8 ms·
Today's Brutal DDoS Attack Is the Beginning of a Bleak Future
- smnscu 10y agoTwitter and GitHub have been down for me for a while now.
- smn1234 10y agothey're not down you just can't resolve the URL
- studio816 10y agoas a temp solution, add these to your /etc/hosts file: 192.30.253.113 github.com 151.101.44.133 assets-cdn.github.com
- atcole 10y agoI navigated to the IP address for Github, but it still tries to resolve to github.com
- kayamon 10y agoI'm kinda surprised at how bad the OSs deal with this. If you can't get a DNS lookup, would it be so crazy to use the last-known cached value for it? There's no reason for a computer to not be able to find a site I've been visiting every day for the last year. DNS data should be cached for at least 48 hours -- TTLs should be set to at least this.
- Mizza 10y agoYou can use this to find IPs for services that are currently out: https://dns.google.com/query?name=github.com&type=A&dnssec=true https://dns.google.com/query?name=github.com&type=A&dnssec=t...
- K2L8M11N2 10y agoTIL about dns.google.com. Seems to be pretty handy for doing quick lookups. Thanks Mizza!
- beamatronic 10y agoIt occurred to me today that since certain sites have been down, it's forced me to use other sites which are still up. As if someone is forcing all my communication and activities to go through "approved" channels.
- meira 10y agoI Heard this after heartbleed too. No, it is not a beginning. Neither a bleak future. Maybe for bigco.
- rdl 10y agoIt seems like some eyeball and distribution networks should get together and run a private subset of the Internet, with good filtering (BCP38 style), etc. internally. You could get pretty good coverage with just ~10 eyeball networks in the US, a few cloud providers, and maybe some key infrastructure. Operate normally most of the time, but when under attack, be able to fall back to just vetted networks, transports, and routes, at least temporarily. Then have a limited number of hardened gateways, the way NIPRnet does with the civilian commercial Internet, which are used in intermediate-level attacks. Opt-in, maybe have an association run it (like an IX, but without the expensive dinners and dues and general activism which inflates IX budgets), etc. This would do more for "critical infrastructure protection" than anything DHS/NSA/FBI have ever done.
- zitterbewegung 10y agoSo, these DDOS attacks take advantage of IoT devices so how would you tell the difference using vetting when they are on the same networks as regular users?
- cheald 10y agoDDOS attacks are nothing new. The scale has increased over time, but DOS has been a constant issue for as long as people have been mad on the internet. This attack is notable because it expsoes a single point of failure for a lot of popular sites. The long-term fix is to distribute that SPOF so it's not so tight a bottleneck. This is as easy as specifying nameservers from multiple providers, or as complex as a distributed DNS system such as namecoin. The internet is a giant cascade of constant failures, and developing for it is an exercise in planning for failure. This isn't new - if it appears new, it's just that most engineers have done their jobs well. What will happen out of this is that the people trusting all their DNS traffic to Dyn will start trusting only half of it to Dyn, and the next time Dyn is knocked out, the people who have diversified against that contingency won't be practically affected.
- the_watcher 10y agoThat the scale of DDoS's has increased is the entire thesis of the OP.
- cheald 10y agoThey've been increasing steadily for decades. Today almost certainly isn't some new record-setting attack orders of magnitude beyond what's been seen before - it isn't the herald of a new age of attacks and the "beginning of a bleak future". Claiming such is just sensationalist garbage that belies a lack of understanding of the way the internet works and the history of DDOSes in general. Spamhaus was historic in 2013 at 75GBPS. In 2014, Cloudflare mitigated a 400GBPS attack. The BBC attack earlier this year crested 600 GBPS. Last month, OVH was hit with a 1TBPS attack. Each of those was mind-bogglingly large at the time, and infrastructure has continued to evolve to deal with them. This attack isn't anything particularly different - it's just notable because it's visible, not because it happened.
- Bartweiss 10y agoHave they been increasing steadily, though? The 2013 attack was <1% of total internet traffic for its duration. The 2014 Cloudflare hit was ~2.5% of all traffic. BBC was ~3%, and OVH was ~4%. (Interpolated from Cisco here: http://www.cisco.com/c/en/us/solutions/collateral/service-provider/visual-networking-index-vni/vni-hyperconnectivity-wp.html http://www.cisco.com/c/en/us/solutions/collateral/service-pr...) Most predictions suggest that IoT attacks will grow faster than what we've already seen, and a rough estimate suggests that DDoS capacity is growing faster than legitimate capacity. None of that means today was orders of magnitude higher - the shock factor was that it exposed a structural weakness people hadn't accounted for. But I expect this to become an increasingly significant problem as capacity increases, and moreover as that capacity becomes available to more attackers.
- excitom 10y agoHighly uninformative article.
- Animats 10y agoDyn, Inc. is toast. They created a central point of failure for the Internet. Major sites will stop using their services within hours. Things need to get more distributed. Don't load Jquery from some central site. Don't load fonts from Google. Make sure your site will work if all the trackers and ad sites are not responding. Use multiple independent DNS providers. It's also time for serious litigation. Find some vulnerable IoT device being used for the attack, and sue the retailer, distributor, and manufacturer for negligence. Junk IoT manufacturers need to feel fear.
- rbinv 10y agoPlease. Dyn has performed pretty well in the past, and any other provider (be it UltraDNS, CloudFlare or anybody else) would be a single point of failure as well. As you said, the only protection (somewhat) is to have redundant/multiple DNS providers. Doesn't mean Dyn can't be one of many.
- Animats 10y agoThey had one job. To stay up no matter what. That's the only justification for using Dyn. They failed.
- a3n 10y agoNo matter what is pretty tough. And it's not like they're an insurance company that can re-insure their risks. The people who depend on DNS have one DNS-related job: to mitigate risk relative to their potential losses and existence.
- rbinv 10y agoYes, they did. But, depending on the details of the attack, I am not sure if any other provider could have withstood the attack without problems. In other words, I doubt there's a single provider/alternative.
- Bartweiss 10y agoWould anyone else have stayed up, though? This isn't just going to be a fear response, the risk assessment will be to ask "what could have prevented this?" Lots of people will quit using Dyn as a sole DNS, but I don't see any reason they'll quit being involved in people's multiple DNS solutions.
- jetru 10y agoWhy are Gizmodo articles even getting upvoted here? They are always sensational and low information density.
- Florin_Andrei 10y agoI thought it raises a few good points, even though it doesn't propose any solutions. The current sorry state of IoT security is something worth thinking about.
- faragon 10y agoJust put DDoS attacks at same level as terrorism.
- whamlastxmas 10y agoGreat, now I need to pass through a naked-body TSA scanner in order to shitpost on reddit.
- faragon 10y agoCome on. That's about world-wide DDoS attacks, not about checking individuals.
- m0llusk 10y agoSaid the clickbait. Bleak future indeed!