‹ BackHN Continuity

Thread

Three Days in August: What a DDoS Attack Exposed in Our Network

19 points · 25 comments · nine_ch

  1. cube00 · · focus · HN ↗
    > There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.

    Hopefully your logging infra is rock solid and nothing has been dropped in the flood. It wouldn't be the first time a DOS was used to mask the actual attack by overwhelming the monitoring infra.

    > Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform. That fixed binding was exactly the problem during the attack: wherever we could change the address on short notice, availability could be restored, wherever we could not, only the blunt measure remained.

    I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?

    1. nine_ch · · focus · HN ↗

      [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.