7 ms·
We are in the process of mitigating a large scale DDoS attack against our global DNS platform. We expect service to return to normal very shortly. Stay tuned an
by ted0 13y ago
We are in the process of mitigating a large scale DDoS attack against our global DNS platform. We expect service to return to normal very shortly. Stay tuned and let me know if you have any questions. ted@namecheap.com
- derwiki 13y agoThanks for posting here!
- sprouticus 13y agoThanks for the update, guys.
- nubela 13y agoYes please, thank you :) All my domains are down now but I understand how shitty (the panic!) it feels to have things going down. I'll be checking this.
- ChrisDiNicolas 13y agoGood luck guys!
- jik 13y agoJust for future reference, it's usually considered a good idea to put your status page on completely independent infrastructure so that it stays up even when the rest of your stuff goes down. A status page that doesn't work during an outage isn't particularly useful.
- kennhardy 13y agoLike!
- backspaces 13y agoNot having separate status hosting is liken not salting passwords. As a NC user, I may leave just for this reason
- ilikesnowflakes 13y agoIf the hackers really want to take you down, adding another server in isn't very hard...
- jik 13y agoIf you're as big as NameCheap, you can afford to pay CloudFlare or somebody like it to protect your status page.
- jkirker 13y agoCloudflare has also been nailed the last 3 weeks in a row causing outages. Just search Twitter for cloudflare DDOS or NTP or etc. etc. etc. At the end of the day there are currently so many slave machines out there we are all vulnerable. It's just the nature of things. At least outages are only temporary. It's much better than the early days were we'd be down for 12 hours at a time. https://twitter.com/search?q=cloudflare%20attack&src=typd https://twitter.com/search?q=cloudflare%20attack&src=typd
- nc-customer 13y agoI suspect the hackers are targeting one of namecheap's customers, not namecheap directly. Because that's usually the case, a good approach is to not give all customers the exact same nameservers.
- sparagi 13y agoI agree. We left Network Solutions b/c they were hit 3 times in less than a year. Maybe the website targets moved to Namecheap, so they were targeted also?
- ted0 13y agoGood point. The status page is on another cloud but since this is a DNS issue, the subdomain is down. In the future, we'll investigate running this page on a secondary DNS.
- jik 13y agoAccording to whois for namecheap.com, the DNS for that domain is hosted on dynect.net, and "host status.namecheap.com" resolves just fine (to 204.232.212.56), so it does not appear to be a DNS issue that is preventing your status page from working.
- irontoby 13y agoPosting up-to-the-minute updates on Twitter is also a good idea. Lots of tweets come back from a search for "Namecheap" & you want to be sure you're a part of that conversation!
- Jailout2000 13y agoThey've been posting updates 30 minutes before your post buddy, and still are now. https://twitter.com/Namecheap https://twitter.com/Namecheap
- ted0 13y agoYes, we are actively posting updates on Twitter.
- 13y ago
- w0ts0n 13y agoYou guys should really put a notice on your homepage or something. Good luck.
- tamar 13y agoThe homepage wasn't accessible until just a bit ago. We're still working on it. tamar (also at Namecheap)
- kitnos 13y agodo you have ETA?
- ted0 13y agoWe're working hard to resolve this and we will keep you posted with updates here. Unfortunately, I can't give you an exact ETA.
- t3ra 13y agoWOOH the Akamai realtime attack visualization is completely red at the moment: http://www.akamai.com/html/technology/dataviz1.html http://www.akamai.com/html/technology/dataviz1.html
- MuratC 13y agoYou need to provide some gift to your customers for this downtime. I am using NC for 10 years, every time on bad issues I continue to use. But this outage very bad, I lost money...
- ilikesnowflakes 13y agoDDOS attacks are not up to Namecheap. You want money, go talk to the people doing it. These are very hard to prevent.
- deleted 13y ago[deleted]
- kelton5020 13y agoThat's what insurance is for.
- jcink 13y agoWhile it's not a customer friendly viewpoint, it's not exactly what happened here. You have to consider what is being provided and how much was paid into it for said service. Had they been paying a lot of money for solid DNS I could agree with you, but they weren't. It's a completely free service. With an extremely low price for domains. Even though it's become almost a standard for domain registrars to provide DNS, it's still free. I've been using NC for years for my business (also a free service) and the downtime for what it provides has been mostly minimal. Now if I was paying namecheap specifically for enterprise DNS something like $10/month or $40/year and it included DDoS protection then yes I should be compensated. Namecheap gave people what they paid for - a domain, the DNS is just a really great perk.
- nc-customer 13y agoIf namecheap chose to stop assigning all customers the same list of DNS servers, it would benefit namecheap as well. There's 200+ people in the queue for live chat right now :) It's not DDOS mitigation or H/A, or some other high end feature.
- kelton5020 13y agoWas going to switch to route 53 while you guys were down and switch back, but the page says it'll take a day...Might as well just wait at that point. I know it's panic mode over there, but some kind of failover record would be awesome for when this happens in the future(or an option for one).
- irontoby 13y agoEverything related to DNS says it'll take a day but that's "worst case"... I've successfully transferred DNS for 5 Namecheap-registered domains to Route 53 since this all started a couple hours ago, and they're now up & running smoothly. Their "update DNS server" page was acting a bit wonky, kept saying some of my nameservers were invalid when they weren't, but I eventually got them all switched. This isn't a dig against Namecheap, it sounds like this attack is pretty bad, but for important domains Route53 just seems like a much better setup (geographically dispersed, different nameservers for each hosted zone, etc).
- kelton5020 13y agoYeah, Route53 isn't as feature rich though. Also I have the same problem, keeps giving me errors about bad nameservers. I guess I'll keep trying.
- mindo3 13y agoWhen did this attack start ?
- ted0 13y agoa little more than 2 hours ago
- nc-customer 13y agoMost DDOS attacks against a company like yours are actually attacks against a specific customer. If: a) you had a pool of DNS server names, say 20, all with unrelated hostnames b) you assigned 2 to each customer, randomly, when they configured a domain to use your servers. Then, a DDOS attack would impact 10% of your customers instead of 100%. (Assuming other practices, like null routing the target until resolved)
- irontoby 13y agoYes, this. Hopefully they take heed after this painful experience.
- kitnos 13y agohi already have OK's, but the DNS are all using the same IP :( bad sign?
- ilikesnowflakes 13y agoYou guys should add an option for us to put in an optional backup DNS record in the settings.
- ted0 13y agoI'd also like to add that we have redunancy on our DNS V1. I advise switching over to this, in the meantime. Please find the tutorial here: https://www.namecheap.com/support/knowledgebase/article.aspx/923/10/what-is-the-difference-between-your-dns-system-v-1-and-v-2 https://www.namecheap.com/support/knowledgebase/article.aspx...
- Jailout2000 13y agoETA how long it will take for the transfer to be completed? I know that editing host records usually is instantaneous (unlike other providers), but we're talking about changing the DNS servers here.
- Jailout2000 13y agoLooks to be up around five to ten minutes after executing the change. Not too terrible.
- hypnotist 13y agoThanks! I just did the switch and the website was up in few minutes.
- edwhitesell 13y agoI had a couple of domains to try this on. One domain switched over within a minute. The other has been almost an hour. I'm assuming the TLD makes a difference? .com was < 1 minute, .cm is > 55 minutes.
- fw0rd 13y agoI tried this and now for some reason my apache server is returning the default page. also I think it wiped out my mailserver settings -- my mail is hosted on namecheap. i guess i gotta wait till everything is fixed.
- User7 13y agoHo quickly will the switch to v1 execute?
- ted0 13y agoIt generally takes less than an hour.
- stevenh 13y agoDoes it take the same amount of time to complete that switching to another provider's DNS server takes? Many of us already switched to other DNS servers during the panic, and we'd like to know whether you'd suggest we reverse that change in order to jump to v1 instead for a quicker result. Thank you.
- dywtk 13y agoThe quick tut on switching to DNSv1 is nice however the option doesnt exist in my account
- trevorc 13y agoI took your advice and transferred a domain to DNSv1. That domain is still not back online, but all the domains I left as DNSv2 have come back!
- njyx 13y agoKudos for using a HN page to stay in touch
- megakf 13y agoDown again My domain down again