Details Behind Today's Internet Hacks
blog.cloudflare.com
blog.cloudflare.com
On the HN post "Google.ps domain was hacked (google.ps)" [1], HN user biot predicted this exact scenario, although not a zero day most likely. He talked about submitting hacked sites to HN "... and thousands of HN readers get infected by a zero-day exploit. Maybe. If you're thinking of submitting a known compromised site to HN, consider instead submitting a third-party site which explains/documents the compromise. Ideally from a respected security research company". [2]
Next time a startup goes down, ask yourself: if I were on a bridge call with their ops team, could I use this to sell my company's reliability product? Clearly, the answer is yes.
Classy, too, jumping out in front of MelbourneIT's response then speculating on it. I would be furious about Cloudflare writing a details-thin "postmortem," headlining it as a postmortem, analyzing my initial statement to customers in it, then getting it on HN before DNS caches are even cold from the incident itself. It's not even subtle.
This is the sort of thing I remember in discussions about using Cloudflare. There's lots of choices for CDNs, a market growing surprisingly full of ambulance chasers: one CDN startup had the fucking courage to email me directly after a hellish multi-hour outage and say "want to set up a call to discuss how our product could have prevented this outage?" I was still awake from fixing the problem overnight and no, your CDN is not going to fix my catastrophic DB failure. Get bent.
This is a disgusting move by Cloudflare. The little human network signoff made me gag; don't forget, small ops teams, you will only get things done if you know people. Notice HuffPo wasn't on the call? Exactly.
But at least they rode in with some knights from the mighty Google and OpenDNS to patch some caching issues and release a State of the Domains address.
Meanwhile the empires of NYT and Twitter were left being ravaged by hordes of Syrian Ninjas and an overseas registrar.
I remember there being a more somber post after the whole incident by another blog detailing just how little fluctations there were on the alleged day of the incident, and how the numbers didn't stack up.
Cloudflare is tricky, isn't it?
"I'm super impressed by the operations, incident/crisis management & expertise of the @CloudFlare and @OpenDNS teams."
edit: thanks John.
Can you point to what you feel makes this statement appropriate on behalf of your company? I can't identify what annoys me most about it, because there are many things: the "it's who you know in ops" attitude that I've been fighting for my entire career, the creation of a Batman-esque hero at a startup CDN provider who assembles a team to guide the lesser ops teams through a crisis, the overdramatizing of a DNS hijack that happens countless times daily (just with an interesting vector this time, but certainly not the first of ITS kind, either), speculating on another company's statements, preempting an official response with your own "postmortem" to score some traffic...
It's particularly frustrating because I've been in this exact scenario, to the T and including a registrar compromise, before. But because my personal side project doesn't have name pull, I didn't get a CloudFlare Crack Squad on speakerphone calling in a dozen courtesy phone favors to score my contract. And I had to wait for tickets and TTLs like everyone else. That sounds bitter -- and I hate bringing it up for that reason -- but that's why this is ethically shitty. Either you're playing favorites or capitalizing on something for sales. There is no third option, not even an altruistic one.
http://www.rajiv.com/blog/2009/12/10/tech-ops-irc/#2013Aug28
Address something smaller and bite-sized, like preempting MelbourneIT's statement with your own and speculating on their behalf. Can you at least defend that inappropriateness? Can we start there?
Your company provided guidance and connections, which makes this statement inappropriate. Or did CloudFlare do something that has been left out of all statements?
I am not annoyed by your "good deed". I'm annoyed by how hard and how inappropriately you are capitalizing upon it as a PR coup, before the ashes have even settled. The victim tone is discouraging for this conversation, I have to say, and it's quite unbecoming.
So if the content on the redirected page had been more subtle - for example, mirroring NYTimes but editing stories etc - then things would have taken a lot longer to have been noticed?
http://reports.internic.net/cgi/whois?whois_nic=microsoft.co...
Domain Name: MICROSOFT.COM
Registrar: MARKMONITOR INC.
Whois Server: whois.markmonitor.com
Referral URL: http://www.markmonitor.com
Name Server: NS1.MSFT.NET
Name Server: NS2.MSFT.NET
Name Server: NS3.MSFT.NET
Name Server: NS4.MSFT.NET
Name Server: NS5.MSFT.NET
Status: clientDeleteProhibited
Status: clientTransferProhibited
Status: clientUpdateProhibited
Status: serverDeleteProhibited
Status: serverTransferProhibited
Status: serverUpdateProhibited
Updated Date: 09-aug-2011
Creation Date: 02-may-1991
Expiration Date: 03-may-2021These flags are the functional equivalent of forcing you to break a piece of glass before pushing the fire alarm button.
It's not unspoofable, but it is an time consuming extra step that involves a human on the receiving end.
Edit: I was thinking of the client(Update|Transfer|Delete)Prohibited flags, which is a registrar lock. I'm not even sure how one goes about setting the "server" version of those flags for a registry lock, but it's probably even more complicated.
DomainPeople does have the feature. It is also the registrar for Gate.com and Hostway.
But if your entire registry is hacked? Probably yes, assuming you have sufficient credibility for them to notice you.
It's always about the money. I learned that from Die Hard 3.
How does this work? How would you get to DNS.EWR1.NYTIMES.COM without first knowing where nytimes.com is?
It's good advice, but seems kind of irrelevant.
> It's worth noting that while some of Twitter's utility domains were redirected, Twitter.com was not -- and Twitter.com has a registry lock in place.
The former is with Verisign and cannot easily be removed by the registrar. The latter is with the registrar and can be removed by the registrar. In whois status codes "clientXXX" = registrar lock (weak). "serverXXX" = registry lock (stronger).
Edit: I don't know why, but the nameservers I use don't resolve any address for nytimes.com now. If I query 8.8.8.8 directly I get a response. So, could be they're still suffering from this attack, which sucks.
They were one of the registrars compromised back in May as part of Hack the Planet[1]. If I recall correctly, they were the only registrar where the attackers actually got shell access on a server. That's when they lost any reputation for security in my eyes.
[1] http://www.theregister.co.uk/2013/05/09/melbourne_it_hacking...