Live data from Hacker News

Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

gizmodo.com

31–40 of 50 posts

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#31
post #15
post #10

Earlier quoted context omitted.

Please. Dyn has performed pretty well in the past, and any other provider (be it UltraDNS, CloudFlare or anybody else) would be a single point of failure as well. As you said, the only protection (somewhat) is to have redundant/multiple DNS providers. Doesn't mean Dyn can't be one of many.

They had one job. To stay up no matter what. That's the only justification for using Dyn. They failed.

Would anyone else have stayed up, though? This isn't just going to be a fear response, the risk assessment will be to ask "what could have prevented this?"

Lots of people will quit using Dyn as a sole DNS, but I don't see any reason they'll quit being involved in people's multiple DNS solutions.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#32
post #9

Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…

Dyn is toast as a single DNS provider. The big boys are just going to move to using two or three providers' nameservers rather than just one.

Dyn will almost certainly remain as one of those two or three.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#33
post #26

Earlier quoted context omitted.

That the scale of DDoS's has increased is the entire thesis of the OP.

They've been increasing steadily for decades . Today almost certainly isn't some new record-setting attack orders of magnitude beyond what's been seen before - it isn't the herald of a new age of attacks and the "beginning of a bleak future". Claiming such is just sensationalist garbage that belies a lack of understanding of the way the internet works and the history of DDOSes in general. Spamhaus was historic in 201…

Have they been increasing steadily, though?

The 2013 attack was http://www.cisco.com/c/en/us/solutions/collateral/service-pr...) Most predictions suggest that IoT attacks will grow faster than what we've already seen, and a rough estimate suggests that DDoS capacity is growing faster than legitimate capacity.

None of that means today was orders of magnitude higher - the shock factor was that it exposed a structural weakness people hadn't accounted for. But I expect this to become an increasingly significant problem as capacity increases, and moreover as that capacity becomes available to more attackers.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#34
post #9

Dyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vuln…

Junk IoT manufacturers need to feel fear. We've reached the point where any clueless business type who pooh-poohs and wishes away security concerns needs to get the idiot bit flipped on them. Today's networked computing environment has reached the point, where this stuff is toxic. It might have been okay for a few isolated frontier weirdos to play with mercury to extract gold, but then when that became a full blown i…

capitalism just isn't ready for prime time

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#35
post #27
post #2

Twitter and GitHub have been down for me for a while now.

You can use this to find IPs for services that are currently out: https://dns.google.com/query?name=github.com&type=A&dnssec=t...

TIL about dns.google.com. Seems to be pretty handy for doing quick lookups. Thanks Mizza!

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#36
post #26

Earlier quoted context omitted.

They've been increasing steadily for decades . Today almost certainly isn't some new record-setting attack orders of magnitude beyond what's been seen before - it isn't the herald of a new age of attacks and the "beginning of a bleak future". Claiming such is just sensationalist garbage that belies a lack of understanding of the way the internet works and the history of DDOSes in general. Spamhaus was historic in 201…

Have they been increasing steadily , though? The 2013 attack was http://www.cisco.com/c/en/us/solutions/collateral/service-pr... ) Most predictions suggest that IoT attacks will grow faster than what we've already seen, and a rough estimate suggests that DDoS capacity is growing faster than legitimate capacity. None of that means today was orders of magnitude higher - the shock factor was that it exposed a structural…

I certainly expect it to become an increasingly-significant problem, as well. I don't mean to downplay the significance of the attack. But the lesson here isn't "welp, the bad guys have won, the internet is dead", it's "don't use one DNS provider, go redundant on it just like you do on every other piece of the stack". Yeah, it's annoying, but it's not an unsolvable problem.

The reporting on this has really annoyed me because the writers writing about it have pretty consistently said that GitHub, Twitter, PayPal, etc have all been knocked offline, which is just untrue. They have unresolvable names - resolve their names and they're working just fine. The fix is improved resilience in name resolution, and it's not a terribly hard fix. Someone in the other thread noted that PornHub is managing just fine despite using Dyn DNS - because they also route half their DNS traffic to UltraDNS.

Attacks like this are certainly a big problem, and are going to become a bigger problem, but IMO, the Chicken Little sky-is-falling hysteria is unwarranted and unuseful.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#38
post #15
post #10

Earlier quoted context omitted.

Please. Dyn has performed pretty well in the past, and any other provider (be it UltraDNS, CloudFlare or anybody else) would be a single point of failure as well. As you said, the only protection (somewhat) is to have redundant/multiple DNS providers. Doesn't mean Dyn can't be one of many.

They had one job. To stay up no matter what. That's the only justification for using Dyn. They failed.

Unless you have a good argument why they are less likely to stay up than the alternatives, I don't see how this would lead to their end. Unless you take it as an argument to abolish ALL DNS servers and start mailing host-files around...

People have been painfully reminded why using multiple providers is best practice, will re-evaluate if that's worth the expense and if yes add other servers. Dyn will easily survive unless some massive blunder is exposed in the aftermath.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#39
post #38
post #15

Earlier quoted context omitted.

They had one job. To stay up no matter what. That's the only justification for using Dyn. They failed.

Unless you have a good argument why they are less likely to stay up than the alternatives, I don't see how this would lead to their end. Unless you take it as an argument to abolish ALL DNS servers and start mailing host-files around... People have been painfully reminded why using multiple providers is best practice, will re-evaluate if that's worth the expense and if yes add other servers. Dyn will easily survive u…

The alternative, not being one of the bigs, has a lot less chance to be hit. I would leave dyndns the same way I'm leaving cloudflare.

Re: Today's Brutal DDoS Attack Is the Beginning of a Bleak Future

#40
post #13

Earlier quoted context omitted.

they're not down you just can't resolve the URL

as a temp solution, add these to your /etc/hosts file: 192.30.253.113 github.com 151.101.44.133 assets-cdn.github.com

I'm kinda surprised at how bad the OSs deal with this. If you can't get a DNS lookup, would it be so crazy to use the last-known cached value for it?

There's no reason for a computer to not be able to find a site I've been visiting every day for the last year. DNS data should be cached for at least 48 hours -- TTLs should be set to at least this.

Post reply on HN