Live data from Hacker News

Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

dynstatus.com

31–40 of 94 posts

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#31
post #3

I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)

Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.

Compromised routers can be used to compromise devices behind it. Also many devices (like IP cameras) usually have port forwarding to allow the users to access it from outside.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#32
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

I agree with you. IoT devices inside a SOHO should communicate externally through a proxy gateway device. IoT devices should only have communications in a p2p network in a LAN, and have strong restrictions or none access to WAN. Any type of updates should be given from a proxy device having proper hardening than a normal IoT device.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#33
So I'm wondering, what are the implications of this ?

Someone is controlling a powerful enough botnet to do this.

How powerfull is it really ? What else can it do ? Was this just a message or a test ? Or both ?

What would happen if they would point it to google's nameservers ?

What should we expect next ?

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#34
post #3

I'm so looking forward at IPv6, the death of NAT, and billions of IoT devices with all ports exposed to the world :-)

Arent most IOT devices behind a router and thus unexposed directly to the internet (excepting routers)? This part of these attacks confuses me.

Many devices use UPNP to automatically punch a hole through the NAT and expose their ports to the world.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#35
post #15

Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…

[deleted]

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#36
post #28
post #18

Earlier quoted context omitted.

I think it's being downvoted because it's not a great strategy to address a distributed denial of service. In a DDOS, you have a high number of attack sources, none of them using a great amount of bandwidth on their own. The bandwidth use isn't notable until you get pretty close to the destination. Thus, the costs are (mostly) borne by the victim. Basically it doesn't put the pain where it needs to go.

If the transaction cost can become insignificantly low, then money could flow in the direction of the victim. Each attack source could end up making a small contribution to the victim's bandwidth bill. I'm not sure economic incentives will lead to this happening. There's also the difficulty in attributing traffic to the person who requested it ("is this a request, so we should bill the packet source, or is this a rep…

Are you suggesting that people should get paid for receiving traffic?

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#37
post #15

Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…

Getting good, consistent, well routed, fast and secure DNS Is harder than you'd think. Dyn typically sing speed as the main selling point for their DNS product, they do this through a large distribution of domain name servers geographically and anycast. Many hosts (like say, DigitalOcean) run their own DNS but use something like CloudFlare Virtual DNS on top. Personally I was surprised so many large sites trusted Dyn, Route 53 is a more robust product for production and scale. In the past, I've seen hosting providers switch to Dyn, give them load, cripple them, and have to scramble to revert away. I'm not at all surprised his happened, even given the uptick in botnet traffic globally.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#38
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

That's assuming that the free market doesn't "solve" things by ISPs and media companies merging into 2-3 mega-conglomerate verticals whose siloed content is only accessible via DRM via their own network.

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#39
post #5

I am sure the DDoS problem is something that the free market will sort out. The individual players will make it costly for the other players to send problems their way. I expect a chain of "charge the next node for resource usage" to evolve. If this chain will go all the way to the end user, I don't know. If it will, then end users will probably start using routers that feature restrictions / monitoring / control of…

vodafone is building a lowband/narrowband WAN that could/should be used for helping fix an impending Botpocalypse type of thing IF It's implemented with such a goal in mind: http://www.theregister.co.uk/2016/10/20/vodafone_nb_iot_roll...

Re: Update Regarding DDoS Event Against Dyn Managed DNS on Oct 21

#40
post #15

Pardon my ignorance, but why don't companies run their own nameservers? I get why you don't want to run email - it's highly reputation driven. But as far as I can tell, running nameservers is no harder than running webservers or DB servers. HA is potentially even easier, because the system was designed that way from day zero. I'm not suggesting I'd run one for my personal website, but twitter and github are already m…

[deleted]
Post reply on HN