‹ BackHN Continuity

Thread

Three Days in August: What a DDoS Attack Exposed in Our Network

19 points · 25 comments · nine_ch

  1. cube00 · · focus · HN ↗
    > There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.

    Hopefully your logging infra is rock solid and nothing has been dropped in the flood. It wouldn't be the first time a DOS was used to mask the actual attack by overwhelming the monitoring infra.

    > Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform. That fixed binding was exactly the problem during the attack: wherever we could change the address on short notice, availability could be restored, wherever we could not, only the blunt measure remained.

    I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?

    1. jiveturkey · · focus · HN ↗
      indeed, this (A vs CNAME) is nonsense. I applaud this provider's transparency but they missed a 4th gap: inadequate network security expertise. Two of the 3 gaps identified are perhaps not baseline but they are well understood hygiene. They shouldn't have had to learn these things as a result of an incident. (the 1st gap, not monitoring customer network blocks, is very understandable and i find no fault there.)

      and then up the stack a bit, they are confused about DNS' role in attack mitigation, at least generally speaking. perhaps there is something specific to their own DNS setup where this made a difference. they should just strike that part of the PM entirely.

      that said, their reaction time is amazing. this would have included live troubleshooting during an ongoing incident! criticism aside, i wouldn't hesitate to use them if I wanted EU service.

      1. nine_ch · · focus · HN ↗

        [dead]

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.