Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

521–530 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#521

Earlier quoted context omitted.

>We don't know who is doing this, but it feels like a large nation state. China or Russia would be my first guesses. Why not the USA?

Because we are not indiscriminate like that.

Who is "we"? The u.s. government is a conglomerate of interests, organizations, individuals... Many of whom are quite indiscriminate. I'm not at all proposing that the U.S. was involved here. I'm questioning the simple identification of the U.S. government with the word "we", and the corresponding assumption that this institution is integrated in a carefully discriminating way...

Re: DDoS Attack Against Dyn Managed DNS

#522
post #340
post #317

Earlier quoted context omitted.

The rogue ISPs thought they were helping people by serving stale data. After all, better something past its use-by date than failing, right? A low tolerance for DNS response times, and suddenly large chunks of the internet are failing a lot... Among other problems, this enables attacks. Leak a route, DDoS a DNS provider, and watch as traffic everywhere goes to an attack server because servers everywhere "protect" peo…

> A low tolerance for DNS response times, and suddenly large chunks of the internet are failing a lot... Hang on a second. I feel that you're piling on other resolver changes in order to make a point. I'm not suggesting that the tolerance for DNS response times be reduced. Nor am I suggesting a scenario where the authority gets one shot after their TTL, after which they're considered dead forever. I would expect my c…

Not sure whether it could be used in a legitimate attack (probably), but it can definitely lead to confusing behavior in some scenarios. You switch servers, your old IP is handed to some random person, your website temporarily goes down - and now your visitors end up at some random website. Would you want that? Especially if you're a business?

Also, "commandeering" an IP of a small hosting might be easier than you think. It depends entirely on how they recycle addresses.

Re: DDoS Attack Against Dyn Managed DNS

#523

Earlier quoted context omitted.

Sorry if this sounds dickish, but renting 3 servers @ $75 apiece from 3 different dedicated server companies in the USA, putting TinyDNS on them, and using them as backup servers, would have solved your problems hours ago. Even a single quad-core server with 4GB RAM running TinyDNS could serve 10K queries per second, based on extrapolation and assumed improvements since this 2001 test, which showed nearly 4K/second p…

That's not how that sound be done. Just use a mix of two providers. Using your own servers and TinyDNS is silly for million/billion dollar companies. See MaxCDN for example who uses a mix of dns providers (AWS Route53 and NS1): ns-5.awsdns-00.com. ['205.251.192.5'] [TTL=172800] ns-926.awsdns-51.net. ['205.251.195.158'] [TTL=172800] ns-1762.awsdns-28.co.uk. ['205.251.198.226'] (NO GLUE) [TTL=172800] ns-1295.awsdns-33.…

+1 for using a mix of two providers. That's what we do at my startup. Never had a problem since (knock on wood).

Re: DDoS Attack Against Dyn Managed DNS

#524

Earlier quoted context omitted.

Sorry if this sounds dickish, but renting 3 servers @ $75 apiece from 3 different dedicated server companies in the USA, putting TinyDNS on them, and using them as backup servers, would have solved your problems hours ago. Even a single quad-core server with 4GB RAM running TinyDNS could serve 10K queries per second, based on extrapolation and assumed improvements since this 2001 test, which showed nearly 4K/second p…

That's not how that sound be done. Just use a mix of two providers. Using your own servers and TinyDNS is silly for million/billion dollar companies. See MaxCDN for example who uses a mix of dns providers (AWS Route53 and NS1): ns-5.awsdns-00.com. ['205.251.192.5'] [TTL=172800] ns-926.awsdns-51.net. ['205.251.195.158'] [TTL=172800] ns-1762.awsdns-28.co.uk. ['205.251.198.226'] (NO GLUE) [TTL=172800] ns-1295.awsdns-33.…

No tool is silly as long as it does the job adequately. Are paperclips silly for a billion-dollar company?

If both Dyn and R53 go down, it's exactly when you want a service like PagerDuty work without a hitch.

Re: DDoS Attack Against Dyn Managed DNS

#526

So who was prepared for this? Pornhub: pornhub.com: Name Server: ns1.p44.dynect.net Name Server: ns2.p44.dynect.net Name Server: ns3.p44.dynect.net Name Server: ns4.p44.dynect.net Name Server: sdns3.ultradns.biz Name Server: sdns3.ultradns.com Name Server: sdns3.ultradns.net Name Server: sdns3.ultradns.org ultradns.biz: Name Server: PDNS196.ULTRADNS.ORG Name Server: ARI.ALPHA.ARIDNS.NET.AU Name Server: ARI.BETA.ARIDN…

ultradns.biz has been down as well.

"ultradns.biz" is not responding to pings, but their DNS servers are responding to DNS queries properly:

    nslookup
    > server pdns196.ultradns.biz
    Default server: pdns196.ultradns.biz
    Address: 156.154.66.196#53
    Default server: pdns196.ultradns.biz
    Address: 2610:a1:1015::e8#53
    > pornhub.com
    Server:		pdns196.ultradns.biz
    Address:	156.154.66.196#53
    Name:	pornhub.com
    Address: 31.192.120.36
Right now, if your site is in trouble, I'd suggest getting UltraDNS service and AWS DNS service, and some obscure service as well, and put them them all in your domain registration. DNS service is cheap. Get some redundancy going. We have no idea how long this DDOS attack will last. It's not costing the attackers anything. They might leave it running for days.

Re: DDoS Attack Against Dyn Managed DNS

#527
post #441

Earlier quoted context omitted.

Let's try to put this DDoS attack in some context aside from the technical part. As @scrollaway mentioned, 6 weeks ago, Bruce Schneier posted that several companies told him that they're detecting attempts to probe their networks and find ways to bring it down https://www.schneier.com/blog/archives/2016/09/someone_is_le... Now let's look at the progress of events: - Hillary Clinton's personal email server was hacked…

> Say Hello to World War III, everybody! Is this sabre rattling or the prelude to a global conflict? Surely at worst it will (continue to) be a proxy war between NATO and Russia in Syria and nothing more? What motive is there for Russia or NATO to engage in open warfare? I'm not sure that a slow and prolonged lead up to an open war would even be effective in this situation. Perhaps it should be "Say hello to Cold War…

Hopefully they stick to semver

Re: DDoS Attack Against Dyn Managed DNS

#528

Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)

Let's try to put this DDoS attack in some context aside from the technical part. As @scrollaway mentioned, 6 weeks ago, Bruce Schneier posted that several companies told him that they're detecting attempts to probe their networks and find ways to bring it down https://www.schneier.com/blog/archives/2016/09/someone_is_le... Now let's look at the progress of events: - Hillary Clinton's personal email server was hacked…

> - Russia's only air craft carrier is trespassing through UK waters to get to Syria in a show of force that doesn't really add anything to their military capabilities there.

I read they were passing in international waters. Is that not the case? It's clearly a show of force, but no need for the hyperbole if it is not true.

Re: DDoS Attack Against Dyn Managed DNS

#529

So who was prepared for this? Pornhub: pornhub.com: Name Server: ns1.p44.dynect.net Name Server: ns2.p44.dynect.net Name Server: ns3.p44.dynect.net Name Server: ns4.p44.dynect.net Name Server: sdns3.ultradns.biz Name Server: sdns3.ultradns.com Name Server: sdns3.ultradns.net Name Server: sdns3.ultradns.org ultradns.biz: Name Server: PDNS196.ULTRADNS.ORG Name Server: ARI.ALPHA.ARIDNS.NET.AU Name Server: ARI.BETA.ARIDN…

Amazon was Using Dyn, now they added also UltraDNS too:

  Name Server: pdns1.ultradns.net 
  Name Server: pdns6.ultradns.co.uk 
  Name Server: ns3.p31.dynect.net 
  Name Server: ns1.p31.dynect.net 
  Name Server: ns4.p31.dynect.net 
  Name Server: ns2.p31.dynect.net

Re: DDoS Attack Against Dyn Managed DNS

#530

Earlier quoted context omitted.

Let's try to put this DDoS attack in some context aside from the technical part. As @scrollaway mentioned, 6 weeks ago, Bruce Schneier posted that several companies told him that they're detecting attempts to probe their networks and find ways to bring it down https://www.schneier.com/blog/archives/2016/09/someone_is_le... Now let's look at the progress of events: - Hillary Clinton's personal email server was hacked…

I just want to sell my software, why does everyone have to fight?! Thank you for these links. I'm trying not to get wrapped up in conspiracies but am increasingly worried by the mounting conflict. I'd love to hear a calm, reasoned response from someone more knowledgable than me on these topics.

Yeah I've gotten a little wrapped up as well looking into all of this mounting tension between the US and Russia. Protip, stay away from /r/the_donald.

My personal opinion is that it is mostly political and I think (hope) that what is happening in Syria won't escalate to direct conflict between the US and Russia.

I stumbled across this little blog article the other day and it helped relieve some of my anxieties.

https://cluborlov.blogspot.com/2016/10/oopsa-world-war.html

Post reply on HN