Earlier quoted context omitted.
A shame OpenDNS used to redirect me to some spam webpage every time I tried to resolve a domain that didn't exist--they earned a spot on my black list forever. :(
It's been years since we did that, and they were not spam pages, and easily able to opt-out.
DDoS Attack Against Dyn Managed DNS
651–660 of 721 posts
Re: DDoS Attack Against Dyn Managed DNS
#652Journalist and security researcher Brian Krebs believes this is someone doing a DDoS as payback for research into questionable "DDoS mitigation services" that he and Dyn's Doug Madory did. Doug just presented his results yesterday at NANOG and Krebs believes this is payback. Read more: https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twit...
Re: DDoS Attack Against Dyn Managed DNS
#653Earlier quoted context omitted.
I had several, sporadic 'secure connection could not be established' yesterday while trying to open HN, amongst others. Painfully slow page load times across the board, too(Craigslist, Monoprice,weather.gov, etc) Still may be my buggy phone SIM...
wait, buggy phone sims is a thing?
Re: DDoS Attack Against Dyn Managed DNS
#654Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)
Let's try to put this DDoS attack in some context aside from the technical part. As @scrollaway mentioned, 6 weeks ago, Bruce Schneier posted that several companies told him that they're detecting attempts to probe their networks and find ways to bring it down https://www.schneier.com/blog/archives/2016/09/someone_is_le... Now let's look at the progress of events: - Hillary Clinton's personal email server was hacked…
Finland isn't worried, they have had stable relations for half a century as both sides agreed to not mess with each other. They have even refused to join NATO because it is actually safer for Finland and vice versa.
Cowboys with missiles stationed on Russia's border making hyperbole statements (like you do) - now that would be a real threat. (the same was also true the other way around with the Soviets stationing missiles in Cuba)
Re: DDoS Attack Against Dyn Managed DNS
#655Earlier quoted context omitted.
It's been years since we did that, and they were not spam pages, and easily able to opt-out.
Well, the fact that people still remember goes to show what a truly terrible idea it really was and that it probably did permanent damage to your brand.
Ironically, those unrealistic expectations are probably a significant factor in the growth of data mining and resell; how else is a free-to-use website that doesn't have any ads (or whose users mostly block ads) going to get paid? You may say "not my problem", but it affects you when you leave the company no option but to resell data on the behaviors they observe from you.
Re: DDoS Attack Against Dyn Managed DNS
#656Earlier quoted context omitted.
Try Akamai managed CDN content. 20 seconds !!
The 20 seconds with Akamai is because of their dynamic end user IP mapping technology, Basically they need to map in near real-time based on characteristics of the end user IP, they can't afford a long TTL
http://www.infoworld.com/article/3133104/mobile-technology/w...
Re: DDoS Attack Against Dyn Managed DNS
#657Journalist and security researcher Brian Krebs believes this is someone doing a DDoS as payback for research into questionable "DDoS mitigation services" that he and Dyn's Doug Madory did. Doug just presented his results yesterday at NANOG and Krebs believes this is payback. Read more: https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twit...
If so that's a quick turnaround.
Krebs indicates in an update at the end that a source had heard rumors in criminal channels that an attack against Dyn was being planned.
Doug Madory's presentation was on the agenda for NANOG and so attackers would have had plenty of time to know about it.
Re: DDoS Attack Against Dyn Managed DNS
#658Earlier quoted context omitted.
The attack is on the DNS servers, which take names like www.github.com and resolve them to ip addresses (i.e. 192.30.253.112 for me). Their status page is status.github.com - it is on the same domain name (github.com) as the rest of the site. Normally this isn't a problem because availability is usually something going on with a server, not DNS. In this case, the servers (DNS server under attack at Dyn) that knows ho…
Right, this was my point. Hosting "status.domain.com" doesn't help much when it's "domain.com" that's having the problem. I think today's event will make a lot of companies consider this a bit more.
Anyway, for them to take the github.com nameservers out of the mix they would need a completely separate domain name; would you know to look there?
You can delegate subdomains to other providers, but the NS records are still present in the servers listed in the registrar. So, you'd already need multiple DNS providers.. And you wouldn't have been down. Just sayin. I'm not sure anyone rated a DNS provider of this status getting hit this hard or completely as high enough risk to go through the trouble.
It's easy enough to look at a system and point out all the things you depend on as being a risk. The harder part is deciding which risks are high enough priority to address instead of all the other work to be done.
Re: DDoS Attack Against Dyn Managed DNS
#659Krebs on Security: https://news.ycombinator.com/item?id=12761859
NY Times: https://news.ycombinator.com/item?id=12765652
Re: DDoS Attack Against Dyn Managed DNS
#660Recent IoT-based Attacks: What Is the Impact On Managed DNS Operators? - http://hub.dyn.com/traffic-management/recent-iot-based-attac...
It's a good piece about how IoT-based DDoS attacks are carried out. And now Dyn has the answer...
HN thread about that article at: https://news.ycombinator.com/item?id=12764650