Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

581–590 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#582
post #566

Earlier quoted context omitted.

It's been years since we did that, and they were not spam pages, and easily able to opt-out.

That is not an appropriate tone for someone representing OpenDNS to take.

Why not? It's blunt, but to the point, honest, and passionate. Who cares about tone?

Re: DDoS Attack Against Dyn Managed DNS

#583

So who was prepared for this? Pornhub: pornhub.com: Name Server: ns1.p44.dynect.net Name Server: ns2.p44.dynect.net Name Server: ns3.p44.dynect.net Name Server: ns4.p44.dynect.net Name Server: sdns3.ultradns.biz Name Server: sdns3.ultradns.com Name Server: sdns3.ultradns.net Name Server: sdns3.ultradns.org ultradns.biz: Name Server: PDNS196.ULTRADNS.ORG Name Server: ARI.ALPHA.ARIDNS.NET.AU Name Server: ARI.BETA.ARIDN…

Digikey just dumped Dyn, and is now back up.

digikey.com:

    Name Server: cbru.br.ns.els-gms.att.net
    Name Server: ns2.digikey.com
    Name Server: cmtu.mt.ns.els-gms.att.net
    Name Server: ns1.digikey.com

Re: DDoS Attack Against Dyn Managed DNS

#584
post #352

Earlier quoted context omitted.

> Hang on a second. I feel that you're piling on other resolver changes in order to make a point. Yes. The point I am making is the additional failure modes that need to be considered and the pain they can cause. Historically have caused. At no point did I ever think you were suggesting that one failure to respond renders a server dead to your resolver forever. Instead, I expect that your resolver will see a failure…

Please stop trolling. None of the issues you're raising apply to his original idea, and it's already implemented by OpenDNS with significant upside and virtually no downside.

I'm afraid we're simply going to have to agree to disagree on this point. I do not share the opinion that this is a good idea with significant upside and virtually no downside. I also do not agree that none of the issues I have raised apply to the original suggestion - I believe they do apply, which is why I raised them.

Re: DDoS Attack Against Dyn Managed DNS

#585
post #532

The DDoS problems, at least those not related to spoofing IPs, could be curtailed if we provide a strong incentive to the ISPs to work on it. Let's hold the ISPs financially liable for the harmful traffic that comes from their network. If a client reports a harmful IP to the ISP, every bit of subsequent traffic sent from that IP to this client carries a penalty. Yeah, I know, routing tables are small, yada yada. If w…

Put the thumbscrews on the IoT manufacturers instead, so they don't release widgets with bad security, so the problem is eliminated at its root. You wouldn't allow car manufacturers to sell cars with faulty airbags, why do we allow device manufacturers to provide plentiful firepower for bad actors?

With ISPs it's a lot easier - you know who your ISP is, so either they respect your blacklist or they automatically owe you money.

How would you even start chasing a manufacturer of a cheap IP cam from China? How many of them can you chase at once?

Re: DDoS Attack Against Dyn Managed DNS

#586
post #441

Earlier quoted context omitted.

> Say Hello to World War III, everybody! Is this sabre rattling or the prelude to a global conflict? Surely at worst it will (continue to) be a proxy war between NATO and Russia in Syria and nothing more? What motive is there for Russia or NATO to engage in open warfare? I'm not sure that a slow and prolonged lead up to an open war would even be effective in this situation. Perhaps it should be "Say hello to Cold War…

Hopefully they stick to semver

Your threat can't be parsed due to depreciation of the old rhetoric API. Please upgrade your rhetoric to 2.3.x.

Re: DDoS Attack Against Dyn Managed DNS

#587
post #524

Earlier quoted context omitted.

That's not how that sound be done. Just use a mix of two providers. Using your own servers and TinyDNS is silly for million/billion dollar companies. See MaxCDN for example who uses a mix of dns providers (AWS Route53 and NS1): ns-5.awsdns-00.com. ['205.251.192.5'] [TTL=172800] ns-926.awsdns-51.net. ['205.251.195.158'] [TTL=172800] ns-1762.awsdns-28.co.uk. ['205.251.198.226'] (NO GLUE) [TTL=172800] ns-1295.awsdns-33.…

No tool is silly as long as it does the job adequately. Are paperclips silly for a billion-dollar company? If both Dyn and R53 go down, it's exactly when you want a service like PagerDuty work without a hitch.

You're asserting that your (or their) homegrown DNS service will have better reliability than Dyn and Route53 combined. That assertion gets even worse when it's a backup because people never, ever test backups. And "ready to go" means an extremely low TTL on NS records if you need to change them (which, for a hidden backup, you will), and many resolvers ignore that when it suits them, so have fun getting back to 100% of traffic.

Spoiler: I'd bet my complete net worth against your assertion and give you incredible odds.

Golden rule: Fixing a DNS outage with actions that require DNS propagation = game over. You'd might as well hop in the car and start driving your content to people's homes.

Re: DDoS Attack Against Dyn Managed DNS

#588

Earlier quoted context omitted.

No, not necessarily journalists; rahter, an information source...Fortune - a site/company known for journalism/reporting - now just gave HackerNews more legitimacy as an official information source ...Now with this power, please use it responsibly. ;-)

Too bad that the majority of the readers will think that HackerNews is somehow related to the "Hackers" that took down the internet.

Eh the name implies (at least in that context) this website would be used to keep track of the hackers.

Re: DDoS Attack Against Dyn Managed DNS

#589

Earlier quoted context omitted.

Russia retaliating for the US taking out the ESA Mars Drone.

What's this about? Confusing premise. Got any links?

Not a joke, just conjecture.

Some NPR story about US Cybercommand responding to Russian cyber attacks, 'at place and time of our choosing.'

'Some you might hear about. Some you might not.'

FFWD to a couple days ago, NPR story about a botched European and Russian lander.

Today, US Eastern Seaboard is seeing connectivity disruption due to DDoS attacks.

*

Unwinding the stack, the latest news is these DDoS attacks are not likely state sponsored.

Russia pulling off a coordinated attack that soon after and in response to my theorized US retaliation seems unlikely.

US attacking a joint partnership between Russia and Europe civilian space program seems unlikely.

Re: DDoS Attack Against Dyn Managed DNS

#590
post #566

Earlier quoted context omitted.

A shame OpenDNS used to redirect me to some spam webpage every time I tried to resolve a domain that didn't exist--they earned a spot on my black list forever. :(

It's been years since we did that, and they were not spam pages, and easily able to opt-out.

[deleted]
Post reply on HN