Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

51–60 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#51
post #44

I am confused. Are so many big websites using Dyn, or does Dyn have some special role in the DNS chain in the US?

They sell premium services, have a large sales team, and are very aggressive. I get emails from them weekly discussing millisecond savings of their DNS solutions and the value increase in customers and sales.

Squeaky wheels get grease and their sales team squeaks a lot.

Re: DDoS Attack Against Dyn Managed DNS

#52
post #44

I am confused. Are so many big websites using Dyn, or does Dyn have some special role in the DNS chain in the US?

They're widely used because they were one of the few providers of geo-aware DNS service for a long time. (These days there are other, cheaper options, including Amazon Route53.)

Re: DDoS Attack Against Dyn Managed DNS

#55

Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)

>We don't know who is doing this, but it feels like a large nation state. China or Russia would be my first guesses. Why not the USA?

It doesn't make a whole lot of sense for the USA to take down the internet, as they benefit the most from it. A significant fraction of that economy is based on it, much larger than in the cases of China and Russia. It would be like the owner of a coal mine campaigning for a carbon emissions tax: maybe there's something we don't know, but from the information we have it seems unlikely.

Note that this wouldn't rule out the USA as such. First, it could be a longshot preparedness thing, with no expectation that it would ever be used. Second, they could be red-teaming the thing (looking for weaknesses so that they can arrange for them to be shored up).

In either of these scenarios, it's no less likely that the USA would be doing it than anyone else. If you assume that whoever is doing this is planning to use their knowledge, however, the economic argument makes the USA less likely to be involved.

Re: DDoS Attack Against Dyn Managed DNS

#56
post #45
post #36

For me redirecting my DNS to Google public DNS 8.8.8.8 and 8.8.4.4 did the trick.

Same story for me here today (reporting from Cork, Ireland)

I'm a Verizon FIOS customer in NYC and was unable to reach nytimes.com and several other sites this morning. Switching my DNS to Google's (8.8.8.8 and 8.8.4.4) seemed to fix the problem, but I don't understand why yet.

Re: DDoS Attack Against Dyn Managed DNS

#60
post #36

For me redirecting my DNS to Google public DNS 8.8.8.8 and 8.8.4.4 did the trick.

that's not going to help much if the authoritative name servers (which is what dyn is, btw) go down for more than a day.

Max record cache time is 86400s (24h), so if the attackers can keep it down for 24h then google will have to have custom instructions in place (or cache more aggressively than the RFC allows)

Post reply on HN