Live data from Hacker News

Basecamp was under network attack

gist.github.com

101–110 of 194 posts

Re: Basecamp was under network attack

#101
post #41

Earlier quoted context omitted.

How is torrents protocol used to DDoS you? I never came across torrents being used as a DDoS. I would appreciate more details on what sort of torrent attack it was, and whether you found any ways of partially neglecting damage.

A malicious tracker, or a peer if using DHT, can claim an IP, the victim, is active in the swarm and has valuable bits of the torrent. Then torrent clients will try to connect to the victim. The attack is pretty clever, being indirect it is hard to trace and because bittorrent allows arbitrary ports you can hit a specific ip & port pair. The one downside is the victims can be sure it is a bittorrent DDOS by checking…

The attacker's packets will contain bittorrent's magic connection bits.

ISTM that once you've determined bittorrent is the attack vector, the hard part is done? Is dropping by "magic bits" harder than dropping by ip/port?

Re: Basecamp was under network attack

#102
post #20

Earlier quoted context omitted.

It depends if this attack is on basecamp.com or the IPs that basecamp.com resolves to. It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.

> so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. Why would it be easier for the attacker to find their direct servers if they only have a /23 - doesn't Cloudflare obscure the identity/location/IP of the server on the other side?

It's only 512 addresses, so the attacker can just switch between different IPs until service degrades and keep on that address. Also, it's likely their rack/cage has a limited amount of bandwidth compared to the whole datacenter, so they can just send traffic to that range and overload the switch.

Re: Basecamp was under network attack

#103
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

> It doesn't matter if your excuse is true, it's still an excuse.

That's not wise, it's just being an asshole. Reasonable people understand that things happen sometimes despite our best efforts. You can spend your life railing at people getting hit by metaphorical meteors, until you're hit by one yourself, or you can take a minute to work with people, be a little flexible, and win your time "investment" back many times over in return.

And Cloudflare is hardly a panacea for DDOS attacks.

Re: Basecamp was under network attack

#104
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

I'm going to play devil's advocate and completely disagree with you here :) Customers, especially non-technical ones, don't give a crap. What they want to know is when the service will be back up, and what steps you're taking to prevent it happening in the future, although I'm sure a certain percentage would be interested in why this is happening in the first place (not as in the technical breakdown, but why you didn…

It's not as if this service failure is due to incompetence. And we don't know what counter-measures they used to mitigate this attack. It's impossible to be unaffected by a DDoS unless your Google or Facebook (with warehouse-sized server facilities).

I think most Basecamp users are savvy enough to understand that there's nobody to blame except for the extortionists responsible for this attacck.

Re: Basecamp was under network attack

#105
post #20
post #3

Would CloudFlare help here?

It depends if this attack is on basecamp.com or the IPs that basecamp.com resolves to. It appears Basecamp only has a /23, so even if they redirected traffic through Cloudflare, the attacker could still find their direct servers fairly easily and attack that IP. It's still possible to block, but not quite as easy as setting up Cloudflare.

...the attacker could still find their direct servers fairly easily and attack that IP.

Can the upstream to the actual server restrict traffic to known Cloudflare blocks?

Re: Basecamp was under network attack

#106
Is there something like cloudfare but more aggressive?

Like something that tries to find exploits on the machines used in the attack and try to shut them down, close their internet connection or inject a self-targeting DNS or something of the sort?

Re: Basecamp was under network attack

#107

Earlier quoted context omitted.

Not sure that your missile analogy holds. Most DDoS attacks do not attempt to crack logins to servers, but rather try to flood the servers with as much garbage as possible. Besides, even if they were trying to crack the SSH password, a properly secured server (long passwords/public key auth + fail2ban) should be fine.

Okay here is a better one. Just because people are blocking each other trying to run into your front door doesn't mean they (or somebody else) aren't cutting open your windows, picking the lock on your garage door, or trying to climb down your chimney.

Yes you do. Because DDoS, so like the service is down for users and attackers.

I'm surprised that on a technical forum there is still this complete misconception of what a DoS is.

Re: Basecamp was under network attack

#108
post #70

Earlier quoted context omitted.

Rhetoric? You've got people who just attempted to blackmail you and then take your service offline when you refuse. The descriptive term "criminal", i.e. one who breaks laws, is perfectly valid IMO.

it's just framing the scenario in good guys vs bad guys terms, it's childish regardless of how accurately the term describes the actors involved..

That is the scenario, it's not just framing it that way, it actually is that way. There's nothing childish about it.

Re: Basecamp was under network attack

#109
post #55

I wonder if there will be a day where on-premise solutions will be touted as the solution to the DDoS vulnerability of cloud-based solutions, in much the same way that there seems to be an ebb and flow between fat and thin clients over the course of computing history.

Because on-premise solutions are even more vulnerable to DDoS. A large data centre will have large amounts of connectivity, giving you a lot of head room for most types of attacks. But in this case 20Gbps of extra traffic was too much too. What on-premise solution can handle 20Gbps of extra traffic?

And I don't think Basecamp is technically "cloud", but collocated. They appear to own most or all of their servers.

Re: Basecamp was under network attack

#110
post #5

Some great language there: framing it as an attack by criminals (gains sympathy from users), explains in plain-terms what a DDOS is (front door analogy), emphasizes (twice!) that user data is safe, apologizes for the likely downtime, informs people where to get updates. Probably worth bookmarking this for when you [hopefully never] have to deal with this same situation.

They use "criminals" 5 times in that short statement. IMO the overuse of emotive language is unnecessary and belies the emotional state of the author. Stay professional and detached—it's a DDoS, I've no doubt it's frustrating but they happen. I prefer Github's recent response [0], clear and helpful but without the rhetoric. [0] https://github.com/blog/1796-denial-of-service-attacks

I like the "criminals" language. It's unfortunate they need to use it, because it points out that many people think this sort of thing is more like youthful hijinks--a type of vandalism, say--as it was when the Internet was younger. Repeating the word criminals is an excellent way to change the tenor of discussion on this topic in the public mind. I hope all companies that are ddos'd will do it, until it becomes redundant.
Post reply on HN