DDoS Attack Against Default DNS System v2
status.namecheap.com
status.namecheap.com
We are mitigating this as fast as we possibly can. I and we share your pain and frustration at the inconvenience this causes.
I'll check HN as we restore service and update will now go out on our status page every 20 minutes.
My apologies once again for the inconvenience this causes.
I appreciate my responses here are a little obscure but we do practice security through obscurity so I am not going to get into specifics that can be used against us in any future attack.
I will say we employ a range of technologies, internal and external, a ddos defense/mitigation. This does include CloudFlare
A lessons-learned whitepaper would be radical, I'll chat to a few of the people that I run this with and see what they think.
All of it will be managed by configuration files in version control, and won't require anything antiquated like zone transfers.
If the code is clean enough I'll release it with pluggable registrar and DNS provider modules.
It's pretty easy to setup too. [1] For my purposes cheaper than Route53.
[1] https://www.zeitgeist.se/2014/05/01/google-cloud-dns-how-to/
Anyone know the details of how these things happen?
https://developers.google.com/speed/public-dns/cache http://cachecheck.opendns.com/
The one problem I encountered with cloudflare is that they don't allow you specify none cloudflare NS.
This presents a problem if you want to have redundant, cross provider DNS.
In our case, we could still specify a cross-provider mix of NS records at our registrar, but it seems like it doesn't take affect until the TTL on the cached NS records expires. So - this left us with a failover, but not really a graceful one.
And it's to be expected to be slightly slower, at least for dynamic requests, since it's a reverse proxy. I doubt it's limited to the free tier.
I've used the DNS for a few years without any issues whatsoever, so I'd recommend them for that.
Any suggestions?
My only gripe would be that the claimed support response times as well as the 'call-me-back' button don't work as advertised.
Seems like they have a nice UI but the lack of technical details would make me a bit wary of it.
And I know they have at least 5 more.
In May, Point received a DDoS that took all (or many?) of their nameservers down and they didn't communicate what was happening very well.
I moved back to self-hosting although, like others in this thread, I'd prefer to settle on using a few major players (Route53, Google, Cloudflare) to reduce the reliance on any one of them.