17 ms·
KrebsOnSecurity is now up and hosted on Google Cloud
- alpb 10y agoCan somebody please enlighten me, why is this vague post on the front page with no comments and 8 upvotes?
- dancsi 10y agoAkamai decided to stop hosting the site after a massive DDOS attack targeted at it
- hkmurakami 10y agoHere's the relevant HN discussion link: https://news.ycombinator.com/item?id=12561928 https://news.ycombinator.com/item?id=12561928
- BozeWolf 10y agoThe original post [1] about krebsonsecurity being kicked of akamai (for valid reasons) had a lot (480) of reactions. I think a many of readers of that post see this as a valuable follow-up. [1] https://news.ycombinator.com/item?id=12561928 https://news.ycombinator.com/item?id=12561928
- keithpeter 10y agohttp://www.zdnet.com/article/krebs-on-security-booted-off-akamai-network-after-ddos-attack-proves-pricey/ http://www.zdnet.com/article/krebs-on-security-booted-off-ak... Provides the context if a little light on technical details.
- poooogles 10y agoI've always wondered how Google would deal with a client on GCP being DDoSed. Mainly as were in online advertising and DDoS extortion isn't uncommon. Guess with this I'll now find out, as crapping on Krebs' site is practically a right of passage when you've got a botnet now.
- MaysonL 10y agoTrying to access 130.211.45.45, which is listed in OP as the IP adress, keep getting 502 server errors.
- poooogles 10y agoSure you're sending the right host header?
- neitsab 10y agoYou can try hardcoding the IP address in your hosts file (see my comment below: https://news.ycombinator.com/item?id=12574428#12575021 https://news.ycombinator.com/item?id=12574428#12575021). This will get you to the site through a regular request.
- hrrsn 10y agoI'd wager this is Project Shield rather than regular GCP. https://projectshield.withgoogle.com/public/ https://projectshield.withgoogle.com/public/
- eric_bullington 10y agoThis is the first I've heard of Google's Project Shield. Very cool project, is it relatively new? Does anyone know if this was the result of someone's 20% time or a top-down Google initiative?
- kerneis 10y agoProject Shield is part of Jigsaw (formerly "Google Ideas"): see https://jigsaw.google.com/ https://jigsaw.google.com/ and https://medium.com/jigsaw https://medium.com/jigsaw for more related projects and context. Google Ideas is 5 years old now. I'm not aware of it having started as a 20% project. [disclaimer: I work at Google, but not on Jigsaw.]
- r3bl 10y ago
- Dolores12 10y agoNow google shareholders will pay for all expenses incurred by ddosers.
- dan1234 10y agoAs a (very very minor) shareholder, I'd rather pay for that than Google+.
- matwood 10y agoProtecting a journalists free speech is in line with the original do not evil motto. It's also great advertising for GCE capabilities around handling DDoS.
- jaypaulynice 10y agoGoogle probably has excess capacity. There is nothing more to be paid if the server is sitting there doing nothing. It's actually good for Google because they get to analyze a huge amount of traffic which they can use to protect paying clients.
- tim333 10y ago>KrebsOnSecurity is now up... It isn't for me. I get "This site can’t be reached - krebsonsecurity.com refused to connect."
- notimetorelax 10y agoLooks like redirect from naked domain to www.krebsonsecurity.com is missing. This seem to work better http://www.krebsonsecurity.com/ http://www.krebsonsecurity.com/
- semi-extrinsic 10y agoClicking your link doesn't work either for me (connection refused).
- dotancohen 10y ago$ dig www.krebsonsecurity.com | grep IN ;www.krebsonsecurity.com. IN A www.krebsonsecurity.com. 267 IN A 127.0.0.1
- wila 10y agoI see the same. But it is not uncommon for DNS as it needs time to propagate globally. FWIW, no inserting the www subdomain does not help either. Waiting will though. Edit: works here now
- mtgx 10y agoIf the 665 Gbps botnet was indeed powered by mainly IoT devices, then this is only the very beginning. We're about to see multi-Tbps botnets soon, all because most IoT companies could care less about security, and because most of them want to connect every IoT device to the Internet by default (rather than through a gateway, which at least could limit infections).
- mschuster91 10y ago> and because most of them want to connect every IoT device to the Internet by default Stuff is going to get even worse when IoT devices begin using IPv6. By design, devices are publically reachable and not hidden behind a NAT router, which makes RCE exploits way, way easier. I'd take a guess that loads of IoT devices have "backdoors" like open SSH/telnet with insecure default passwords, too - the same shit that hit el-cheapo routers, for example.
- therealidiot 10y agoLet's hope router manufacturers include sensible firewall defaults. They probably won't in many cases, though.
- mschuster91 10y agoThey can't, because IoT. IoT devices like surveillance cams, VoIP babyphones etc. have two options: 1) depend on third-party servers for operation, so no outside-to-device-initiated communication is needed. Downside: costs money to run the servers, and just imagine the sausagefest when a camera cloud server gets hacked. Upside: you can firewall off your private network as you like, and the device will still work. 2) allow the owner of the device to directly connect to the IoT device via IPv6. Downside: everyone and their dog can access (and exploit) your devices, provided that they know the IP address. IPv6 addresses are long and pretty random, but e.g. if the MAC address is used for assigning the IPv6 address, not so random any more. Upside: no SPOF/centralized node that turns your device into a brick if the operator shuts down. Basically, the only way to "securely" operate IoT devices is inside a separate VLAN. FritzBox routers can do this, but not many others, e.g. because the router can't independently manage the Ethernet ports, because it's cheaper to put in a GBit switch than to choose a SoC that's beefy enough to drive four GBit ports individually. I put "securely" into quotation marks, as a hacked surveillance cam or babyphone is an open invitation to any hacker.
- PuffinBlue 10y agoI've always wondered just how much a network run by someone like Google or Facebook or one of the other absolute top tier providers like AWS or Azure might be able to 'handle' in terms of dealing with DDoS attacks. Presumably these giants can easily handle such traffic as long as someone is willing to pay for the privilege? 665gbps seems tiny in comparison to the capacity someone like Google might have at its disposal but I'm speculating as I haven't seen anything detailing their network stats. To give something of a concluding statement to this waffle I guess I have respect for Google in running this public service type protection for sites that have a strong enough 'public good' element.
- VertexRed 10y agoI recall that Google was taken down by a botnet in 2003, but I'm not able to find any articles about it. Today it's different, not only do they have a massive network, but they probably also have firewalls which drop the attacks from the start.
- tw04 10y agoThat wasn't Google, that was Yahoo!, Amazon, CNN and a few others by a script kiddie that went by MafiaBoy using someone else's botnet. https://en.wikipedia.org/wiki/MafiaBoy https://en.wikipedia.org/wiki/MafiaBoy
- williamstein 10y agoFor what it is worth: My GCP-hosted site (https://cloud.sagemath.com https://cloud.sagemath.com) was hit by a DDoS attack in April (a WordPress amplification attack), which was about 5GB/s at peak time. The GCP network had no problem handling the traffic, but the Linux network stack in my cluster of GCE VMs -- which were running nginx -- simply couldn't handle the load. I now use CloudFlare.
- boulos 10y agoSorry for your troubles! Why'd you let it through, Bill? (Also, did Support help you out with this or not? You can email me your case number if so). Disclosure: I work on Google Cloud.
- imaginenore 10y agoHow would that solve anything? He would have to pay crazy Google CDN fees now: https://cloud.google.com/cdn/pricing https://cloud.google.com/cdn/pricing At 650 Gbps (81.25 GB/s) he's looking at $1.625/sec ($5850/hr) in cache egress fees alone. I would go CloudFlare, which is flat rate.
- prawn 10y agoComments elsewhere here suggest that this service is involved: https://projectshield.withgoogle.com/public/ https://projectshield.withgoogle.com/public/ "Project Shield is a free service that uses Google technology to protect news sites and free expression from DDoS attacks on the web."
- phihag_ 10y agoHe's not using Google CDN, but Google Project Shield: https://projectshield.withgoogle.com/public/ https://projectshield.withgoogle.com/public/ . Project Shield is a free service.
- boulos 10y agoYou're assuming that the flood is actually responded to, instead of being blocked. Also, in defense of our Cloud CDN fees, they're not crazy ;). Disclosure: I work on Google Cloud, so I'm after your money (but not via having you pay for egress to DDoSers).
- patawa 10y agolagers
- patawa 10y ago[url=https://projectshield.withgoogle.com/public/ https://projectshield.withgoogle.com/public/ reply ]asds[/url]
- mxpxrocks10 10y agoseems to be down again at 6:06AM PST sometimes you can get the HTML to load from :80 but the CSS breaks. HTTPS doesn't seem to work at all.
- mxpxrocks10 10y agoseems to be down again at 6:06AM PST sometimes you can get the HTML to load from :80 but the CSS breaks. HTTPS doesn't seem to work at all.
- deleted 10y ago[deleted]
- mkopinsky 10y agoUnfortunately I can't get to the new site (without changing my DNS servers) because Verizon is resolving krebsonsecurity.com to loopback. Presumably doing it for (poor) DDOS mitigation, but this sort of censorship is ridiculous. $ nslookup krebsonsecurity.com 71.242.0.12 Server: 71.242.0.12 Address: 71.242.0.12#53 Non-authoritative answer: Name: krebsonsecurity.com Address: 127.0.0.1 EDIT: I see downthread that this is a DNS propagation issue. Nevermind.
- cesarb 10y agoThe krebsonsecurity.com site was really pointed to 127.0.0.1 by its owner recently (see https://twitter.com/briankrebs/status/779144394360381440 https://twitter.com/briankrebs/status/779144394360381440), so it's probably just a DNS cache at Verizon which hasn't expired yet. Give it some time.
- gipsies 10y agoA wild claim without any source. The owner set the IP to localhost himself. https://twitter.com/briankrebs/status/779144394360381440 https://twitter.com/briankrebs/status/779144394360381440
- mkopinsky 10y agoWhile in this case I was wrong, DNS poisoning is certainly not out of the realm of what Verizon will do, and when a site resolves properly on one ISP and not another, I don't think it's a "wild claim" to assume that it's the ISP's fault.
- user5994461 10y agoThe solution I'd like to see: 1) Put the site behind CloudFlare. 2) Wait for an attack... 3) Force all users to go through a capcha before accessing the site. Note: The capcha setting can be enabled with 3 clicks in cloudflare UI and it takes 2-5 minutes to propagate. (Yes, I speak from experience)
- michaelt 10y agoKrebs won't use Cloudflare because Cloudflare protect DDOS-for-hire sites from each other. He thinks, before CF offered this protection, the DDOS-for-hire services would take one another offline; and that it's an ethical problem, for CF to be protecting the very people whose criminal acts create (some of) the demand for their services. Cloudflare, in their defence, say they don't censor/check/approve sites and that's a good thing - after all, sites like wikileaks should be allowed protection.
- bitmapbrother 10y agoI'm all for free speech, but protecting sites that commit criminal activities is not a "good thing". In fact, they should be partly liable for the damage if they were aware of it and did nothing to stop it.
- tux1968 10y agoNow that he has quickly found another safe harbor, this attack may well have a sort of Streisand effect and give Brian Krebs more prominence than he already had. Would be nice to see something good come out of this and maybe even cause future attacks to be seen as counterproductive by potential perpetrators.