Three Days in August: What a DDoS Attack Exposed in Our Network
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
Three Days in August: What a DDoS Attack Exposed in Our Network
Unofficial Hacker News client; not affiliated with Y Combinator.
cube00 · · focus · HN ↗
Hopefully your logging infra is rock solid and nothing has been dropped in the flood. It wouldn't be the first time a DOS was used to mask the actual attack by overwhelming the monitoring infra.
> Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform. That fixed binding was exactly the problem during the attack: wherever we could change the address on short notice, availability could be restored, wherever we could not, only the blunt measure remained.
I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?
beecasthurlbow · · focus · HN ↗
I assume the customer controls the domain DNS records here rather than the hosting provider.
CNAME record: hosting provider can change underlying IP freely.
A record: hosting provider must get in touch with customer to change DNS.
cube00 · · focus · HN ↗
> we provide that customer’s connection to the internet
as providing the DNS infra for their customers.
nine_ch · · focus · HN ↗
[dead]
jiveturkey · · focus · HN ↗
and then up the stack a bit, they are confused about DNS' role in attack mitigation, at least generally speaking. perhaps there is something specific to their own DNS setup where this made a difference. they should just strike that part of the PM entirely.
that said, their reaction time is amazing. this would have included live troubleshooting during an ongoing incident! criticism aside, i wouldn't hesitate to use them if I wanted EU service.
nine_ch · · focus · HN ↗
[dead]