Live data from Hacker News

Incident Report: DNS Outage due to DDoS Attack

blog.dnsimple.com

11–13 of 13 posts

Re: Incident Report: DNS Outage due to DDoS Attack

#11
I want to apologize for my earlier downvoted comment by saying that, I only said what anyone in a software organization would say. eg your boss.

If you dont know how to run DNS, then your the wrong guy to be running it.

Dont come out in public and whine about hackers. Its your job and yours alone to know how DNS works and what to do.

Its not even mildly interesting anymore than TCP/IP is interesting. So do your job.

Thats what my boss would tell me and thats what your boss should tell you.

Its not mean what Im saying. Its the truth.

Re: Incident Report: DNS Outage due to DDoS Attack

#12

I want to apologize for my earlier downvoted comment by saying that, I only said what anyone in a software organization would say. eg your boss. If you dont know how to run DNS, then your the wrong guy to be running it. Dont come out in public and whine about hackers. Its your job and yours alone to know how DNS works and what to do. Its not even mildly interesting anymore than TCP/IP is interesting. So do your job.…

There's nothing whiny about it. They're explaining to their customers what happened which is a part of their job.

Re: Incident Report: DNS Outage due to DDoS Attack

#13
post #5

Another reminder: If you're running DNS servers, make sure you are not providing recursion: http://openresolverproject.org/

Had dnsimple failed to do so? Did it help? Because Easydns http://blog.easydns.org/2013/06/04/post-mortem-of-the-june-3... said "While most of these typically use open resolvers, it is also now common to use authoritative nameservers in reflection attacks". Can we end the "War on 'Open' Internet (Resolvers)" now? Because I don't think an organized crackdown on "open" authoritative nameservers is in the best interests…

We can end the war on open revolvers when we stop getting hit with multi-gigabit DDOS attacks from open revolvers.
Post reply on HN