Live data from Hacker News

Fastmail, Runbox, and Posteo under DDoS extortion attack

therecord.media

111–120 of 130 posts

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#111

If you didn’t want to depend on a big provider like AWS or Cloudflare, what is the approach to fending off a DDoS attack? What type of hardware would you need to acquire? What type of software? Are there guides on this type of thing?

You need a massive amount of bandwidth and a few redundant servers. There are counties with less bandwidth than you need to handle. It isn't impossible, but cloudflare isn't evil (that I know of?) and so it is best to support them as your backup

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#112
post #108

Well that explains it, I literally switched from gmail to fastmail 2 days ago and it was going amazingly until last night when I couldn't load it. "Oh great, an unreliable service I just paid a year for" -- this makes me want to support them even more. Their customer support was fantastic. I didn't inquire about the outage, instead a dns issue I'd created. If you're a heavy gmail user you should read this story of my…

I feel like I hear more and more of these horror stories. I’ve been looking to migrate my custom domain away from Google for a while and was also looking at Fastmail. I use an @gmail.com for everyday things because it’s widely recognised and easy to communicate to people over the phone or even face to face in a shop for a digital receipt.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#113
post #108

Well that explains it, I literally switched from gmail to fastmail 2 days ago and it was going amazingly until last night when I couldn't load it. "Oh great, an unreliable service I just paid a year for" -- this makes me want to support them even more. Their customer support was fantastic. I didn't inquire about the outage, instead a dns issue I'd created. If you're a heavy gmail user you should read this story of my…

I feel like I hear more and more of these horror stories. I’ve been looking to migrate my custom domain away from Google for a while and was also looking at Fastmail. I use an @gmail.com for everyday things because it’s widely recognised and easy to communicate to people over the phone or even face to face in a shop for a digital receipt.

About the domain, I recommend you get your own domain if you ever migrate off Gmail. That way you hopefully won't have to do it again anytime soon, even if you move to another provider

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#114
post #108

Well that explains it, I literally switched from gmail to fastmail 2 days ago and it was going amazingly until last night when I couldn't load it. "Oh great, an unreliable service I just paid a year for" -- this makes me want to support them even more. Their customer support was fantastic. I didn't inquire about the outage, instead a dns issue I'd created. If you're a heavy gmail user you should read this story of my…

I feel like I hear more and more of these horror stories. I’ve been looking to migrate my custom domain away from Google for a while and was also looking at Fastmail. I use an @gmail.com for everyday things because it’s widely recognised and easy to communicate to people over the phone or even face to face in a shop for a digital receipt.

Thanks for the reminder that one of my most critical domain names is still on google domains. I've started using porkbun for newer domains I get but I still have the main one on google. I need to get that off before they lock me out of the console or something ridiculous.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#116

Coincidentally, the app password that I've used for Fastmail's CalDAV service for years suddenly started causing 403's today. I wonder if that's related (but can't think of how it could be)

(I work for Fastmail.) One of our attempts at doing some mitigation of the attack caused this; we fixed it about 16:00 US Eastern this afternoon. Sorry about that!

Without getting into too much detail: we were limiting some HTTP methods, but unintentionally blocked REPORT, which DAV clients use to see what’s changed.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#117

We still hear about DDoS attacks like this once in a while but it seems it's not anywhere near as common as it used to be. What happened? It looks like the bad guys are really having more and more trouble mounting succesful DDoS: how comes? It also looks like, in despair, they're targetting smaller fishes. Why? Smaller botnets? Cloudflare and OVH and the likes just being too good at absorbing everything and anything…

Maybe ransomware. A bit speculative, but my hunch is -- IOT and some other advancements still create opportunities for new DDoS attacks, but attackers herd. And the "X as a service" support infrastructure is mostly supporting ransomware right now, likely because its safer and more lucrative. You can walk away from a ransomware target, fire and forget, so you can do it at scale. DDoS you have to pick your victims, and…

That is already a thing and has been for a while now. Unless you are describing a new version with it but it's already there

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#118

Coincidentally, the app password that I've used for Fastmail's CalDAV service for years suddenly started causing 403's today. I wonder if that's related (but can't think of how it could be)

(I work for Fastmail.) One of our attempts at doing some mitigation of the attack caused this; we fixed it about 16:00 US Eastern this afternoon. Sorry about that! Without getting into too much detail: we were limiting some HTTP methods, but unintentionally blocked REPORT, which DAV clients use to see what’s changed.

This is going to sound weird, but my father can't send email with attachments currently. I'm a long time fastmail user/customer and I'm also a long time IT guy so can't see what's going on.

Basically SMTP login and everything works fine, client sends the message and then it just times out.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#119

We still hear about DDoS attacks like this once in a while but it seems it's not anywhere near as common as it used to be. What happened? It looks like the bad guys are really having more and more trouble mounting succesful DDoS: how comes? It also looks like, in despair, they're targetting smaller fishes. Why? Smaller botnets? Cloudflare and OVH and the likes just being too good at absorbing everything and anything…

The general quality of DDoS scrubbing services has dramatically improved in the last 10 years. I work for a large tech company and Silverline has protected us from 100G+ attacks.

What about 250, 500, 1tbps. Hell 2.5 is possible now

100gbps is basically trivial test for a new botnet

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#120
post #85

Earlier quoted context omitted.

How that's a good point: especially that if you DDoS while asking for a ransom, you take the risk that your botnets gets taken down. While if you "discretly" mine CPU (and/or GPU?) mineable cryptocurrencies, you kinda fly under the radar.

You DDoS from routers and other embedded devices which aren’t capable of mining anything.

There are bandwidth-based coins.
Post reply on HN