5 ms·
> DNS is so trivial to distribute that it's not normally a worthwhile attack vector. F5 knows that. Really? So what do you say for the evidence they provide in
by kvs 17y ago
> DNS is so trivial to distribute that it's not normally a worthwhile attack vector. F5 knows that.
Really? So what do you say for the evidence they provide in the article, from Arbor and from Twitter's DNS provider?
- gfodor 17y agoPardon me if I'm just being dumb here, but the notion that DNS servers are two "lonely servers" seems totally wrong. They might be two IP addresses, but you can be damn sure DynDNS doesn't have two klunky duct taped together linux boxes on those IPs as the article would lead you to believe. To me their objectivity went out the window when they started that train of FUD. My naive guess here is that twitter probably accidentally set really low TTLs on their root DNS entries on dyndns so some downtime on the dyndns servers due to a DDoS (the same kind of DDoS the article seems to say is not the root cause) caused the intermediate caches to all expire as well. DNS is designed to withstand these kind of outages if you configure it correctly since most DNS entries should be able to be cached for a damn long time. We use dyndns and set our public DNS entries to have a large TTL and internal dynamic IPs to be short TTL. EC2 elastic IPs make this really nice since we can swap out physical machines behind the elastic IPs without having to update any DNS at all.
- moe 17y agoWell, my best guess would be: Incompetence. If your business is DNS and you fail at the basic task of distributing it for fault tolerance then what other explanation could there be? To make this clear. The cost for running n DNS servers for your domain in n datacenters is equal to the cost of having one (possibly rented) pizza-box in each datacenter. You can list any number of nameservers for any domain. Domains like google.com and microsoft.com have up to 5, for example. Synchronizing the nameservers is a non-issue. For tinydns it's a one-liner (rsync), for bind it's a few lines of axfer configuration. There is no administrative overhead. You don't even have to worry about host failures much because DNS is resilient by design (that's why you can have multiple NS records in first place). So, in dollar terms, in most datacenters a rented pizza-box starts at around $30/month, often cheaper. Making your DNS 5-way redundant therefore costs roughly $150/month. You don't have to be google to afford that. And a potential attacker will damn sure not even attempt to take out your 5 DNS locations. He will go directly for your application instead because that one, in most cases, can not be distributed over 5 locations for a measly 150 dollars/month.
- kvs 17y agoFWIW: http://www.blyon.com/blog/index.php/2009/08/06/twitters-hosting-illustrated-fckyeahboobies-com/ http://www.blyon.com/blog/index.php/2009/08/06/twitters-host...