4 ms·
"Between 11am until 1pm UTC today, DNS traffic-the phone book of the internet, routing you to your favourite websites-was hijacked by an unknown actor." Is it
by textmode 8y ago
"Between 11am until 1pm UTC today, DNS traffic-the phone book of the internet, routing you to your favourite websites-was hijacked by an unknown actor."
Is it worth keeping a record of the IP addresses for "your favorite websites"?
For example, with IP addresses saved, would this enable reaching the websites ven if DNS is not working?
How often do these "favorite websites" change IP addresses?
Are they all the same in that regard?
(The frequency with which they chaange IP addresses.)
Is it worth paying attention when one of them changes its IP address?
Is it worth noting where these addresses are thought to be located (e.g. the countries)?
What if several of "your favorite websites" each change their IP address on the same day, the same week or even the same month?
Is this worth noting?
- viraptor 8y agoDepends on how the website is hosted. If it's a tiny website on a single server/VPS, then it's going to be fairly stable with the IP. For anything else, you're out of luck. Shared hosting or PaaS will change ips when needed internally, or to rebalance the traffic, or when new hosts come up. Anyone with large enough traffic will use some edge network like CloudFlare which would also get a different address depending on your location. Some IPs may stay stable for a long time, but virtually every change to them is going to be intended. And you can't tell easily which one want.
- textmode 8y ago"Anyone with large enough traffic will use some edge network like Cloudflare which would also get a different address depending on your location." What if the request is always sent from the same location? What if when the user moves location, e.g., from one country to another, she updates her stored IP addresses? "And you can't tell easily which one want." Personal experience as a user is that when it is an "intended" change, the previous IP address no longer hosts the content. Personal experience is that this is surprisingly rare. In the case of the more common load balancing, the user who may store several IP addresses for the website, all of which continue to serve the content. She can choose which of those she prefers. Personal experience is that this works very well. Further questions: If this was a BGP hijack, why did the hijackers target the IP addresses of DNS servers, rather than the target IP addresses of the websites? If they had targeted the IP addresses of the websites, then what would be the possible mitigations, if any?
- viraptor 8y ago> What if the request is always sent from the same location? Then you may get the same IP. > What if when the user moves location, e.g., from one country to another, she updates her stored IP addresses? It doesn't have to be a different country. Different ISPs with different peering may get different results. Moving between your home wifi and you phone tethering may get different results. So depending on your usage style, it's between "change multiple times a day" and "no change". > Personal experience as a user is that when it is an "intended" change, the previous IP address no longer hosts the content. In some cases I'm sure it's true. In others, it isn't. Basically it's not a reliable indicator. > If this was a BGP hijack, why did the hijackers target the IP addresses of DNS servers, rather than the target IP addresses of the websites? Haven't seen the site's announced block, but it's possible that it's announced as /24 block. This attack was possible because Amazon announced /23 and the attacker could announce something more specific.
- textmode 8y ago"So depending on your usage style, it's between "changes multiple times a day" and "no change"." For me, for each ISP, it's been "no change". Can only relate personal experience.