Skip to content

Comment on Sourcehut network outage post-mortemparent

Comments

I'd consider it mostly protected, because no their servers are not on OVH, just a single box performing front-facing NAT/proxy essentially. The attacker now just needs to find the "secret" production subnet and attack it directly instead of through the front-facing NAT addresses.

That is very easy to mitigate, because you null route the production subnet except for a VPN that only can be reached by the proxy. You can even VPN over a completely different IPv6 route.

They could still try to knock your entire datacenter offline but that is much harder.

That's not much harder, that's exactly what happened to them in the initial attack.

You're still depending on either a "secret" IPv6 network, or your upstream provider performing some source-based routing to only route packets from the VPN connection. I doubt that's available to a simple colo customer.

That's true. I guess it'd be more accurate to say they're on OVH's network, not necessarily their compute and other infrastructure.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.