Live data from Hacker News

Incident Report – DDoS Attack

blog.dnsimple.com

11–20 of 40 posts

Re: Incident Report – DDoS Attack

#11
post #2

I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515 I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling c…

"and even then you can still be screwed if your bandwidth is saturated"

Which is exactly what happened in this case. It sucks to be on the receiving end of this. We couldn't defend against it and let our customers down, and that hurts me deeply. We choose one approach to defense, which was internal, and that was a mistake. We're going to work on rectifying that now.

Re: Incident Report – DDoS Attack

#12
post #5

The solution here is one for customers, not providers. Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs). Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results d…

It seems like inbound and outbound zone transfers aren't offered by a number of providers (like AWS). Do you know of a list of DNS providers that support either option?

Re: Incident Report – DDoS Attack

#13
post #12
post #5

The solution here is one for customers, not providers. Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs). Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results d…

It seems like inbound and outbound zone transfers aren't offered by a number of providers (like AWS). Do you know of a list of DNS providers that support either option?

A search for "secondary DNS service" should give you several results.

My research into it is from a "manage your DNS records internally, then use a couple of providers for all public facing responders". In that situation all you need them to support is inbound transfers, which several do.

Re: Incident Report – DDoS Attack

#14

Earlier quoted context omitted.

I've had a similar thought RE using Route53 for Neocities. Here's the problem with Route53 though. If you get a DDoS attack using it, it's quite plausible that you would be charged for resources used in the DDoS attack. A recent Vice article discussed this: http://motherboard.vice.com/read/inside-the-unending-cyber-s... DDoS is a nasty problem. We've received a DDoS attack that shut the entire site down for days. We…

If you're going to go the Amazon route then you absolutely need to keep an eye on billing, and set up alerts so that any DDoS which caused a spike in your costs would be caught as soon as possible.

I was burnt by this in the first 48 hours of using Amazon DNS. Very unlucky I guess... I'm amazed they still bill for DDOS traffic, or even traffic from black-listed IPs. It seems many of their competitors don't.

Re: Incident Report – DDoS Attack

#17
Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source of DDoS attacks?

Investing in anti DDoS devices is important but even more important is for the perpetrators to face the consequences of their acts (or anyone who lets his machine being used by pirates - terminating or suspending their contract would be a fair response).

Re: Incident Report – DDoS Attack

#18
post #17

Out of curiosity, what are the follow ups of an attack like that? The perpetrators are probably using their own servers or compromised clients or servers. Would DNS Simple follow up on this with the abuse/complaint dept of the ISP of the attackers? Are ISP typically responsive to abuse and complaints? If they are not is there any way to black list blocks of IPs assigned to ISP who do not care about being the source o…

I was looking at http://map.ipviking.com earlier and it was apparent it was a botnet, most likely innocent home users with a virus.

Re: Incident Report – DDoS Attack

#19
post #12
post #5

The solution here is one for customers, not providers. Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs). Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results d…

It seems like inbound and outbound zone transfers aren't offered by a number of providers (like AWS). Do you know of a list of DNS providers that support either option?

I used to use these two services together do this:

  https://puck.nether.net/dns
  https://acc.rollernet.us/
They're both free to sign up, provide free secondary DNS, zone transfers and fully support IPv6.

I only stopped using them because I wanted to run my own DNS service.

Re: Incident Report – DDoS Attack

#20
post #3

So who do you think the "well-known third-party service that provides external DDoS protection using reverse DNS proxies" is they're going to use now? CloudFlare?

I would assume Prolexic or Incapsula, assuming they're using a high end provider (which they should, DDOS attacks against smaller DNS providers being so easy to carry out).
Post reply on HN