Ask HN: How did Dyn fail to fend off DDOS?
11–20 of 74 posts
Re: Ask HN: How did Dyn fail to fend off DDOS?
#12I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement: https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?
Re: Ask HN: How did Dyn fail to fend off DDOS?
#13I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#14Is it that simple? or am I missing something?
Re: Ask HN: How did Dyn fail to fend off DDOS?
#15Earlier quoted context omitted.
Indeed, flashpoint (1) confirmed that the botnet attacking Dyn was the same one that attacked Krebs (2), and Krebs has more details as well (3). The previous attack on Krebs was seen to exceed 620Gbps. 1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns... 2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with... 3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...
Wow. That means the same culprits are still out there with their botnet? And it's still growing?
Re: Ask HN: How did Dyn fail to fend off DDOS?
#16I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#17I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.
Not quite, the "IoT" botnets are particularly small in the great scheme of things. Google "conficker" for example.
Edit: Interesting how this is getting downvoted so much. Conficker had up to 15 million nodes, far bigger than any "IoT" net (when did home routers become IoT anyway?). It's far easier to build such huge windows nets because you get millions of insecure computers with relatively standard hardware and software, not so much with "IoT".
In the past decently sized botnets simply weren't used to send DDoS attacks as much, that's all that's changed.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#18I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement: https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?
last night the consensus was 1.2 tbps.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#19I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.
The original Mirai program tried a little over 60 passwords and it would just brute force into an IoT device.[1]
From what I read, it seems that one specific manufacturer in China is the owner of a lot of devices used in the Mirai botnet attacks.[2]
1: https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi... 2: (I cannot find the link, but it was an article from yesterday)
EDIT:
Found this when googling the strange '7ujMko0admin' password in Mirai: http://www.cam-it.org/index.php?topic=9396.0 So it looks like the Chinese manufacturer that they target is Dahua.
Re: Ask HN: How did Dyn fail to fend off DDOS?
#20I think the answer is surprisingly simple: The attack was just huge. The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.
Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.