Live data from Hacker News

Incident Report: DNS Outage due to DDoS Attack

blog.dnsimple.com

1–10 of 13 posts

Re: Incident Report: DNS Outage due to DDoS Attack

#5

Another reminder: If you're running DNS servers, make sure you are not providing recursion: http://openresolverproject.org/

Had dnsimple failed to do so? Did it help?

Because Easydns http://blog.easydns.org/2013/06/04/post-mortem-of-the-june-3... said "While most of these typically use open resolvers, it is also now common to use authoritative nameservers in reflection attacks".

Can we end the "War on 'Open' Internet (Resolvers)" now?

Because I don't think an organized crackdown on "open" authoritative nameservers is in the best interests of our freedom.

Re: Incident Report: DNS Outage due to DDoS Attack

#8
post #7

Is there something "going on" with DNS DDOS right now, or have I just happened to notice several in the last few days? cloudns.net, EasyDNS, and now dnsimple.com - all in the last week...

I don't think it's anything out of the ordinary. Attacks happen quite regularly, most are mitigated quickly and quietly.

Re: Incident Report: DNS Outage due to DDoS Attack

#10
post #5

Another reminder: If you're running DNS servers, make sure you are not providing recursion: http://openresolverproject.org/

Had dnsimple failed to do so? Did it help? Because Easydns http://blog.easydns.org/2013/06/04/post-mortem-of-the-june-3... said "While most of these typically use open resolvers, it is also now common to use authoritative nameservers in reflection attacks". Can we end the "War on 'Open' Internet (Resolvers)" now? Because I don't think an organized crackdown on "open" authoritative nameservers is in the best interests…

No, this was not due to open resolvers in this case. We do not run public resolvers - we only provide authoritative DNS.
Post reply on HN