Live data from Hacker News

Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

dynstatus.com

51–60 of 94 posts

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#51

This attack looks like another probing into critical internet infrastructure Bruce Schneier had talked about. Who's next?

Nothing seems to be loading on YouTube and Hulu this morning, FWIW. http://downdetector.com/status/hulu http://downdetector.com/status/youtube

YT is fine for me here.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#52
post #15

Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…

I have an opposite question. Why does anyone even need to run their own non-cache nameserver ?

My current understanding of dns infra is, We have root nameservers which takes record change request, apply to itself and send it to other listening root nameservers & cache nameservers. The dns root nameservers would be extremely ddos resilient, more than any other kind of servers. Considering millions of dollars get spent per year on domain keeping, its fair to expect it too.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#54
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

Sometimes the free market needs a little help, due to the tragedy of the commons [1].

That's why the FCC has regulations on interference created by electronic devices. Reducing interference costs money. The free market punishes extra costs. The situation of networked devices with security-impacting bad features is analagous.

[1] https://en.wikipedia.org/wiki/Tragedy_of_the_commons

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#56
post #32
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

I agree with you. IoT devices inside a SOHO should communicate externally through a proxy gateway device. IoT devices should only have communications in a p2p network in a LAN, and have strong restrictions or none access to WAN. Any type of updates should be given from a proxy device having proper hardening than a normal IoT device.

The router could provide password-protected web proxy to access the LAN IOT webserver. Then you've reduced the attack surface to the router.

It almost seems like we need some protocol extensions:

1) Standard auth protocol (not just web-based) for the router to protect the local computers. Some kind of user-and-software-friendly firewall. This could even extend to game servers and whatnot - what if the "shared password" for connecting to a hosted game server had the shared password implemented at router protocol level?

2) DHCP registration on a network should require a name, one that the user was prompted to provide at some point. No more identifying devices on you router by IP or MAC. You already need to provide a name for SMB or DNS, just finish the job and name all DHCP clients. Possibly this should work with DNS in some way.

This way user-friendly logging information can be presented to the user. Without that, routers don't have the critical information needed to tell the user which device is screwing up.

Edit: Google tells me this is already a thing... Sadly, good conformance on providing meaningful DHCP client names won't happen unless the FCC et al start testing IP-enabled devices for it.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#57
The free market will solve this problem with an existing and efficient tool.

Tort law.

A few wins in court will do the trick. Here is how.

A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack.

As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the risk created by the product. It is far easier to take the product off the shelf. Therefore the manufacturer must either make a better product or die.

We don't need government regulation. We just need time. The legal system will do what it is designed to do: assign economic consequences to the right parties.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#58
post #3

I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)

Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.

This is an interesting approach to get past NAT: https://thehackerblog.com/sonar-a-framework-for-scanning-and...

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#59

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

[deleted]

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#60

The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…

You say this as if it is just one device used in these attacks. And as if it will be easy to stroll over to the owner's location and determine the supply chain of that one device. And as if it will be easy to collect from the Chinese manufacturer who probably folded last week and reopened under a different name for completely different reasons.
Post reply on HN