Live data from Hacker News

Anonymous plans to take down the 13 root DNS servers that power the Internet?

pastebin.com

41–50 of 108 posts

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#41

And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...

Anycast in a DDoS situation would help, but if you throw enough traffic at it you end up with the original DDoS, plus a second DoS caused by cascade failure of the individual nodes going offline, causing BGP flap dampening.

Not sure if Anonymous has those kinds of resources though.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#42
I don't know if they're just simplifying things or are just clueless, but none of the 13 DNS roots are single servers. Most or all of them aren't even in a single physical site.

There's somewhere around 240 root server sites each consisting of multiple physical servers, just served up on 13 IP's.

Given that many of these sites are colocated at interchanges and with providers with tons of multi gigabit links, they have quite a challenge...

Ripe last year had an incident where they reported a fivefold increase in queries to the K-root without any operational problems, for example. They successfully handled close to 70,000 queries per second at one point.

I'll be surprised if they manage to even have a noticeable effect.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#43

And they are going to get around anycast redundancy how? [0] Also, what consumer level ISP allows egress of packets with a spoofed source IP? [0] http://www.icann.org/en/announcements/factsheet-dns-attack-0...

TFA recommends using VPN (which I assume has fewer restrictions than residential ISPs), or TOR (which has most of its outbound bandwidth on very large pipes which probably aren't filtered much).

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#44
post #15
post #4

Earlier quoted context omitted.

No, you could still get to the site with just an IP address, if you have it.

ok, thanks for the clarification. what confused me was "thus, disabling the HTTP Internet" i'm kinda glad they're attempting this, IMO. i'm tired of ignorant people not understanding what the "web" really is, and how important it is to keep it free and open. sure, this might make "hackers" look bad, but honestly, if we sit back and do nothing, then we cannot complain when laws are passed, etc.. if they pull this off,…

Did you seriously just ask how the web works, then complain about ignorant people who don't know how the web works...?

What does hackers using DDoS to knock a service offline have to do with it being free/open? Everything isn't about SOPA/ACTA/et al...

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#45
post #11

Isn't their example of google that won't be affected? I was under the impression that very few DNS queries actually go to the root nameservers as ISP's and so on have it all cached. And since I highly doubt there is any ISP that has not had a user visit google.com in the last 48 hours, Google will still function for people? In fact, the only people I can see this affecting (in the unlikely event it does happen) are p…

The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)

Most ISP's dns cache servers honor the TTL defined in the authoritative SOA records, unless is 1 minute or less.

I think the average TTL time for a dns zone would be measured in minutes. It needs to be that low in order to do SRV load-balancing, A/B testing, etc.

In any case, in the highly unlikely event that they manage to overload the 13 servers, there's plenty of time for every domain to temporarily extend the TTL on March 31.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#46
post #39
post #16

Earlier quoted context omitted.

What is the purpose of the action if not to create some small amount of terror on the part of "our irresponsible leaders"?

DOS is a kind of protest, like a picket line. Protest != terrorism.

A protest becomes terrorism when it prevents access to vital services (eg "picketing" a hospital and not allowing ambulances in/out)

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#47
post #11

Isn't their example of google that won't be affected? I was under the impression that very few DNS queries actually go to the root nameservers as ISP's and so on have it all cached. And since I highly doubt there is any ISP that has not had a user visit google.com in the last 48 hours, Google will still function for people? In fact, the only people I can see this affecting (in the unlikely event it does happen) are p…

The pastebin post says that 'While some ISPs uses DNS caching, most are configured to use a low expire time for the cache.' (Just re-iterating the post for Macha... I don't personally believe that the expire-times for ISP DNS cache is as short as Anonymous is making it seem -- but I don't have any numbers off-hand)

In my experience many ISPs do the exact opposite, and inflate cached TTLs up to a week. Makes migrations a pain in the ass.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#48

Earlier quoted context omitted.

Here.[1] Most of them are not single-box servers, but cluster with multisite redundancy. That's why all attacks were unsuccessful in the past. 1. http://en.wikipedia.org/wiki/Root_name_server

So could organizations build their own Root NS cluster and be added to the 13 that already exist? Do I misunderstand something as to why there are only 13, who controls them, etc?

* Verisign, because they inherited MCI and thus UUNet.

* USC, one of the headquarters of academic network research.

* Cogent (no idea why, but they're a sort-of tier 1 NSP).†

* UMD, another headquarters of academic network research.

* NASA, because space.

* ISC, because they organized the authorship of BIND.

* DISA, because of DARPA.

* Army Research Lab, because of .MIL.

* Whoever owns NORDU.NET, which was is a consortium of Nordic network academics.

* Verisign because they stole it from Thráin II during their final captivity in Dol Guldur.

* RIPE, because they number Europe.

* ICANN, because they ostensibly oversee the whole DNS.

* WIDE because they're like the NORDU or MERIT of Japan.

Most of this, if you can't tell, is an artifact of which organizations built the instance of the Internet that caught on in the '90s (I was going to say "that built the commercial Internet", but they didn't mostly didn't realize that was what they were doing when they did it).

Fun fact: in the early '90s, there were actual Internet netsplits, like you see on IRC, but across the Internet. Ripco, my ISP at the time, lost access to NSFNet and all of .EDU.

No, you can't add your company to this list.

Aha, it's Cogent because they bought PSI, and it was PSI because they helped build NSFNet and CIX.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#49

hmm..and people here on HN say they aren't a digital terrorist group.....

You'd have to be more clear on who "they" are. Some of them are no doubt 'digital terrorists', many are not. The they isn't the same they from campaign to campaign.

Everyone who wants to be Anonymous, is.

Re: Anonymous plans to take down the 13 root DNS servers that power the Internet?

#50
Leaving aside the why, I'm highly doubtful they'd be able to pull it off. Back in the Conficker days, it was rumored that it could be used to shut down the Internet with a similar mechanism. Conficker, I can see. Anon? Hell no.
Post reply on HN