try to access the site. [24:51.590 --> 24:55.870] If you attack with processing time consumptions, [24:59.150 --> 25:08.090] there's one single web server process that can be forced to do really, really a lot of processing. [25:08.430 --> 25:11.070] There were attacks against Apache, for example. [25:11.070 --> 25:22.730] you could craft the path name in such a complex way that the Apache itself took several seconds to decode just the path name of the file you were accessing. [25:23.570 --> 25:37.950] The fun part usually is if there's a database driven website, you can make the web server really exercise the database a lot, and this will cause a hell of a lot of processing time. [25:37.950 --> 25:49.330] You might cause serious damage if this database is not only used for the website, but for other production users and the company you are demonstrating against. [25:49.610 --> 26:06.110] For example, if the Lufthansa database for flight schedules is also used to serve flight schedules to travel agencies, and you are able to slow that database down, you can cause serious financial damage. [26:08.470 --> 26:14.490] Users who access the site while you are demonstrating might get all kinds of errors. [26:15.590 --> 26:24.590] The fun thing is, and I think we all know from slash dot sites, MySQL, no further connections possible or something like that. [26:25.370 --> 26:27.270] That's a typical error we see there. [26:28.310 --> 26:32.470] So, eating up system resources like PIDs. [26:34.150 --> 26:48.090] For forking web servers, that is Apache, the one series mainly, and all the older web services like the CERN, HTTPD, and NSCA, HTTPD. [26:48.990 --> 27:00.090] For every connection, every request, they need a PID, a lot of file descriptors, a lot of memory, and the time to fork off the additional client. [27:01.410 --> 27:08.110] Modern Unix systems are really fast at forking off a client, but still it takes time on the client an additional process. [27:08.850 --> 27:23.370] Threading servers like Apache 2 or the internet information servers don't use PIDs for every connection, but they still need file descriptors, memory, and some time to start an additional thread. [27:24.190 --> 27:42.950] Polling servers, that are the state of the art, in my mind, like Zoys and THTTPD, but the most famous one is, I think, SQUID, which is not really a web server, but mainly does the same, need a lot of less resources per connection, some file descriptors, [27:43.090 --> 27:44.210] and a little memory. [27:44.210 --> 27:57.650] The thing is that usually with the forking servers, which are dominating today with Apache 1 series, they have compiled in or configured in a hard limit. [27:57.850 --> 28:14.250] That means they never will fork off more than 150 processes in the default configuration, which means the Apache server can't, in this default configuration, handle more than 150 clients being exactly at the same time. [28:15.610 --> 28:27.970] So, if you would manage to get 100 users requesting pages at exactly the same time, other users would get logged out. [28:29.590 --> 28:38.390] Using system resources to slow down the server, operating system resources, is very kernel dependent or operating system dependent. [28:38.390 --> 28:51.430] For every TCP connection, the operating system needs some resources and buffs on 3BSD, that is, on other systems it's quite different, but they need connection slots and so on. [28:52.670 --> 28:55.630] These resources are usually very good protected. [28:56.390 --> 29:07.130] The operating system designers put a lot of thought into this because they were attacked on the base of these resources for a long time. [29:07.730 --> 29:13.390] Think of SYN flooding, which was exactly an attack on the operating system resources. [29:13.990 --> 29:18.450] So, to slow down the web server, what should be our goals? [29:18.830 --> 29:21.330] If we want to demonstrate online. [29:21.870 --> 29:25.910] We should avoid to keep... to hurt others. [29:25.910 --> 29:28.830] So, we should keep down the bandwidth consumption. [29:30.050 --> 29:33.830] So, other servers at the same hosting center and so on won't be affected. [29:34.090 --> 29:36.270] The internet at all won't be affected. [29:37.590 --> 29:43.270] And, if ever possible, we should avoid keeping other users at the virtual web server. [29:43.550 --> 29:52.910] So, if there is a machine which is hosting 2,000 websites, we just want to demonstrate against one website. [29:53.150 --> 29:55.410] We don't want to slow down 2,000 websites. [29:56.910 --> 29:58.830] That's really a hard problem. [29:59.730 --> 30:04.870] We want to show obvious modification of server behavior. [30:05.070 --> 30:11.950] So, everybody should be able to see without having a PhD in computer science that there is a demonstration going on. [30:12.970 --> 30:21.810] And, we should try to maintain a linear relation between participants and, let's call it damage or effect. [30:22.290 --> 30:32.910] So, if there are 100 people on your online demonstrations, it should be 10 times less the effect as if there are 1,000 people. [30:34.930 --> 30:40.770] And, in my mind, the people taking part at the demonstration should be accountable. [30:40.770 --> 30:44.490] Which means no IP spoofing or something like this. [30:45.330 --> 30:50.150] If you are expressing your political opinions, you should stand up for that. [30:50.330 --> 30:53.330] And, usually, you won't be prosecuted for taking part in a demonstration. [30:55.450 --> 31:05.570] Now, I will show two concepts relatively new to my knowledge that haven't been used in online demonstrations up to now. [31:05.570 --> 31:07.930] The first thing is except flooding. [31:11.530 --> 31:15.270] That forces the server to fork off another process. [31:16.590 --> 31:18.830] And, you leave him at that state. [31:19.910 --> 31:22.750] Except flooding is not really new. [31:23.070 --> 31:26.310] But, it hasn't been used in the context of online demonstrations. [31:26.910 --> 31:28.550] You connect to the web server. [31:29.750 --> 31:32.290] That means you do the three-way handshake. [31:33.890 --> 31:36.510] And, then, you don't send a request at all. [31:37.510 --> 31:43.410] The server has started another process and has to wait for your request to be completed. [31:43.690 --> 31:46.970] And, since you won't send a request, it will time out eventually. [31:47.330 --> 31:49.450] And, usually, after 300 seconds. [31:49.450 --> 32:02.770] That means, with just the three-way handshake, which are just a few dozen bytes, you can tie up one server process for 300 seconds or five minutes. [32:03.270 --> 32:04.690] Yes, please, can you use the microphone? [32:10.560 --> 32:12.640] Isn't that just a synth flood? [32:13.280 --> 32:13.640] No. [32:15.860 --> 32:21.300] The synth flooding, you won't even complete the three-way handshake. [32:22.520 --> 32:31.000] But, with except flooding, you start a completely legitimate connection, but just don't send your request. [32:34.060 --> 32:37.480] The nice thing is, spoofing this is really difficult. [32:37.740 --> 32:38.900] So, people are accountable. [32:39.280 --> 32:40.840] It doesn't use that much traffic. [32:43.260 --> 32:52.020] But, the people defending against the demonstration might screw with the timeouts on the server side. [32:52.260 --> 32:54.740] And so, it won't have effect at all. [32:55.540 --> 32:56.900] So, no, we don't have slides. [32:57.120 --> 32:59.800] I have written a little example program for this. [32:59.920 --> 33:02.920] It's exactly four lines of Python. [33:03.120 --> 33:04.620] So, it's a really simple thing. [33:06.480 --> 33:09.160] Except for what you use minimal bandwidth. [33:10.300 --> 33:12.300] And, like I said, it's hard to fake. [33:12.500 --> 33:14.740] But, it has some cons. [33:14.740 --> 33:17.640] It's typical denial of service style. [33:18.000 --> 33:20.700] It shows you thought it was synth flooding. [33:22.940 --> 33:24.100] It's typical. [33:24.580 --> 33:26.760] You open something and leave it alone. [33:27.260 --> 33:28.660] And, the server has to handle that. [33:28.880 --> 33:34.780] And, it would be usually really difficult to explain to a judge what you are doing there. [33:35.600 --> 33:40.720] And, that this is a legitimate way to do a demonstration. [33:41.700 --> 33:44.000] So, I have another try at this. [33:44.660 --> 33:46.680] I called it communicating slowly. [33:49.220 --> 33:52.660] You acting all the way like a regular browser. [33:53.460 --> 33:56.540] You do just the thing a web browser would do. [33:56.760 --> 33:58.920] This could be implemented as a proxy. [33:59.220 --> 34:04.240] Which would sit between your browser and a demonstrated against site. [34:05.340 --> 34:07.020] But, we are doing it slow. [34:07.300 --> 34:07.820] Very slow. [34:09.860 --> 34:14.860] Because of this, we won't consume a lot of bandwidth. [34:15.200 --> 34:18.540] We are just sending, let's say, a character per second. [34:19.540 --> 34:24.070] But, it will still tie up a lot of system resources on the server side. [34:26.650 --> 34:33.240] The difficult thing about this is that TCP was designed to handle exactly this stuff. [34:34.690 --> 34:39.940] So, if you are doing it, you have to screw a little bit with the parameters of your TCP stack. [34:40.260 --> 34:46.130] And, to keep it from buffering your output and input and so on. [34:47.340 --> 34:51.570] If we are just communicating slowly, this means we are setting up a connection. [34:51.760 --> 34:53.220] Doing the three-way handshake. [34:53.460 --> 34:56.860] The server has to fork another process to handle your request. [34:56.860 --> 35:00.550] And then you start sending your request. [35:01.020 --> 35:03.630] One character at a time. [35:04.610 --> 35:11.740] So, a usual HTTP 1.1 request would take, let's say, four minutes to send. [35:12.050 --> 35:13.340] With all the headers. [35:15.760 --> 35:24.200] The web server usually has this one child, then, just listening to your incoming request. [35:24.440 --> 35:25.880] In blocking I.O. [35:26.130 --> 35:30.130] So, this child is completely tied up with handling your request. [35:32.320 --> 35:39.720] And, since a usual Unix server, so, just can't handle a few thousand processes. [35:39.720 --> 35:44.700] Or, like I told Apache, per default can just handle 150. [35:46.460 --> 35:51.540] With 150 demonstrants, the Apache server would be tied up completely. [35:52.050 --> 35:55.720] Of the two thousand demonstrants of the server was heavily tuned. [35:59.360 --> 36:06.700] And, the nice thing is that at least Apache spends a lot of processor time, even, in this blocking I.O. [36:06.700 --> 36:07.070] loop. [36:07.070 --> 36:10.550] Because it was implemented, not very efficient. [36:10.820 --> 36:12.570] Because this is an... [36:12.570 --> 36:16.000] That's not the usual thing Apache has to handle. [36:17.300 --> 36:20.500] Then, you read back your data very, very slowly. [36:21.720 --> 36:22.780] And this... [36:22.780 --> 36:25.360] That can happen several things. [36:26.040 --> 36:41.340] If the page you have requested, in this very slow way, is short, let's say, below 30k, the Apache will completely hand over the data of the page to the operating system. [36:41.800 --> 36:46.720] The operating system will buffer it, and send it one character by character to you. [36:47.100 --> 36:53.640] So, the web server has a new process, or it's not tied up anymore. [36:55.720 --> 36:58.700] But the operating system has to buffer your data. [36:59.200 --> 37:06.050] And the operating systems are not designed to buffer hundreds of... hundreds of megabytes of data. [37:06.240 --> 37:17.620] So, if you are requesting hundreds of thousands of these under 30k pages on this way, the operating system tends to get unstable and act in funnery ways. [37:18.660 --> 37:26.460] If the page is larger, the operating system does not buffer the whole page, or image, or whatever. [37:26.840 --> 37:34.100] And the web server process is tied up for the time until he got all the data to the operating system buffer. [37:35.680 --> 37:40.700] Sending it byte by byte, and if it's less than 30k, the server process can return. [37:42.140 --> 37:50.780] So, all this slow communication is tying up nearly no bandwidth, but a lot of resources on the server side. [37:54.520 --> 37:59.050] And the nice thing is, you might be able to explain it to a judge. [37:59.320 --> 38:03.580] You were saying, we were just surfing, doing it slowly. [38:03.860 --> 38:06.600] That's a usual way to do political protest. [38:06.600 --> 38:14.700] At least in Germany, the clerks at the government offices are not allowed to do demonstrations. [38:15.160 --> 38:18.050] And they have something they call Dienst nach Vorschrift. [38:18.840 --> 38:21.580] So, we are working strictly after the rules. [38:22.040 --> 38:22.460] Slowly. [38:24.240 --> 38:32.020] And saying, we went all to this website and requested pages on a slow way, might be acceptable by the public. [38:32.020 --> 38:35.080] So, they might understand you are doing a demonstration here. [38:35.360 --> 38:36.440] And nothing unusual. [38:37.920 --> 38:40.260] It's very hard to fake the client address. [38:40.700 --> 38:45.920] So, people can use this, but they can't use it for denial of service attacks. [38:46.140 --> 38:47.840] Well, they can, but they will be found. [38:51.000 --> 38:52.550] But, it's very difficult. [38:52.680 --> 38:55.700] You have to screw a little bit with the timing you do. [38:55.700 --> 39:00.540] Because if you are reading too slow, the server will do a timeout. [39:02.400 --> 39:05.520] The big problem is, you still hit virtual hosts. [39:06.700 --> 39:12.800] Whatever you do, if there are a thousand websites hosted on a virtual server, you will hit all of them. [39:17.660 --> 39:24.980] In my mind, this way is the best way, if you decide to do a demonstration, by slowing down servers. [39:25.240 --> 39:28.300] But, I think it will be really the way to go in the future. [39:29.240 --> 39:33.620] Like this virtual sit-in people said, possess symbolic action. [39:34.060 --> 39:38.740] And symbolic actions get used up if you do it too often. [39:39.900 --> 39:46.740] I think, still, this slowing down web servers is what's very hard to grasp for the public. [39:46.740 --> 39:58.800] And, if we think we need to put our political opinions in a demonstration like form online, we need new ways to do it. [39:58.960 --> 40:01.380] This on mid-term or long-term. [40:03.040 --> 40:08.380] But, still, if you think you have to do it, try to do it in a way not hurting the net too much. [40:10.300 --> 40:19.460] My slides come with an example code for this, and with a source code of this Lufthansa demonstration software. [40:20.320 --> 40:23.620] And, it can be found at the address md... [40:24.280 --> 40:26.580] Oh, I've tried to... [40:26.580 --> 40:31.580] Oh, it will be frustrating at all to get the video thing on. [40:31.580 --> 40:43.320] At the web page, http, md, for Max Dornseif, udora, h-u-d-o-r-a dot d-e. [40:46.400 --> 40:54.560] I'll try to get a link to this page with the slides for the presentation on the DEFCON website this afternoon. [40:55.880 --> 40:57.480] So, thank you very much. [40:57.580 --> 40:58.740] That was a demonstration. [40:58.740 --> 41:01.780] And I'm here to get your questions, if there are any. [41:13.800 --> 41:19.700] In the online approach, are you still trying to get the media attention that you would in an offline approach? [41:22.040 --> 41:24.820] In this with communicating slowly, sure. [41:25.140 --> 41:36.440] I think there's no other way to do an online demonstration, because most people won't recognize whatever you do, except you are able to slow down AOLCon. [41:37.560 --> 41:49.200] What happens the first time somebody writes a virus, spreads an applet or an application of some sort that does this unwittingly on others' computers? [41:49.480 --> 41:55.180] Does that dilute the... does that dilute how well your process is? [41:55.180 --> 42:00.160] Oh, in fact, we have this already. [42:01.700 --> 42:12.360] All this worm stuff was about doing a lot of communication between web servers and because usually the sites who caught the worm were overloaded. [42:12.900 --> 42:13.820] They were very slow. [42:14.160 --> 42:16.140] And we saw exactly this happening. [42:18.120 --> 42:21.680] I think it's really the context to set it in. [42:22.120 --> 42:41.040] If on the worms, code red and so on, it was just some techy thing and some evil software was tearing down the internet, but if you... you never could do an online demonstration without offline support, doing offline actions, media support and so on. [42:41.040 --> 42:49.380] And if you say, we are surfing slowly on the website of Lufthansa, what light you put on your actions in this case? [42:49.640 --> 42:52.160] So you're making that publicly known that this is a... [42:52.160 --> 42:56.000] this is an action that was meant to be performed for a particular purpose? [42:56.600 --> 42:57.660] Is that what you're saying? [42:58.300 --> 43:04.420] So you would... you would offline, you would publicize it as an action that you're taking on purpose rather than something next to it? [43:04.420 --> 43:05.540] Yeah, that's very important. [43:05.880 --> 43:06.220] Yeah, that's very important. [43:06.220 --> 43:11.460] And I think it's very important that all the stuff we can doing... [43:11.460 --> 43:13.860] or we are doing is... can't be anonymous. [43:14.360 --> 43:17.980] Or at last... can't... can be tied to an IP address. [43:18.520 --> 43:26.480] So if somebody is messing something up because you've got a virus with this stuff, we at last can try to track him down and tell him he has a problem. [43:29.160 --> 43:43.740] We just heard... I think... a few weeks ago, or one week ago, Falun Gong took over Chinese satellites, digital satellites, and they broadcast their message over satellites. [43:44.340 --> 43:45.780] What do you think about that? [43:49.240 --> 43:54.720] There's a big difference between the things I like and I consider cool. [43:55.840 --> 44:02.640] and the things which will work to change the options of politicians and other decision makers. [44:03.580 --> 44:14.940] And usually you can... if you try to stick to this classical paradigm of a demonstration, people gathering and voicing their opinion, that's the best way you can go. [44:15.200 --> 44:28.780] We see that even the stuff Greenpeace and so on does, being just a dozen of people and blocking a lot of things, isn't accepted by the general public often. [44:31.940 --> 44:32.820] Yes, please. [44:33.200 --> 44:33.920] Next person. [44:35.320 --> 44:52.640] Yes, I guess... I guess my question sort of dovetails in with what he had said about the Falun Gong protests, or their Falun Gong actions anyway. [44:53.900 --> 45:11.140] It's different from the traditional protest in that, yes, it may seem very cool, and no, it's not going to directly affect the government positions, or people in authority. [45:11.720 --> 45:23.640] However, what may have been affected by that is that they did get their ideas, their concepts across to a lot of people who wouldn't have seen them otherwise. [45:23.640 --> 45:34.600] And in that sense, although the authorities weren't being affected, many individuals saw them. [45:35.120 --> 45:38.800] At least that's what I picked up from what he had said. [45:42.860 --> 46:10.920] Actually, my question was specifically in regards to website defacements, and people who take over or do things to websites to modify the contents of the pages they're providing, and so print their message up on the website for other people to see. [46:11.180 --> 46:15.180] Do you consider this a valid form of protest? [46:17.460 --> 46:29.660] Is it more valid in any way because it causes many more people to see specifically your message? [46:29.980 --> 46:51.400] Whereas in the sorts of protests that you're describing, people will see that their website sits slower, but almost nobody will know what's going on unless they happen to see on the news, or they happen to see a person, oh, this was a protest movie. [46:51.620 --> 46:56.880] When there are website defacements, people see it in big letters, the message. [46:57.320 --> 47:00.000] And does that make it more effective? [47:01.000 --> 47:05.040] So, on the other hand, you can't compare defacement with a demonstration. [47:05.040 --> 47:12.980] So, if you take over a broadcast station and send your message out on television, you won't call it demonstration. [47:13.440 --> 47:21.520] On the other hand, I haven't seen a defacement up to now, which occurred to me to be really a political thing. [47:21.840 --> 47:28.940] There are things... people defacing mom and pop's fishing shop and saying, we are doing this against the war or against anything. [47:29.260 --> 47:33.420] Then I ask them, why do you go on a website nobody visits anytime? [47:33.420 --> 47:44.880] And when we see this high-profile defacement, I can't understand the political message in putting people in sexual positions on the Air Force website. [47:46.860 --> 47:51.220] That might be cool, but it's not a political opinion or something like that. [47:51.300 --> 48:00.120] And I haven't seen that somebody defaced a site with political value, I would call it, and put on a political message. [48:00.560 --> 48:05.920] But putting fluffy bunny was here on the WTO website doesn't change anything. [48:07.540 --> 48:08.760] But still, I like it. [48:11.220 --> 48:11.760] Yes? [48:12.020 --> 48:12.560] Hi. [48:12.800 --> 48:14.860] I actually have two comments. [48:15.060 --> 48:19.680] One sort of from a technical point of view and the other one from a social point of view. [48:19.680 --> 48:22.300] I work for Slash.org. [48:22.300 --> 48:26.840] We're a news website and we get attacked more or less continuously. [48:27.440 --> 48:32.120] So we have some experience with dealing with denial of service attacks. [48:33.480 --> 48:40.820] Your whole point there about mimicking the act of a regular user is right on. [48:40.820 --> 48:49.820] We find in general, the closer something looks to a regular user, the harder it is for us to stop it. [48:50.400 --> 48:52.900] And we have some very competent people. [48:53.080 --> 49:06.620] So when we see things, we can see a sin flood or we can see a spider that's crawling through and hitting every single page or hitting some database intensive page repeatedly or anything like that. [49:06.620 --> 49:11.020] And we can do whatever we can feasibly do to stop these things. [49:13.580 --> 49:29.660] So from both sides, from a judicial point of view where you have something that may be eventually looked at from a judge and you want to look like a regular user and not look like you're doing something illegitimate, that's right on. [49:29.840 --> 49:36.840] And then also from a technical point of view, from them doing something to stop it, then also you want to look like a regular user. [49:38.900 --> 49:41.600] From the other side, from a sort of social point of view, [49:45.420 --> 49:47.560] I don't know how to go... [49:47.560 --> 49:50.580] I mean some of the other commenters have said something about this. [49:50.740 --> 49:55.480] But I think that you only have a few limited options. [49:55.660 --> 50:01.340] I mean you can either slow down the website, you can get rid of the website, you can replace the website with something else. [50:02.160 --> 50:06.320] And of these, the slowing down may be legitimate. [50:06.680 --> 50:10.480] Getting rid of the website or replacing it with something else definitely isn't. [50:10.520 --> 50:14.180] But those are the only ones that have a real effect. [50:14.280 --> 50:18.400] And only replacing it has any potential to get your message across. [50:18.820 --> 50:24.940] You know, you're saying it needs to be linked with an offline protest, so that people know why this website is down. [50:25.100 --> 50:35.920] But the fact of the matter is, you know, if you take down CNN.com, you know, because you hate AOL Time Warner, well, you know, 100% of the people who visit CNN.com are going to know that it's not there. [50:36.300 --> 50:40.240] But .0001% of them are going to know why it's not there. [50:40.240 --> 50:44.940] You know, no matter how big your offline protest is, it isn't going to reach most of the visitors. [50:45.900 --> 50:52.180] So, you know, that's not really... I don't feel that that's a really effective way to get your message across. [50:52.180 --> 51:07.500] I mean, so far, the most effective online protest that I know of was EFF's blue ribbon campaign against the CDA, where they had people, A, turn their web pages black, and B, put blue ribbon graphics on their web pages. [51:07.800 --> 51:11.540] And so, you know, this has nothing to do with the people that they're protesting against. [51:11.640 --> 51:15.880] You know, they didn't go after Senator Exxon's website or the website of the U.S. [51:16.000 --> 51:17.300] Congress or anything like that. [51:17.440 --> 51:21.300] But it's, you know, it has most of the characteristics that you're talking about. [51:21.300 --> 51:25.040] I mean, it's traceable to individual people because they're putting it on their own web pages. [51:25.360 --> 51:28.280] You know, it's proportional to the number of people participating. [51:28.500 --> 51:31.520] You know, the more people you get participating, the more often you see this graphic. [51:31.740 --> 51:33.600] You know, the more often you see black web pages. [51:33.840 --> 51:37.340] You know, and you get a sense of how many people care about this issue. [51:38.560 --> 51:43.460] You know, it has all the good effects without having any of the negative effects. [51:43.620 --> 51:48.760] And it absolutely, you know, there's no question of it being legitimate or anything like that. [51:49.560 --> 52:02.900] So it seems to me that something like that, where you can enlist people putting stuff up on their own webpages rather than going after somebody else's internet server has all the characteristics... [52:03.340 --> 52:04.440] But that's not a demonstration. [52:04.800 --> 52:10.040] That's like putting a, I like to be an American and tell us a bad flag on your house. [52:10.320 --> 52:12.260] And that's completely different to a demonstration. [52:12.560 --> 52:14.040] I'm sorry our time is up. [52:14.480 --> 52:18.560] I will be outside for questions for the next ten minutes or something like that. [52:19.100 --> 52:20.020] Thank you very much. [52:21.340 --> 52:22.900] And thank you a lot for the network.