Live data from Hacker News

DNSimple DDOS Attack

dnsimplestatus.com

31–40 of 120 posts

Re: DNSimple DDOS Attack

#31
post #27

[deleted]

One of the most valuable things I learned in my career was to never kick your competitors when they are down. It upsets the karma gods, and makes you look like a total douchebag.

The best thing you can do right now is to reach out and offer your help, privately. Even from a selfish perspective, you'll learn a lot about the attack that is taking them down now which will help you out when the targeted customer inevitably signs up for your service.

EDIT: The parent comment was spam from Kris Beevers at NSone.

Re: DNSimple DDOS Attack

#32
post #26
post #19

Anyone switching from DNSimple? I really don't want to, but we've been down for almost 3 hours. I've seen chatter about Cloudfare and it looks pretty good, reviews?

We switched periscope.io from DNSimple to Amazon Route 53. DNSimple doesn't have an exporter so it took about an hour, including having one engineer review the other engineer's work. Many customers were able to resolve the domain in the minutes immediately following the switch, and the rest seem to be trickling in.

Are you talking about a zone file exporter? DNSimple does have one, we just used it to migrate to Route53. http://support.dnsimple.com/articles/zone-export/

EDIT: right, must have been able to log in during a brief period where dnsimple was not down.

Re: DNSimple DDOS Attack

#33
post #26

Earlier quoted context omitted.

We switched periscope.io from DNSimple to Amazon Route 53. DNSimple doesn't have an exporter so it took about an hour, including having one engineer review the other engineer's work. Many customers were able to resolve the domain in the minutes immediately following the switch, and the rest seem to be trickling in.

Are you talking about a zone file exporter? DNSimple does have one, we just used it to migrate to Route53. http://support.dnsimple.com/articles/zone-export/ EDIT: right, must have been able to log in during a brief period where dnsimple was not down.

link doesnt work

Re: DNSimple DDOS Attack

#34
post #26

Earlier quoted context omitted.

We switched periscope.io from DNSimple to Amazon Route 53. DNSimple doesn't have an exporter so it took about an hour, including having one engineer review the other engineer's work. Many customers were able to resolve the domain in the minutes immediately following the switch, and the rest seem to be trickling in.

Are you talking about a zone file exporter? DNSimple does have one, we just used it to migrate to Route53. http://support.dnsimple.com/articles/zone-export/ EDIT: right, must have been able to log in during a brief period where dnsimple was not down.

That page doesn't load for me. :)

We went by this:

https://twitter.com/dnsimple/status/539521794802483202

https://twitter.com/dnsimple/status/539520808599957505

Re: DNSimple DDOS Attack

#35

Earlier quoted context omitted.

For those with a more deterministic bent: "propagation" time has a maximum bound of your TTL, which will show with any dig queries.

Propagation is bound at the DNS TTL plus whatever time it takes your DNS provider/setup to relay records to all of its authoritative servers.

Hmm, never considered that. Is it a slow, static process for ISPs to do that? I just assumed that they ran more-or-less stock DNS resolvers with in-memory caches.

Re: DNSimple DDOS Attack

#36
post #30

DNS is so straightforward, so easily distributed, and so fundamental, that I'm always astounded when it's a single point of failure for so many operations. I wonder how many of the affected companies do have redundant appservers and load balancers, but missed this piece of the puzzle...

dns is less easily distributed when fancy features like ALIAS (which dnsimple is widely known for) are in the mix. and wide distribution isn't enough to win vs truly volumetric attacks. it takes a lot of ports and compute to absorb 100Gbps+ attacks which are not uncommon against major providers.

DNSimple is widely know for the ALIAS pseudo-"record" because they invented it[1].

Small wonder that a proprietary syntactical sugar leaves you at the mercy of select vendors?

As for volumetric attacks: your point is correct, but is irrelevant if you're using multiple vendors, and a specific, single vendor is the target, like it appears here. Your other authoritative servers would be unaffected.

1 http://support.dnsimple.com/articles/alias-record/, or http://webcache.googleusercontent.com/search?q=cache:ST1BABj...

Re: DNSimple DDOS Attack

#37
post #31
post #27

[deleted]

One of the most valuable things I learned in my career was to never kick your competitors when they are down. It upsets the karma gods, and makes you look like a total douchebag. The best thing you can do right now is to reach out and offer your help, privately. Even from a selfish perspective, you'll learn a lot about the attack that is taking them down now which will help you out when the targeted customer inevitab…

hi. i did not mean to spam or kick dnsimple, we know them and they are a great company and service. we are actively receiving inbound queries about this from folks asking for help, so thought it made sense to chime in publicly here. but you're right, i should have kept it on topic to the discussion at hand instead of offering anything else up.

you're not wrong: in this industry you never kick your competitors when they're down, everyone is subject to the same constraints, attacks, and complications. that wasn't my intention and i said so in the post.

Re: DNSimple DDOS Attack

#40
post #30

Earlier quoted context omitted.

dns is less easily distributed when fancy features like ALIAS (which dnsimple is widely known for) are in the mix. and wide distribution isn't enough to win vs truly volumetric attacks. it takes a lot of ports and compute to absorb 100Gbps+ attacks which are not uncommon against major providers.

DNSimple is widely know for the ALIAS pseudo-"record" because they invented it[1]. Small wonder that a proprietary syntactical sugar leaves you at the mercy of select vendors? As for volumetric attacks: your point is correct, but is irrelevant if you're using multiple vendors, and a specific, single vendor is the target, like it appears here. Your other authoritative servers would be unaffected. 1 http://support.dnsi…

[deleted]
Post reply on HN