Live data from Hacker News

Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

gizmodo.com

21–30 of 50 posts

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#21

Earlier quoted context omitted.

So, these DDOS attacks take advantage of IoT devices so how would you tell the difference using vetting when they are on the same networks as regular users?

I would just ban the ips for 24hrs if I detect an IP that is part of a ddos. After that people will wise up and unplug their nanycam/toaster/iotwhatever

You're assuming that people will know or be able to guess what is compromised. Assuming multiple IOT devices the average user won't have any clue, and will think they just need to run antivirus on their Windows box.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#22
post #6

DDOS attacks are nothing new. The scale has increased over time, but DOS has been a constant issue for as long as people have been mad on the internet. This attack is notable because it expsoes a single point of failure for a lot of popular sites. The long-term fix is to distribute that SPOF so it's not so tight a bottleneck. This is as easy as specifying nameservers from multiple providers, or as complex as a distri…

That the scale of DDoS's has increased is the entire thesis of the OP.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#23
post #15
post #10

Earlier quoted context omitted.

Please. Dyn has performed pretty well in the past, and any other provider (be it UltraDNS, CloudFlare or anybody else) would be a single point of failure as well. As you said, the only protection (somewhat) is to have redundant/multiple DNS providers. Doesn't mean Dyn can't be one of many.

They had one job. To stay up no matter what. That's the only justification for using Dyn. They failed.

No matter what is pretty tough. And it's not like they're an insurance company that can re-insure their risks.

The people who depend on DNS have one DNS-related job: to mitigate risk relative to their potential losses and existence.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#25
post #9

Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…

Junk IoT manufacturers need to feel fear. We've reached the point where any clueless business type who pooh-poohs and wishes away security concerns needs to get the idiot bit flipped on them. Today's networked computing environment has reached the point, where this stuff is toxic. It might have been okay for a few isolated frontier weirdos to play with mercury to extract gold, but then when that became a full blown i…

Selling insecure devices (be that IoT, wifi routers, etc) is almost like aiding and abetting, in the context of DoS attacks.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#26
post #6

DDOS attacks are nothing new. The scale has increased over time, but DOS has been a constant issue for as long as people have been mad on the internet. This attack is notable because it expsoes a single point of failure for a lot of popular sites. The long-term fix is to distribute that SPOF so it's not so tight a bottleneck. This is as easy as specifying nameservers from multiple providers, or as complex as a distri…

That the scale of DDoS's has increased is the entire thesis of the OP.

They've been increasing steadily for decades. Today almost certainly isn't some new record-setting attack orders of magnitude beyond what's been seen before - it isn't the herald of a new age of attacks and the "beginning of a bleak future". Claiming such is just sensationalist garbage that belies a lack of understanding of the way the internet works and the history of DDOSes in general.

Spamhaus was historic in 2013 at 75GBPS. In 2014, Cloudflare mitigated a 400GBPS attack. The BBC attack earlier this year crested 600 GBPS. Last month, OVH was hit with a 1TBPS attack. Each of those was mind-bogglingly large at the time, and infrastructure has continued to evolve to deal with them. This attack isn't anything particularly different - it's just notable because it's visible, not because it happened.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#28
post #13

Earlier quoted context omitted.

they're not down you just can't resolve the URL

as a temp solution, add these to your /etc/hosts file: 192.30.253.113 github.com 151.101.44.133 assets-cdn.github.com

I navigated to the IP address for Github, but it still tries to resolve to github.com

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#29

Earlier quoted context omitted.

Junk IoT manufacturers need to feel fear. We've reached the point where any clueless business type who pooh-poohs and wishes away security concerns needs to get the idiot bit flipped on them. Today's networked computing environment has reached the point, where this stuff is toxic. It might have been okay for a few isolated frontier weirdos to play with mercury to extract gold, but then when that became a full blown i…

Selling insecure devices (be that IoT, wifi routers, etc) is almost like aiding and abetting, in the context of DoS attacks.

If they had to recall all vulnerable devices I am sure they would take security a lot more seriously.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#30
post #10
post #9

Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…

Please. Dyn has performed pretty well in the past, and any other provider (be it UltraDNS, CloudFlare or anybody else) would be a single point of failure as well. As you said, the only protection (somewhat) is to have redundant/multiple DNS providers. Doesn't mean Dyn can't be one of many.

Dyn is still one of the biggest and hardest to hit providers, so I'd be surprised if they're broadly abandoned. Redundant providers are pretty much the only fix available to users, but it's still sensible to be redundant via the the best providers out there, and that still means Dyn.
Post reply on HN