Live data from Hacker News

DDoS Attack Against Dyn Managed DNS

dynstatus.com

501–510 of 721 posts

Re: DDoS Attack Against Dyn Managed DNS

#501

Earlier quoted context omitted.

Assuming you're referring specifically to targeting media companies reporting on the results and not the electric grid like someone else mentioned, wouldn't they have to DDoS Google itself for that to work? I don't really see a DDoS of Google being effective.

.

This comment says literally nothing.

Re: DDoS Attack Against Dyn Managed DNS

#502
post #465

Earlier quoted context omitted.

Please check our status page as an alternative method for updates. Unfortunately, it's also been encountering the same issue so we're sending out an email with the latest updates.

I didnae get an email

It's still a work in progress. If you have any immediate issues please contact us at support@pagerduty.com or (844) 700-3889.

Re: DDoS Attack Against Dyn Managed DNS

#503
post #471
post #451

Earlier quoted context omitted.

Yes, but there's one piece missing. > Here's the attack: > - Compromise IP (maybe facebook.com) - Attacker generates or acquires counterfeit facebook.com certificate. > - DDoS nameservers > - facebook removes IP from rotation > - Users still connect to bad actor even though TTL expired I understand what you are saying, but this attack scenario is extraordinarily difficult as a means to attack users who have opted to…

You're right! Completely, absolutely, 100% right. If this was a plausible attack vector, we could see it used now. And you know what? We do! This is why some people are concerned about technical decisions that make this vector more dangerous. Systems that attack by, say, injecting DNS responses already exist and are deployed in real life. The NSA has one - Quantum. Why make the cache poisoning worse?

Kalium, I really appreciate your responses.

If my adversary can steal an IP from Facebook, create a valid certificate for facebook.com, and provide bogus DNS resolution for facebook.com, I feel it's game over for me. My home network is forfeit to such an adversary.

But I get your point. It's about layering on mitigating factors. The lower the TTL, the lower the exposure. Still, my current calculus is that the risk of being attacked by such an adversary is fairly low (well, I sure hope so), and I would personally like to configure my local caching resolver to hold onto last-known-good resolutions for a while.

All that said, I have to hand it to you and others like you, those whom keep the needle balanced between security and convenience.

Re: DDoS Attack Against Dyn Managed DNS

#504
post #470

Earlier quoted context omitted.

And the ratio of false flag operations to false accusations of false flag operations is about 1:99. Lots of unlikely things "do happen," but if that's the immediate explanation you reach for you're going to be wrong most of the time.

> Lots of unlikely things "do happen," but if that's the immediate explanation Where did I say it was my immediate explanation and this is _likely_ what is happening?

You might want to take this up with that "rdtsc" guy who wrote "As someone else pointed out this is a classic false flag operation." He seems to disagree with you on those points.

Re: DDoS Attack Against Dyn Managed DNS

#505

I wanted to provide an update on the PagerDuty service. At this time we have been able to restore the service by migrating to our secondary DNS provider. If you are still experiencing issues reaching any pagerduty.com addresses, please flush your DNS cache. This should restore your access to the service. We are actively monitoring our service and are working to resolve any outstanding issues. We sincerely apologize f…

Running multiple DNS providers is not actually that difficult and certainly not cost prohibitive. I am sure after this, we will see lots of companies adding multiple DNS providers and switching to AWS Route53 (which has always been solid for me).

Re: DDoS Attack Against Dyn Managed DNS

#506
post #459

Earlier quoted context omitted.

Aw, don't leave us hanging like that. What problems did it cause?

Proper cache invalidation is one of the 2 hard problems of computer science (the other 2 being naming things and off by 1 errors).

Yes, and there are 10 kinds of people in the world: those who understand binary and those who don't.

Re: DDoS Attack Against Dyn Managed DNS

#507

So who was prepared for this? Pornhub: pornhub.com: Name Server: ns1.p44.dynect.net Name Server: ns2.p44.dynect.net Name Server: ns3.p44.dynect.net Name Server: ns4.p44.dynect.net Name Server: sdns3.ultradns.biz Name Server: sdns3.ultradns.com Name Server: sdns3.ultradns.net Name Server: sdns3.ultradns.org ultradns.biz: Name Server: PDNS196.ULTRADNS.ORG Name Server: ARI.ALPHA.ARIDNS.NET.AU Name Server: ARI.BETA.ARIDN…

Github just added AWS DNS:

github.com:

    Name Server: ns2.p16.dynect.net
    Name Server: ns-1283.awsdns-32.org.
    Name Server: ns-1707.awsdns-21.co.uk.
    Name Server: ns-421.awsdns-52.com.
    Name Server: ns1.p16.dynect.net
    Name Server: ns4.p16.dynect.net
    Name Server: ns3.p16.dynect.net
    Name Server: ns-520.awsdns-01.net.

Re: DDoS Attack Against Dyn Managed DNS

#509

Why not use: OpenDNS - recursive DNS Cloudflare (DNS only) - authoritative DNS Both services are free and distributed across the world.

Dyn was supposed to be distributed too.

The takeaway here should be to use multiple authoritative DNS providers, not a single (even if better) one.

Re: DDoS Attack Against Dyn Managed DNS

#510

Relevant (or at least a-propos) post by Bruce Schneier, from a month ago: "Someone Is Learning How to Take Down the Internet" https://www.schneier.com/blog/archives/2016/09/someone_is_le... Edit: And to be clear: I don't mean to imply there's any connection :)

If this is supposed to be "taking down the internet", then I'm not impressed. Using cached DNS still gives access to any service. I'm even typing here on HackerNews. If this is another practice run, then I'm still not impressed. Taking down one provider is not that hard. Good luck finding the resources to do this DDoS to ALL large DNS providers out there. Maybe it's not really fair to link to that post every time a D…

I work as a freelancer and today I didn't get paid and that's just me. Companies probably lost millions today. By just one DDoS to one DNS provider.

Yeah it's not the whole Internet, but how do you define "taking down the Internet" anyway. Is it every connected computer or just a huge amount of interconnected big websites? Because the latter is happening right now.

Post reply on HN