6 ms·
Why Friday's Massive DDoS Attack Should Be Terrifying
- perseusprime11 10y agoDo we know who is behind this?
- TheSpiceIsLife 10y ago"The Russians™"
- perseusprime11 10y ago:) you want me to fall for that?
- idlewords 10y agoIn some sense it doesn't matter, because the tools are now out there and the problem is structural. Delving into motives can have the effect of encouraging people who want attention.
- jwarren116 10y agoA group called New World Hackers have claimed responsibility[1]. I read a bit that they stopped their attacks by 2pm EST, and that another group picked up some of the minor attacks later in the day. Anonymous was mentioned, but didn't claim it. I can't seem to track down that article at the moment... I'll keep looking. [1] https://twitter.com/fbajak/status/789611472280178688 https://twitter.com/fbajak/status/789611472280178688 and http://www.anonintelgroup.com/2016/10/21/twitter-down-its-not-the-russians-its-the-new-world/ http://www.anonintelgroup.com/2016/10/21/twitter-down-its-no...
- gfody 10y agoFriday's massive ddos attack barely registered on my day-to-day, the only annoyance was that Github was slightly slower than usual. It has been amusing though to see all the hundreds of news articles trying desperately to sensationalize the event.. and it simply didn't even matter.
- shenoybr 10y agoIt mattered for people on the East Coast. Where I am (New York), we couldn't access Github, Twitter, Paypal and many other services. To make matters worse, AWS us-east region was configured to use Dyn. Therefore, many applications that depended on it (and on Heroku) were down. At my workplace, we had to reconfigure DNS for our own applications even though we didn't directly use Dyn. It really was a big deal.
- helthanatos 10y agoNo. It mattered.
- meddlepal 10y agoDid it? I only sort of noticed as well.
- deelowe 10y agoYes. The attack vector and coordination is very concerning. Just because it didn't impact you doesn't mean it wasn't significant. It could have only been a feasibility test. Scaled up, this attack would be devastating.
- laughfactory 10y agoIt seems like it was a warning shot to show what they can do. Imagine the impact to the US if this had gone on for, what, days? Weeks? Is there any reason it couldn't continue indefinitely? It could be as devastating as a nuclear bomb detonation... One of the most profound effects would be the lack of trust everyone would now have for the services (etc) they rely on. The SaaS business model would become extinct overnight, and nothing important would be in the cloud. We'd all go back to desktop first applications, and all the enormous investment in cloud technology would be vaporized. If you don't trust the reliability of the internet, why would you rely on AWS and the like. You wouldn't. But perhaps this is a smarter approach: build software and services in the most reliable way possible: offline enabled without the assumption of mostly available internet. Oh, and VOIP phone service? Gonzo. Where I work that was the worst effect of the outage. The phones simply didn't work... And we're basically a sales company. Not a lot of sales were made that day...
- johansch 10y agoReddit, Netflix, Github and Airbnb all appear to have switched from Dyn to AWS DNS for their primary .com domains by now.
- andrewmitchell 10y agoI can understand the instinct to move, but I think the answer is to split your eggs among many baskets, not just pick a sturdier basket. I don't think the Dyn team is necessarily bad, it was an enormous assault.
- gooeyblob 10y agoNot accurate, Reddit was on CloudFlare previously and switched to Route53 a few weeks ago.
- coreyp_1 10y ago90 miles from Chicago. Didn't notice a thing. Note: I'm not dismissing the validity of the concern. I'm only reporting that I didn't even know about it as the attack was happening. I'm sure others were much more severely affected.
- zitterbewegung 10y agoI was in the northern suburbs of Chicago and wasn't able to access GitHub .
- tarellel 10y agoI'm along the North Western New Mexico/South Western Colorado border and didn't notice a difference either. I'm not saying this is shouldn't be a major concern. Just some areas are effected quite a bit more than others, it appears to mainly effect high metro/coastal regions.
- jacobsenscott 10y agoI'm in Denver. Couldn't get to github, and our site is hosted on Heroku and was down for most of the day.
- emblem21 10y ago/etc/hosts saved the day for me.
- andrewmitchell 10y agoI found a really really stale name server that didn't respect TTLs.
- vitus 10y agoI found a HN post that recommended switching my nameservers to OpenDNS, which uses SmartCache. Seems like a better approach in general.
- jwarren116 10y agoSame. I use OpenDNS and I had no idea there was an attack happening until I asked a co-worker to review something on GitHub and they couldn't access it. SmartCache saved me a lot of hours that could have been lost Friday.
- taf2 10y agoMe too. I also setup a crontab to capture DNS entries for all services I depend on.
- pessimizer 10y agoIt should be terrifying because the government's complete lack of ability to regulate anything has allowed the so-called "internet of things," more accurately called the "internet of corporate things that the user is locked out of," to develop into a national security threat.
- jstandard 10y agoI'm trying to understand your position. Are you saying this is partially (or fully) the government's fault because they didn't regulate the IoT device market to force it to be open source? And if they had done so this attack could have been avoided?
- andrewmitchell 10y agoThere's a very strong argument to be made that regulation is the only way to improve this situation. A negative externality like this is unlikely to correct itself. Cheap manufacturers will continue to save money by cutting security features, and unaware or price-driven consumers will reinforce that behavior. What else can we do? Note: this isn't something the US can solve. A lot of this traffic came from overseas. It's needs a coordinated response.
- dogma1138 10y agoThe problem with most regulation is that it tends to be quite a bit behind the current trends. You also need to acount for the fact that these devices are going to be alive for years maybe even decades which means that their security measures would become obsolete. DDoS needs to be solved on the infrastructure level at this point, securing endpoint nodes is a game you are going to constantly lose.
- cariaso 10y agoThe same backdoors that owned the devices as a botnet, should be used to brick the devices. And the courts should support that purchasers are entitled to refunds and damages. Your IoT refrigerator got bricked? You can sue for $500 worth of spoiled food. Encourage class action lawsuits and watch how fast this is fixed. https://github.com/jgamblin/Mirai-Source-Code https://github.com/jgamblin/Mirai-Source-Code
- marze 10y agoOk, dumb question: Why can't a list of addresses of all the devices in the world of the type used in the attack be created, and all packets from any address on the list be trashed? At least, for the duration of the attack. If such lists were made ahead of time, they could be turned on rapidly. Is anything like this done?
- hueving 10y agoTwo issues: NAT and dynamic addresses. NAT: blocking an iot address may be blocking grandma's whole network (or her whole apartment complex's network), and the ISP doesn't want that support call. Dynamic addresses: depending on the ISP, the IP could change quite frequently (daily), so keeping the list up to date to avoid collateral damage to the unlucky recipient of the blacklisted IP is very difficult.
- 1812calif 10y agoYou are speaking of basically an IP-based version of the spamhaus blacklist. For general http or TCP protocol. I, for one, would be fine with a general internet citizen losing access if they have a compromised device. I suspect this is how we will go -- your home security cam was used in an attack, now every single website you visit for XXXXXXXX days gives you a CAPTCHA. I maintain the crucial element is informing people why they have that hassle. Add extra friction, but not inhibit what they can do, because they are unable and unwilling to secure their devices. Yes, this affects the internet-uneducated disproportionately. Yes, I think it is the responsibility of anyone with a broadband connection to understand the responsibilities that come with it. No, I do not expect grandma to learn this. I expect her to deal with a crippled internet because they are not able to fix their pollution.
- michilehr 10y agoIn germany, the Telekom (T-Online) used to block http or SMTP traffic when they recognized an infected connection which sent SPAM emails. Don't know if they still act like this.
- rasz_pl 10y agoL3 already confessed to having build a list of >500K Mirai bot static IPs, they used it to .... do NOTHING, because they are in business of selling pipes, and ddos makes good business.
- BerislavLopac 10y agoI'm not aware of all the technical intricacies here, but could this kind of attack be preventable by having local DNS caches in the OS itself, kinda like a dynamic hosts file?