Live data from Hacker News

DNSimple DDOS Attack

dnsimplestatus.com

71–80 of 120 posts

Re: DNSimple DDOS Attack

#71
post #44

Earlier quoted context omitted.

DNSimple is widely know for the ALIAS pseudo-"record" because they invented it[1]. Small wonder that a proprietary syntactical sugar leaves you at the mercy of select vendors? As for volumetric attacks: your point is correct, but is irrelevant if you're using multiple vendors, and a specific, single vendor is the target, like it appears here. Your other authoritative servers would be unaffected. 1 http://support.dnsi…

good luck finding any major online property or infrastructure that isn't making use of some kind of proprietary syntactical dns sugar. it doesn't mean you can't span providers, but it does mean it takes a lot more work to do so. anyway, you're not wrong, the best approach to mitigate this kind of thing is to leverage multiple dns networks. but doing so is not easy unless the application is still using dns like it was…

Using a WWW subdomain with CNAMEs accomplishes effectively the same thing as using ALIAS on an apex domain name, and doesn't rely on anything out-of-spec or proprietary, making it easier to serve redundantly. (Did you ever wonder why google.com and facebook.com redirect to www?)

(Or is there more to ALIAS than that, which wasn't on the page in GP? Happy to be corrected if so)

Re: DNSimple DDOS Attack

#72
post #39

"30 minute ETA from our network provider to begin scrubbing traffic in a location with capacity." https://twitter.com/dnsimplestatus/status/539551209452232705

"New ETA is 30 minutes from now, trying to get systems wired up in the data center."

https://twitter.com/dnsimple/status/539560631863877632

Re: DNSimple DDOS Attack

#74
Can someone help me understand what happens to email sent to a domain hosted by DNSimple while it's down?

I'm hoping it will get queued by the sending server, and make it's way back when DNSimple is up and running. Is that correct?

Re: DNSimple DDOS Attack

#75
post #60

Earlier quoted context omitted.

Will these services not have the same thin pipe issue that's currently affecting DNSimple?

Not that I have any reliable info, but what I've heard, DNS Made Easy is a pretty stable and established DNS provider. They brag about "99.9999% uptime history" at http://www.dnsmadeeasy.com/technology/ . Though they doesn't seem as innovative and nice as DNSimple. Really hope things work out for DNSimple (really like the idea of their beta feature GitHub sync).

How does their beta-feature with github work? I can't find any obvious link and it seems frustratingly close to something I offer over at https://dns-api.com/ ..

(I wrap Amazon's route53 with DNS entries read from github/gitbucket/similar.)

Re: DNSimple DDOS Attack

#76
post #74

Can someone help me understand what happens to email sent to a domain hosted by DNSimple while it's down? I'm hoping it will get queued by the sending server, and make it's way back when DNSimple is up and running. Is that correct?

It will depend on the configuration of the sending server. Some will retry for a while, some will return failures.

Re: DNSimple DDOS Attack

#77
post #76
post #74

Can someone help me understand what happens to email sent to a domain hosted by DNSimple while it's down? I'm hoping it will get queued by the sending server, and make it's way back when DNSimple is up and running. Is that correct?

It will depend on the configuration of the sending server. Some will retry for a while, some will return failures.

Thanks!

Re: DNSimple DDOS Attack

#78
I moved from Zerigo to DNSimple, and it's been awesome until now!

What can you do to prevent this in future? Can you run multiple DNS providers simultaneously? So, ns1/ns2 go to DNSimple, and ns3/ns4 go to another provider?

Re: DNSimple DDOS Attack

#79

Earlier quoted context omitted.

Not that difficult for whom? Great if you have the in-house resources to devote to managing your own DNS (and can't put them to better use elsewhere), but that is not the case for the vast majority of us. The fact that so many of us use PaaS companies like Heroku should be a pretty big indicator that most platform-related engineering is not going to happen in-house under a certain scale.

Not that difficult for somebody who is a sysadmin or developer. I would hope that services like Heroku offer DNS too, but I wouldn't know. If your site is already hosted at Heroku, it would be better for them to deal with your DNS so that you don't introduce additional third parties. That is my point.

Ah, I entirely misunderstood your point. I thought the point was that the end users of DNS should be hosting. My mistake.

Re: DNSimple DDOS Attack

#80
post #37
post #31

Earlier quoted context omitted.

One of the most valuable things I learned in my career was to never kick your competitors when they are down. It upsets the karma gods, and makes you look like a total douchebag. The best thing you can do right now is to reach out and offer your help, privately. Even from a selfish perspective, you'll learn a lot about the attack that is taking them down now which will help you out when the targeted customer inevitab…

hi. i did not mean to spam or kick dnsimple, we know them and they are a great company and service. we are actively receiving inbound queries about this from folks asking for help, so thought it made sense to chime in publicly here. but you're right, i should have kept it on topic to the discussion at hand instead of offering anything else up. you're not wrong: in this industry you never kick your competitors when th…

dsl (1402 days old, 4664 karma) - beevek (123 days old, 4 karma). beevek you just lost our business.
Post reply on HN