Live data from Hacker News

Hijack of Amazon’s domain service used to reroute web traffic for two hours

doublepulsar.com

1–10 of 291 posts

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#2
A website I own was affected by this. I got an alert from our monitoring saying the website was down for 1hr 2min 59sec. Luckily, they didn't redirect it to anything.

I have other domains using Route53 (and hosted at AWS, just like this one).. that weren't affected AFAICT.

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#3
How do we know it was unnoticed? It could very well have been noticed and taken two hours for Amazon to mitigate it. I don't know the technical process behind making such a correction, but in any large organization there are steps that have to be followed. It's not like some kid typing out a shell command on his basement Linux box.

Inflammatory/clickbait headlines do not make the internet a better place.

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#4

A website I own was affected by this. I got an alert from our monitoring saying the website was down for 1hr 2min 59sec. Luckily, they didn't redirect it to anything. I have other domains using Route53 (and hosted at AWS, just like this one).. that weren't affected AFAICT.

Experienced the same behavior on only one of my hosted zones. Started around 11:28am UTC

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#5
It was certainly noticed in under 2 hours. The Outages list thread about the issue started at 11:54 UTC: https://puck.nether.net/pipermail/outages/2018-April/011257....

I'm sure that there were ops teams working on it before then. The people involved in actually fixing the problem wouldn't have been posting to public mailing lists.

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#6

How do we know it was unnoticed? It could very well have been noticed and taken two hours for Amazon to mitigate it. I don't know the technical process behind making such a correction, but in any large organization there are steps that have to be followed. It's not like some kid typing out a shell command on his basement Linux box. Inflammatory/clickbait headlines do not make the internet a better place.

Ok, we've taken that word out of the title above.

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#9
> This traffic was redirected to a server hosted in Russia, which served the website using a fake certificate — they also stole the cryptocoins of customers.

What does this sentence mean? Sorry if I'm being slow. I thought the whole point of certificates is that you can't generate a legitimate one for a domain you don't control, so messing with name resolution wouldn't affect it.

Re: Hijack of Amazon’s domain service used to reroute web traffic for two hours

#10

> This traffic was redirected to a server hosted in Russia, which served the website using a fake certificate — they also stole the cryptocoins of customers. What does this sentence mean? Sorry if I'm being slow. I thought the whole point of certificates is that you can't generate a legitimate one for a domain you don't control, so messing with name resolution wouldn't affect it.

[deleted]
Post reply on HN