I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)
Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.
Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
31–40 of 94 posts
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#32I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#33Someone is controlling a powerful enough botnet to do this.
How powerfull is it really ? What else can it do ? Was this just a message or a test ? Or both ?
What would happen if they would point it to google's nameservers ?
What should we expect next ?
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#34I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)
Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#35Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#36Earlier quoted context omitted.
I think it's being downvoted because it's not a great strategy to address a distributed denial of service. In a DDOS, you have a high number of attack sources, none of them using a great amount of bandwidth on their own. The bandwidth use isn't notable until you get pretty close to the destination. Thus, the costs are (mostly) borne by the victim. Basically it doesn't put the pain where it needs to go.
If the transaction cost can become insignificantly low, then money could flow in the direction of the victim. Each attack source could end up making a small contribution to the victim's bandwidth bill. I'm not sure economic incentives will lead to this happening. There's also the difficulty in attributing traffic to the person who requested it ("is this a request, so we should bill the packet source, or is this a rep…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#37Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#38I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#39I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…
Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21
#40Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…