Incident Report – DDoS Attack
blog.dnsimple.com
blog.dnsimple.com
I've been a DnsMadeEasy customer for a while (they had an outage ~4 years ago from a 50Gbps attack), but once my year is up, I'm switching to Route53. The addition of the Geo DNS Queries was key for me. It isn't clear to me why I shouldn't pick Route53. DnsSimple's unlimited queries seems nice, but I kinda like having actual scaling costs forwarded to customers.
DDoS is a nasty problem. We've received a DDoS attack that shut the entire site down for days. We can't use Cloudflare because they don't support wildcard domains without their very expensive plan. I've also heard stories from people using Cloudflare that have still not been able to resolve DDoS issues (I'm not knocking Cloudflare, they're a great company that does a really good job fighting this very hard problem, but sometimes even they have trouble with it).
I'll be completely honest and say that I have no idea how to solve this problem. It's really, really, really hard. Switching to different service providers won't get you very far against the monster DDoS attacks that some people can execute.
Which is exactly what happened in this case. It sucks to be on the receiving end of this. We couldn't defend against it and let our customers down, and that hurts me deeply. We choose one approach to defense, which was internal, and that was a mistake. We're going to work on rectifying that now.
I swear by Route53, it is the only service I use on AWS and I have moved a lot of my clients over to it.
I'm curious did they know this in advance or discovered it after the fact?
I often wonder about business models where the core expense is "unlimited and free". The reality is there is nothing unlimited or free for the service provider. It seems with a business model like this you open yourself to people abusing your service either by accident or by choice. Imagine poor Mr. Customer here who most likely was having horrible problems thinking to themselves "These guys can do it and for free, if I go to X service they'll cost me a lot of money".
I'm a big believer in business models that incentivize both parties properly. I'm sure in general this service provider is arbitraging the 99.9% of domains that barely need any services. That said it only takes a couple of "opps" customers to drive your operational costs through the roof.
to pull it off properly as a service provider, you really need to have a solid understanding of user usage patterns.
one of the big problems that tips the low/high utilization ratio unfavorably is that unlimited plans that are primarily marketed for being unlimited tend to attract users in the high utilization bracket.
so the challenge for service providers is not just understanding users and understanding that ratio but figuring out how you are going to market to, and signup, those users who will be in the low utilization bracket and will essentially be paying for something they won't be user (which is hard to do)
it isn't hard to find case studies of companies that launch optimistically with one pricing plan around unlimited, to then only go back and revise their pricing and break promises because they didn't understand their users and were unable to market to and signup low utilization users.
one recent example is Bitcasa
Manage your DNS at one location on "master" (potentially a "private" server with IP restricted access and zone transfer ACLs).
Setup 2+ accounts with "DNS providers" that support incoming zone transfers - that is, they can operate as "slave" DNS servers, pulling records automatically from your "master" (once access rules are set of course) and returning results directly to clients making DNS queries.
Most "Secondary DNS" packages are < $50 year, so use a few, and don't worry about individual DNS networks being burnt to the ground.
My research into it is from a "manage your DNS records internally, then use a couple of providers for all public facing responders". In that situation all you need them to support is inbound transfers, which several do.
https://puck.nether.net/dns
https://acc.rollernet.us/
They're both free to sign up, provide free secondary DNS, zone transfers and fully support IPv6.I only stopped using them because I wanted to run my own DNS service.
They have an interesting blog post about setting up secondary DNS: http://blog.easydns.org/2013/09/10/what-we-are-doing-about-c...
I have no affiliation with them, just a happy customer.
CloudFlare?
Last I checked CloudFlare routinely handles[1] 10Gbps to 65Gbps attacks, and has successfully handled attacks as large as 300Gbps and 400Gbps. According to this report DNSSimple crumbled under 25Gbps.
[1]: https://support.cloudflare.com/hc/en-us/articles/200170216-H...
Granted we are probably more vulnerable to DoS, but our general uptime is far better now.
Investing in anti DDoS devices is important but even more important is for the perpetrators to face the consequences of their acts (or anyone who lets his machine being used by pirates - terminating or suspending their contract would be a fair response).
Abuse would be tricky, you might be able to limit it by letting only a few DDoS mitigation providers populate the list.
Other people share a network behind a NATed IP which is also a problem. They'd all receive a banner, check their computer and a test would come up negative.
No thanks.
This particular DDoS I actually believe is _not_ due to a botnet, or at least believe there is insufficient evidence either way. The attack appears to be using a technique/infrastructure I’ve been passively tracking for nearly a year, wherein the attack DNS requests are spoofed to appear from seemingly-random clients and sent to open recursive DNS servers across the Internet. This makes the attack look like a botnet to superficial analysis on the target side, but this isn’t necessarily the case. In the small amount of time I’ve so-far invested in trying to track down the origin, I have yet to observe generation of the initial query packets.
Unfortunately this is already in use with some malicious ads as well as phone scams to get people to give remote access to overseas tech centers that then scam them into paying good money for nothing.
To date the only tech line about this is, "nobody legitimate will ever contact you to tell you you're infected with a virus."
So I don't know how you could develop trust in that environment.