8 ms·
This is one reason why I'm moving our startup over to AWS. :/ They seem to experience less of these catastrophic DDoS attacks. Edit: Err, not a DDoS attack app
by methodover 10y ago
This is one reason why I'm moving our startup over to AWS. :/ They seem to experience less of these catastrophic DDoS attacks.
Edit: Err, not a DDoS attack apparently. But catastrophic nonetheless.
- josephb 10y agoRoute53 also: A) Serves DNS from multiple domain names. A number of variants in .com .org and others etc B) Serves DNS from multiple internet networks / sources. Queries from an end user don't all hit the same Anycast subnet.
- kyledrake 10y agoRoute 53 also has no IPv6 support, and no stated policy on how it deals with DDoS attacks, or if you get charged for the attack if it's directed at you. Good luck!
- jtrtoo 10y agoIt might be more accurate to say R53 has partial v6 support. It'll return v6 records (AAAA) happily. The nameservers themselves do not respond on v6 (which is unfortunate and certainly means v6 support is lacking). Practically, however, it's pretty unlikely, that a v6 only host isn't going to also have access to a v6-to-v4 gateway. Not ideal, but generally transparent for most intents and purposes ...and generally used by just about anyone with a v6 address assignment today, everyday. For DDoS attacks, I'm not sure what you mean by a "stated policy." They do a lot of countermeasures, some of which can be found via linked PDFs at https://aws.amazon.com/security/ https://aws.amazon.com/security/ Various R53 items are included in their DDoS document there. Officially you get charged. Unofficially, it depends on the circumstances. There's also a world of difference between a DDoS attack against a fully managed offering (like R53) versus, say, an EC2 instance. Have you seen a better approach taken by other providers? I don't mean technical approach (which is near impossible to compare other than by track record), but from a policy perspective?