Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

31–40 of 74 posts

Re: Ask HN: How did Dyn fail to fend off DDOS?

#31

I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement: https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/ Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?

last night the consensus was 1.2 tbps.

For a DNS-only service provider, it seems like 1.2Tbps could be 1000x normal traffic. But Akamai claims 30Tbps+ is their routine traffic[1]. Some have commented that this DDOS questions consolidation around cloud providers, but I think it will cause consolidation among service providers. You can no longer be a critical service provider if you don't have the capacity to absorb attacks like this.

http://www.csoonline.com/article/3123797/security/some-thoug...

Re: Ask HN: How did Dyn fail to fend off DDOS?

#32

I've been wondering if the UDP nature of a DNS server makes it harder to protect. Particularly coupled with the amplification attacks that DNS makes possible.

That's part of the problem. DNS servers should probably reject queries that require long answers when they come in over UDP. If you want a zone transfer, use TCP. That prevents amplification attacks.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#33
I would like to remind those that think all is lost with this:

A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it.

There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS OH NO', but we cleaned up, recovered, hardened. Microsoft went from being botnet enabler to an active force in dismantling bots and crime rings. It sucks, and some of us have a bad day, but we recover ever stronger.

XiongMai Technologies may well find themselves in some international hot water over this incident, and I think they deserve it. They sold a faulty product that caused billions of dollars in lost revenue to some very large internet properties for a day in October 2016. I would encourage vendors look at these incidents from last decade and how these were turning points for upping their security game. I would encourage its victims to investigate legal recourse.

Specifically the current vulnerable nodes of Mirai, i am sure these will be removed from the internet pretty soon. One only gets to fire something like this a few times before the feds are on the door.

Your regularly scheduled program will commence shortly.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#34

Earlier quoted context omitted.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Change the default admin password. The original Mirai program tried a little over 60 passwords and it would just brute force into an IoT device.[1] From what I read, it seems that one specific manufacturer in China is the owner of a lot of devices used in the Mirai botnet attacks.[2] 1: https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi... 2: (I cannot find the link, but it was an article from yesterday) ED…

Brian Krebs pegged a company called XiongMai: https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

Re: Ask HN: How did Dyn fail to fend off DDOS?

#35

Just thinking, Is there any chinese production of IOT involved? might be firmware involved?

That's what the following blog claims:

https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

I don't know any other independent researcher who confirms this.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#36
It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.)

We also need some big recalls. If Homeland Security tells the Consumer Product Safety Commission this is a national safety issue, the CPSC can order a recall. Something like this worked with those exploding "hoverboards". CPSC ordered recalls, Amazon took the junk back, and Amazon refused to pay manufactures in Shentzen. The manufacturers were furious, but hoverboards with crap batteries disappeared from the market very fast.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#37

Earlier quoted context omitted.

last night the consensus was 1.2 tbps.

For a DNS-only service provider, it seems like 1.2Tbps could be 1000x normal traffic. But Akamai claims 30Tbps+ is their routine traffic[1]. Some have commented that this DDOS questions consolidation around cloud providers, but I think it will cause consolidation among service providers. You can no longer be a critical service provider if you don't have the capacity to absorb attacks like this. http://www.csoonline.c…

I suppose Akamai wasn't ready to deal with the attack that size. They only recently bought Prolexic, but things move slowly on their scale.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#38

I would like to remind those that think all is lost with this: A serious conversation with vendors about default passwords and backdoors post this incident will help prevent recurrence. This has forced this talk and we are better for it. There was a time when your windows box would get popped from being online for more than 4 minutes. We recovered from this. Conficker in 2008. Blaster in 2003. It was a 'BIG BOTNETS O…

I would encourage its victims to investigate legal recourse.

It's all well and good saying that, and yes, if manufacturers are repeatedly/grossly negligent then maybe they should pay compensation and/or punitive financial penalties. However, unless you know something the rest of us don't about how to guarantee Internet-connected devices are perfectly secure, that sort of financial pressure can't be the whole solution, or even the main part of the solution. Ultimately, it may just mean that smaller players can't afford to risk participating in the industry any more, and no-one will be better off if reduced competition is the main result of this. We must be able to handle this more constructively than just demanding perfection and punishing those who inevitably fail to deliver it.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#39
post #16

Earlier quoted context omitted.

Does anybody have solid recommendations for secure IoT devices? Initial searches lead me to believe that they are non-existent.

Well, a good initial step is usually changing the default password.

A good initial step is not to have a default password. There was a time when all routers came with a default password and people were told to change it. They didn't. Now most new routers come with a randomly generated unique password printed on a sticker under the router. IoT devices should follow the same practice.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#40
post #36

It's time to apply some serious pain to the junk IoT manufacturers, retailers, distributors, and importers. A nice big billion-dollar lawsuit against Amazon for gross negligence would be a good way to start. US consumer law allows suing everybody in the supply chain. (They can then sue each other and try to sort out who pays, but that's not the victim's problem.) We also need some big recalls. If Homeland Security te…

Unfortunately, unless either you can get that sort of result across a substantial part of the developed world or it happens that most of the insecure devices used here were sold to US-based customers, the US legal system alone isn't necessarily going to help much.
Post reply on HN