This attack looks like another probing into critical internet infrastructure Bruce Schneier had talked about. Who's next?
Nothing seems to be loading on YouTube and Hulu this morning, FWIW. http://downdetector.com/status/hulu http://downdetector.com/status/youtube
Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
51–60 of 94 posts
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#52Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…
My current understanding of dns infra is, We have root nameservers which takes record change request, apply to itself and send it to other listening root nameservers & cache nameservers. The dns root nameservers would be extremely ddos resilient, more than any other kind of servers. Considering millions of dollars get spent per year on domain keeping, its fair to expect it too.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#53I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#54I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…
That's why the FCC has regulations on interference created by electronic devices. Reducing interference costs money. The free market punishes extra costs. The situation of networked devices with security-impacting bad features is analagous.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#55Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#56I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…
I agree with you. IoT devices inside a SOHO should communicate externally through a proxy gateway device. IoT devices should only have communications in a p2p network in a LAN, and have strong restrictions or none access to WAN. Any type of updates should be given from a proxy device having proper hardening than a normal IoT device.
It almost seems like we need some protocol extensions:
1) Standard auth protocol (not just web-based) for the router to protect the local computers. Some kind of user-and-software-friendly firewall. This could even extend to game servers and whatnot - what if the "shared password" for connecting to a hosted game server had the shared password implemented at router protocol level?
2) DHCP registration on a network should require a name, one that the user was prompted to provide at some point. No more identifying devices on you router by IP or MAC. You already need to provide a name for SMB or DNS, just finish the job and name all DHCP clients. Possibly this should work with DNS in some way.
This way user-friendly logging information can be presented to the user. Without that, routers don't have the critical information needed to tell the user which device is screwing up.
Edit: Google tells me this is already a thing... Sadly, good conformance on providing meaningful DHCP client names won't happen unless the FCC et al start testing IP-enabled devices for it.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#57Tort law.
A few wins in court will do the trick. Here is how.
A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack.
As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the risk created by the product. It is far easier to take the product off the shelf. Therefore the manufacturer must either make a better product or die.
We don't need government regulation. We just need time. The legal system will do what it is designed to do: assign economic consequences to the right parties.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#58I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)
Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#59The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#60The free market will solve this problem with an existing and efficient tool. Tort law. A few wins in court will do the trick. Here is how. A victim of a DDoS attack sues manufacturers, distributors, and retailers of that product for selling a defective product--the IoT device used in the IoT attack. As soon as there is a win, the product disappears. Distributors and retailers must now price in the externality of the…