Skip to content

Comment on DNSimple DDOS Attack

Comments

"30 minute ETA from our network provider to begin scrubbing traffic in a location with capacity."

https://twitter.com/dnsimplestatus/status/539551209452232705

It's surprising that they're appear to not be multihomed...

http://bgp.he.net/AS32771

Unlike Dyn or CloudFlare:

http://bgp.he.net/AS33517 http://bgp.he.net/AS13335

They're in ServerCentral's datacenter and ServerCentral is very much multi homed. They wouldn't gain anything by doing native BGP to all these peers in the exact same datacenter when SC's backbone will handle this stuff for them.

Doing native BGP would allow them to anycast, which would increase their reliability and allow them to sink traffic much more easily. DDOS traffic sink starts announcing your AS and anycast IP block close to the traffic source, sinking that traffic and allowing real traffic through.

I'm pretty sure they're only in one of Server Central's datacenters. Anycast won't help. That's why I said they don't gain anything by directly peering.

"New ETA is 30 minutes from now, trying to get systems wired up in the data center."

https://twitter.com/dnsimple/status/539560631863877632

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.