Live data from Hacker News

DDOS on Namecheap Free DNS and Default DNS V2

status.namecheap.com

91–100 of 119 posts

Re: DDOS on Namecheap Free DNS and Default DNS V2

#91

Earlier quoted context omitted.

Everything related to DNS says it'll take a day but that's "worst case"... I've successfully transferred DNS for 5 Namecheap-registered domains to Route 53 since this all started a couple hours ago, and they're now up & running smoothly. Their "update DNS server" page was acting a bit wonky, kept saying some of my nameservers were invalid when they weren't, but I eventually got them all switched. This isn't a dig aga…

Yeah, Route53 isn't as feature rich though. Also I have the same problem, keeps giving me errors about bad nameservers. I guess I'll keep trying.

[deleted]

Re: DDOS on Namecheap Free DNS and Default DNS V2

#92
Best of luck to their support team. Outages can make tech support's life miserable. If you call in, just remember the person on the other side of the phone has likely been yelled at all morning for something that wasn't their fault. Totally reasonable to be upset at the situation, just don't take it out on the tech you're talking to!

Re: DDOS on Namecheap Free DNS and Default DNS V2

#93
post #56
post #52

Earlier quoted context omitted.

According to whois for namecheap.com, the DNS for that domain is hosted on dynect.net, and "host status.namecheap.com" resolves just fine (to 204.232.212.56), so it does not appear to be a DNS issue that is preventing your status page from working.

I stand corrected. It's on Rackspace, which apparently is also experiencing issues.

Rackspace helped us get our status page back online: http://status.namecheap.com/

Re: DDOS on Namecheap Free DNS and Default DNS V2

#94
post #92

Best of luck to their support team. Outages can make tech support's life miserable. If you call in, just remember the person on the other side of the phone has likely been yelled at all morning for something that wasn't their fault. Totally reasonable to be upset at the situation, just don't take it out on the tech you're talking to!

Job security ;).. j/k! I imagine it must not be fun

Re: DDOS on Namecheap Free DNS and Default DNS V2

#95
post #64

Earlier quoted context omitted.

If you use Route 53, your zone file is still at Namecheap (registrar). Doesn't that still make Namecheap a failure point?

No. The zone file lives on the nameserver (DNS server) which Route 53 provides. Namescheap registers a list of nameservers for your domain with the TLD. An over simplified example for looking up "news.ycombinator.com": 1. First query the TLD nameserver for all ".com" domains asking for the authoritative nameserver(s) for "ycombinator.com". 2. Next query that nameserver for "news.ycombinator.com".

But, the first entry point is namecheap. The domain is at Namecheap, so it will not find the zone file at Route 53, if Namecheap does not send it there. Right?

Re: DDOS on Namecheap Free DNS and Default DNS V2

#96
post #15

We are in the process of mitigating a large scale DDoS attack against our global DNS platform. We expect service to return to normal very shortly. Stay tuned and let me know if you have any questions. ted@namecheap.com

The quick tut on switching to DNSv1 is nice however the option doesnt exist in my account

Re: DDOS on Namecheap Free DNS and Default DNS V2

#98
post #76
post #15

We are in the process of mitigating a large scale DDoS attack against our global DNS platform. We expect service to return to normal very shortly. Stay tuned and let me know if you have any questions. ted@namecheap.com

I'd also like to add that we have redunancy on our DNS V1. I advise switching over to this, in the meantime. Please find the tutorial here: https://www.namecheap.com/support/knowledgebase/article.aspx...

I had a couple of domains to try this on. One domain switched over within a minute. The other has been almost an hour. I'm assuming the TLD makes a difference?

.com was 55 minutes.

Re: DDOS on Namecheap Free DNS and Default DNS V2

#99
post #15

We are in the process of mitigating a large scale DDoS attack against our global DNS platform. We expect service to return to normal very shortly. Stay tuned and let me know if you have any questions. ted@namecheap.com

I took your advice and transferred a domain to DNSv1. That domain is still not back online, but all the domains I left as DNSv2 have come back!

Re: DDOS on Namecheap Free DNS and Default DNS V2

#100
post #54

Earlier quoted context omitted.

While it's not a customer friendly viewpoint, it's not exactly what happened here. You have to consider what is being provided and how much was paid into it for said service. Had they been paying a lot of money for solid DNS I could agree with you, but they weren't. It's a completely free service. With an extremely low price for domains. Even though it's become almost a standard for domain registrars to provide DNS,…

If namecheap chose to stop assigning all customers the same list of DNS servers, it would benefit namecheap as well. There's 200+ people in the queue for live chat right now :) It's not DDOS mitigation or H/A, or some other high end feature.

The only way this would be successful is if the "customer IP's" were spread accross separate networks, and the announcement for the attacked network was sent somewhere else.

Assigning customers across lots of IP's in the same /24 isn't going to do anything. A volumetric attack is still going to succeed there.

In this landscape of ever-dwindling portable IPv4 subnets, it's harder and harder to get a /24. You won't get an assignment if your justification is "to fight a DDoS."

Post reply on HN