4 ms·
Why do AWS http://status.aws.amazon.com http://status.aws.amazon.com say that only Google resolvers were affected? Between 4:05 AM PDT and 5:56 AM PDT, some cu
by 925dk 8y ago
Why do AWS http://status.aws.amazon.com http://status.aws.amazon.com say that only Google resolvers were affected?
Between 4:05 AM PDT and 5:56 AM PDT, some customers may have experienced elevated errors resolving DNS records hosted on Route 53 using DNS resolvers 8.8.8.8 / 8.8.4.4. This issue was caused by a problem with a third-party Internet provider. The issue has been resolved and the service is operating normally.
- fooblitzky 8y agoIt seems like either the title is misleading, or the article does a poor job of explaining the situation. From my reading of the article text, it seems DNS traffic was rerouted to Route53, which the attackers then used to serve false DNS records. That does not sound like Route53 was hijacked at all, just that the attackers happened to use the service it provides.
- 925dk 8y agoTraffic to Route 53 was rerouted to an alternative DNS server. But that has nothing to do with my question re. AWS calling out Google in particular in their status update.
- dgemm 8y agoSome Route53 traffic was redirected somewhere else. Traffic can only be hijacked from neighbors that actually accept the routes. You would think Google of all networks would have effective ingress filtering to prevent this, but it seems like they did accept it in this case.
- dward 8y agoI don't think ingress filtering on Google's edge would have helped if the rerouting happened in any of the transit ASs between AWS and Google.