Live data from Hacker News

Ask HN: How did Dyn fail to fend off DDOS?

news.ycombinator.com

1–10 of 74 posts

Ask HN: How did Dyn fail to fend off DDOS?

#1
I'd imagine that DDoS attacks is something that DYN and other DNS providers would spend a lot of resources to prevent. Was there something specific about this DDoS attack that DYN was unprepared for? Or is there some reason that distributed natural of DNS makes it hard to prevent DDoS? Anyone know of any steps that DNS guys are taking to prevent another DDoS?

Re: Ask HN: How did Dyn fail to fend off DDOS?

#4
Hackers have started to use insecure Internet of Things devices, especially internet connected video cameras, to produce DDoS attacks larger than have ever been seen before. The KrebsonSecurity website was hit by a DDoS that was twice as large as the previous largest attack seen by Akemai, and there have been larger attacks since.

The problem will continue, and may get even worse, since many of the insecure internet attached video cameras are insecure because of passwords hard-coded into the devices; they can't be easily made more secure.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#5
I think the answer is surprisingly simple: The attack was just huge.

The unfortunate truth is that with the Internet of Things the amount of devices that can easily be taken over has grown so fast that we see DDoS attacks of unprecedented size. Even more unfortunate is that there is no sign whatsoever that this is going down again.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#7
post #3

if the attack is sufficiently distributed and scale is very large it can knock out even much bigger targets. I think there have been attacks at over 600 Gbps scale.

OVH DDoS late last month was over 1.5Tbps: https://twitter.com/olesovhcom/status/779297257199964160

I believe the Dyn attack was via Mirai also.

Re: Ask HN: How did Dyn fail to fend off DDOS?

#8
post #3

if the attack is sufficiently distributed and scale is very large it can knock out even much bigger targets. I think there have been attacks at over 600 Gbps scale.

Indeed, flashpoint (1) confirmed that the botnet attacking Dyn was the same one that attacked Krebs (2), and Krebs has more details as well (3). The previous attack on Krebs was seen to exceed 620Gbps.

1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns...

2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with...

3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

Re: Ask HN: How did Dyn fail to fend off DDOS?

#9
I've been waiting for some announcement around the Gbps of the DDOS similar to this Cloudflare announcement:

  https://blog.cloudflare.com/technical-details-behind-a-400gbps-ntp-amplification-ddos-attack/
Does DYN routinely deal with very large DDOS which would past this attack in a new category? Can someone who attends security conferences with DYN personnel comment?

Re: Ask HN: How did Dyn fail to fend off DDOS?

#10
post #3

if the attack is sufficiently distributed and scale is very large it can knock out even much bigger targets. I think there have been attacks at over 600 Gbps scale.

Indeed, flashpoint (1) confirmed that the botnet attacking Dyn was the same one that attacked Krebs (2), and Krebs has more details as well (3). The previous attack on Krebs was seen to exceed 620Gbps. 1. https://www.flashpoint-intel.com/mirai-botnet-linked-dyn-dns... 2. https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with... 3. https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powe...

Wow. That means the same culprits are still out there with their botnet? And it's still growing?
Post reply on HN