Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

201–210 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#201

Earlier quoted context omitted.

>We don't know who is doing this, but it feels like a large nation state. China or Russia would be my first guesses. Why not the USA?

Russia retaliating for the US taking out the ESA Mars Drone.

I thought, "first actual space battle! Neat!"

Then I felt horrible.

Re: DDoS Attack Against Dyn Managed DNS

#202
post #55

Earlier quoted context omitted.

It doesn't make a whole lot of sense for the USA to take down the internet, as they benefit the most from it. A significant fraction of that economy is based on it, much larger than in the cases of China and Russia. It would be like the owner of a coal mine campaigning for a carbon emissions tax: maybe there's something we don't know, but from the information we have it seems unlikely. Note that this wouldn't rule ou…

There are many types of actors even within the USA nation-state / government. For example, if a particular part of the government got wind of a data dump about to be released by another nation-state or independent actor (for example, a leak of some kind) - I think some parts of the USA government that possesses the ability to do so wouldn't hesitate to take down dns to the entire internet to avoid another similar dat…

> wouldn't hesitate to take down dns to the entire internet to avoid another similar data leak to the Snowden dump.

I don't understand how this would change anything unless you're assuming they would take down the Internet permanently

Re: DDoS Attack Against Dyn Managed DNS

#204
post #58

AWS says "We are investigating elevated errors resolving the DNS hostnames used to access some AWS services in the US-EAST-1 Region." Is that coincidental, or are they being DDoSed also?

Apparently us-east-1 is backed by Dyn (and only Dyn) as well? $ host -t NS us-east-1.amazonaws.com us-east-1.amazonaws.com name server ns3.p31.dynect.net. us-east-1.amazonaws.com name server ns1.p31.dynect.net. us-east-1.amazonaws.com name server ns2.p31.dynect.net. us-east-1.amazonaws.com name server ns4.p31.dynect.net. That's… utterly bizarre to me. us-east-2 has a more diverse selection: $ host -t NS us-east-2.ama…

Ex-Amazonian here. I worked on the EC2 API for just over a year, and this could simply be a legacy thing. See https://en.wikipedia.org/wiki/Timeline_of_Amazon_Web_Service....

us-east-1 is the oldest region and predates Route 53. Not adding extra DNS providers to the older regions is probably an oversight.

(The EC2 API team requests load balancers from a separate load balancer team. The load balancer team probably didn't exist as a separate team when some of these regions were created.)

Re: DDoS Attack Against Dyn Managed DNS

#205

I can't currently get resolution on www.paypal.com. $ dig @8.8.8.8 www.paypal.com ; > DiG 9.8.1-P1 > @8.8.8.8 www.paypal.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; QUESTION SECTION: ;www.paypal.com. IN A ;; Query time: 29 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Fri Oct 21 12:35:33 2016 ;; MSG SIZE rcvd: 32

I'm in New-York too and can't resolve Paypal, Etsy, Soundcloud, Github, Netflix, Heroku or Twitter

Re: DDoS Attack Against Dyn Managed DNS

#206

USA cyber defenses are NOT up to the task of defending our critical electronic infrastructure. Letting every company that runs critical services decide their own security posture is not scalable and has left us vulnerable. While no one is getting hurt, we are taking cyber missile hits from our enemies and eventually the damage will be worse. Other countries with more central controls will be less vulnerable than we a…

> we are taking cyber missile hits

A better analogy would be 'mocked cyber mass protests' seeing as how no infrastructure will need to be rebuilt after this passes.

Re: DDoS Attack Against Dyn Managed DNS

#207
post #198

I can't currently get resolution on www.paypal.com. $ dig @8.8.8.8 www.paypal.com ; > DiG 9.8.1-P1 > @8.8.8.8 www.paypal.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; QUESTION SECTION: ;www.paypal.com. IN A ;; Query time: 29 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Fri Oct 21 12:35:33 2016 ;; MSG SIZE rcvd: 32

Me either. I'm in NYC on TWC. I can't resolve PayPal with Google's DNS or with TWC dns servers. Also, I'm unable to resolve Twitter on TWC dns.

[deleted]

Re: DDoS Attack Against Dyn Managed DNS

#208

I can't currently get resolution on www.paypal.com. $ dig @8.8.8.8 www.paypal.com ; > DiG 9.8.1-P1 > @8.8.8.8 www.paypal.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; QUESTION SECTION: ;www.paypal.com. IN A ;; Query time: 29 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Fri Oct 21 12:35:33 2016 ;; MSG SIZE rcvd: 32

Quote from the status page:

> This attack is mainly impacting US East and is impacting Managed DNS customers in this region.

I'm in Italy, using my provider's default DNSs (not Google) and I can't reach paypal.com, thenextweb, twitter, spotify etc either.

Re: DDoS Attack Against Dyn Managed DNS

#209

Earlier quoted context omitted.

Prediction: A massive, sustained attack will occur on key US Internet infra on election night in an attempt to debase the US election results.

This is terrifying. Thankfully I don't think much actual voting infra is network reliant. But it could probably delay the results from being finalized for days, and allow Trump to spew further allegations of rigging. Though if they targeted electric grid, water, and public transport, starting early in the day and choosing the regions by their populations political leaning, it could easily have an effect on the result…

Hahahaha. For sure it's not supposed to be network reliant. But from my experience working on critical infra, even things like power grids and rail systems, this is almost never the case.

Re: DDoS Attack Against Dyn Managed DNS

#210

I can't currently get resolution on www.paypal.com. $ dig @8.8.8.8 www.paypal.com ; > DiG 9.8.1-P1 > @8.8.8.8 www.paypal.com ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER ;; QUESTION SECTION: ;www.paypal.com. IN A ;; Query time: 29 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Fri Oct 21 12:35:33 2016 ;; MSG SIZE rcvd: 32

Exactly the same right now from Spain. It seems the attackers are now targeting Dyn's European servers.
Post reply on HN