Live data from Hacker News

Incident Report – DDoS Attack

blog.dnsimple.com

1–10 of 40 posts

Re: Incident Report – DDoS Attack

#2
I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515

I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling costs forwarded to customers.

Re: Incident Report – DDoS Attack

#4
post #2

I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515 I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling c…

I've had a similar thought RE using Route53 for Neocities. Here's the problem with Route53 though. If you get a DDoS attack using it, it's quite plausible that you would be charged for resources used in the DDoS attack. A recent Vice article discussed this: http://motherboard.vice.com/read/inside-the-unending-cyber-s...

DDoS is a nasty problem. We've received a DDoS attack that shut the entire site down for days. We can't use Cloudflare because they don't support wildcard domains without their very expensive plan. I've also heard stories from people using Cloudflare that have still not been able to resolve DDoS issues (I'm not knocking Cloudflare, they're a great company that does a really good job fighting this very hard problem, but sometimes even they have trouble with it).

I'll be completely honest and say that I have no idea how to solve this problem. It's really, really, really hard. Switching to different service providers won't get you very far against the monster DDoS attacks that some people can execute.

Re: Incident Report – DDoS Attack

#5
The solution here is one for customers, not providers.

Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs).

Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results directly to clients making DNS queries.

Most "Secondary DNS" packages are < $50 year, so use a few, and don't worry about individual DNS networks being burnt to the ground.

Re: Incident Report – DDoS Attack

#6
post #3

So who do you think the "well-known third-party service that provides external DDoS protection using reverse DNS proxies" is they're going to use now? CloudFlare?

Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.

Re: Incident Report – DDoS Attack

#7
post #6
post #3

So who do you think the "well-known third-party service that provides external DDoS protection using reverse DNS proxies" is they're going to use now? CloudFlare?

Hopefully not. CloudFlare is remarkably unreliable for a service that claims to improve uptime.

Curious to hear more about this.

Re: Incident Report – DDoS Attack

#8
post #2

I need to learn to let things go, but: https://news.ycombinator.com/item?id=4280515 I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling c…

I've had a similar thought RE using Route53 for Neocities. Here's the problem with Route53 though. If you get a DDoS attack using it, it's quite plausible that you would be charged for resources used in the DDoS attack. A recent Vice article discussed this: http://motherboard.vice.com/read/inside-the-unending-cyber-s... DDoS is a nasty problem. We've received a DDoS attack that shut the entire site down for days. We…

If you're going to go the Amazon route then you absolutely need to keep an eye on billing, and set up alerts so that any DDoS which caused a spike in your costs would be caught as soon as possible.

Re: Incident Report – DDoS Attack

#9
> A new customer signed up for our service and brought in multiple domains that were already facing a DDoS attack. The customer had already tried at least 2 other providers before DNSimple. Once the domains were delegated to us, we began receiving the traffic from the DDoS.

I'm curious did they know this in advance or discovered it after the fact?

I often wonder about business models where the core expense is "unlimited and free". The reality is there is nothing unlimited or free for the service provider. It seems with a business model like this you open yourself to people abusing your service either by accident or by choice. Imagine poor Mr. Customer here who most likely was having horrible problems thinking to themselves "These guys can do it and for free, if I go to X service they'll cost me a lot of money".

I'm a big believer in business models that incentivize both parties properly. I'm sure in general this service provider is arbitraging the 99.9% of domains that barely need any services. That said it only takes a couple of "opps" customers to drive your operational costs through the roof.

Re: Incident Report – DDoS Attack

#10
post #9

> A new customer signed up for our service and brought in multiple domains that were already facing a DDoS attack. The customer had already tried at least 2 other providers before DNSimple. Once the domains were delegated to us, we began receiving the traffic from the DDoS. I'm curious did they know this in advance or discovered it after the fact? I often wonder about business models where the core expense is "unlimi…

Anthony from DNSimple here. We discovered it after the fact, via a tip from other DNS providers.
Post reply on HN