https://news.gandi.net/en/2017/07/report-on-july-7-2017-inci...
https://news.gandi.net/en/2017/07/report-on-july-7-2017-inci...
One of my site user's reported that the website is inaccessible on Friday. I went to check and observed the DNS changing. Then went to check Route 53 status page[2] in which I learn that this is not specific to my site. The behavior is exactly the same as what is described in the SWITCH report[1]. Luckily that I have HSTS on my site, so the damage is limited (users not getting redirected), and Gandi seems to fixed this quick enough (I was in the middle of commuting back home by the time of the attack.)
[1]: https://securityblog.switch.ch/2017/07/07/94-ch-li-domain-na...
[2]: http://status.aws.amazon.com/ (The blue icon for Amazon Route 53 Domain Registration)
I issued a support ticket to aws today to see what measures can be taken, otherwise we might need to change registrar.
This makes no sense - how did the attacker get between gandi.net and their technical partner in order to MITM them? MITMs aren't magic - simply sending an unencrypted password somewhere doesn't result in it becoming public knowledge unless a router or switch in the path is malicious.
On the top of my head, bgp hijacking perhaps?
> MITMs aren't magic
No. But do not trust the network. Ever.
And no, don't trust the network, but "the network isn't trustworthy" is not a diagnosis, only a potential risk factor. "X entity used BGP hijacking to situate their router between me and Y" is a diagnosis.