Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

11–20 of 74 posts

Re: Ask HN: How did Dyn fail to fend off DDOS?

#12

I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement: https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?

last night the consensus was 1.2 tbps.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#13
post #5

I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#15

Earlier quoted context omitted.

Indeed, flashpoint (1) confirmed that the botnet attacking Dyn was the same one that attacked Krebs (2), and Krebs has more details as well (3). The previous attack on Krebs was seen to exceed 620Gbps. 1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns... 2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with... 3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

Wow. That means the same culprits are still out there with their botnet? And it's still growing?

The code for it has been released on Github, so there are now likely to be many botnets.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#16
post #5

I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Well, a good initial step is usually changing the default password.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#17
post #5

I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

>The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size.

Not quite, the "IoT" botnets are particularly small in the great scheme of things. Google "conficker" for example.

Edit: Interesting how this is getting downvoted so much. Conficker had up to 15 million nodes, far bigger than any "IoT" net (when did home routers become IoT anyway?). It's far easier to build such huge windows nets because you get millions of insecure computers with relatively standard hardware and software, not so much with "IoT".

In the past decently sized botnets simply weren't used to send DDoS attacks as much, that's all that's changed.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#18

I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement: https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?

last night the consensus was 1.2 tbps.

or 2x krebs, the 2nd? previously largest in history; we could use that or this incident as the future benchmark of ddos capacity. Attacker may have been involved with the 1.5Tb against OVH.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#19
post #5

I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Change the default admin password.

The original Mirai program tried a little over 60 passwords and it would just brute force into an IoT device.[1]

From what I read, it seems that one specific manufacturer in China is the owner of a lot of devices used in the Mirai botnet attacks.[2]

1: https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi... 2: (I cannot find the link, but it was an article from yesterday)

EDIT:

Found this when googling the strange '7ujMko0admin' password in Mirai: http://www.cam-it.org/index.php?topic=9396.0 So it looks like the Chinese manufacturer that they target is Dahua.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#20
post #5

I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Where's the pain-free device with open source, easily upgradeable firmware, that puts all of our IoT devices in their own private network but lets us tunnel through to them? It needs to be easy enough that our (grand)parents could pick one up on Amazon, Best Buy, or Home Depot and plug in and go...
Post reply on HN