Files
nexus/sreweekly/articles/45/04-ddos-on-dyn-impacts-twitter-spotify-reddit.html
2026-09-12 17:23:01 +08:00

987 lines
85 KiB
HTML
Raw Blame History

This file contains invisible Unicode characters
This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
<!DOCTYPE html>
<!--[if IE 7]>
<html class="ie ie7" lang="en-US">
<![endif]-->
<!--[if IE 8]>
<html class="ie ie8" lang="en-US">
<![endif]-->
<!--[if !(IE 7) | !(IE 8) ]><!-->
<html lang="en-US">
<!--<![endif]-->
<head>
<meta charset="UTF-8" />
<meta name="viewport" content="width=device-width" />
<link rel="profile" href="http://gmpg.org/xfn/11" />
<!--[if lt IE 9]>
<script src="https://krebsonsecurity.com/wp-content/themes/kos-mar2021/js/html5.js" type="text/javascript"></script>
<![endif]-->
<title>DDoS on Dyn Impacts Twitter, Spotify, Reddit &#8211; Krebs on Security</title>
<meta name='robots' content='max-image-preview:large' />
<link rel='dns-prefetch' href='//fonts.googleapis.com' />
<link rel="alternate" type="application/rss+xml" title="Krebs on Security &raquo; Feed" href="https://krebsonsecurity.com/feed/" />
<link rel="alternate" type="application/rss+xml" title="Krebs on Security &raquo; Comments Feed" href="https://krebsonsecurity.com/comments/feed/" />
<link rel="alternate" type="application/rss+xml" title="Krebs on Security &raquo; DDoS on Dyn Impacts Twitter, Spotify, Reddit Comments Feed" href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/feed/" />
<script type="text/javascript">
window._wpemojiSettings = {"baseUrl":"https:\/\/s.w.org\/images\/core\/emoji\/14.0.0\/72x72\/","ext":".png","svgUrl":"https:\/\/s.w.org\/images\/core\/emoji\/14.0.0\/svg\/","svgExt":".svg","source":{"concatemoji":"https:\/\/krebsonsecurity.com\/wp-includes\/js\/wp-emoji-release.min.js?ver=6.2.2"}};
/*! This file is auto-generated */
!function(e,a,t){var n,r,o,i=a.createElement("canvas"),p=i.getContext&&i.getContext("2d");function s(e,t){p.clearRect(0,0,i.width,i.height),p.fillText(e,0,0);e=i.toDataURL();return p.clearRect(0,0,i.width,i.height),p.fillText(t,0,0),e===i.toDataURL()}function c(e){var t=a.createElement("script");t.src=e,t.defer=t.type="text/javascript",a.getElementsByTagName("head")[0].appendChild(t)}for(o=Array("flag","emoji"),t.supports={everything:!0,everythingExceptFlag:!0},r=0;r<o.length;r++)t.supports[o[r]]=function(e){if(p&&p.fillText)switch(p.textBaseline="top",p.font="600 32px Arial",e){case"flag":return s("\ud83c\udff3\ufe0f\u200d\u26a7\ufe0f","\ud83c\udff3\ufe0f\u200b\u26a7\ufe0f")?!1:!s("\ud83c\uddfa\ud83c\uddf3","\ud83c\uddfa\u200b\ud83c\uddf3")&&!s("\ud83c\udff4\udb40\udc67\udb40\udc62\udb40\udc65\udb40\udc6e\udb40\udc67\udb40\udc7f","\ud83c\udff4\u200b\udb40\udc67\u200b\udb40\udc62\u200b\udb40\udc65\u200b\udb40\udc6e\u200b\udb40\udc67\u200b\udb40\udc7f");case"emoji":return!s("\ud83e\udef1\ud83c\udffb\u200d\ud83e\udef2\ud83c\udfff","\ud83e\udef1\ud83c\udffb\u200b\ud83e\udef2\ud83c\udfff")}return!1}(o[r]),t.supports.everything=t.supports.everything&&t.supports[o[r]],"flag"!==o[r]&&(t.supports.everythingExceptFlag=t.supports.everythingExceptFlag&&t.supports[o[r]]);t.supports.everythingExceptFlag=t.supports.everythingExceptFlag&&!t.supports.flag,t.DOMReady=!1,t.readyCallback=function(){t.DOMReady=!0},t.supports.everything||(n=function(){t.readyCallback()},a.addEventListener?(a.addEventListener("DOMContentLoaded",n,!1),e.addEventListener("load",n,!1)):(e.attachEvent("onload",n),a.attachEvent("onreadystatechange",function(){"complete"===a.readyState&&t.readyCallback()})),(e=t.source||{}).concatemoji?c(e.concatemoji):e.wpemoji&&e.twemoji&&(c(e.twemoji),c(e.wpemoji)))}(window,document,window._wpemojiSettings);
</script>
<style type="text/css">
img.wp-smiley,
img.emoji {
display: inline !important;
border: none !important;
box-shadow: none !important;
height: 1em !important;
width: 1em !important;
margin: 0 0.07em !important;
vertical-align: -0.1em !important;
background: none !important;
padding: 0 !important;
}
</style>
<link rel='stylesheet' id='colorbox-theme1-css' href='https://krebsonsecurity.com/wp-content/plugins/jquery-lightbox-for-native-galleries/colorbox/theme1/colorbox.css?ver=1.3.14' type='text/css' media='screen' />
<link rel='stylesheet' id='wp-block-library-css' href='https://krebsonsecurity.com/wp-includes/css/dist/block-library/style.min.css?ver=6.2.2' type='text/css' media='all' />
<link rel='stylesheet' id='classic-theme-styles-css' href='https://krebsonsecurity.com/wp-includes/css/classic-themes.min.css?ver=6.2.2' type='text/css' media='all' />
<style id='global-styles-inline-css' type='text/css'>
body{--wp--preset--color--black: #000000;--wp--preset--color--cyan-bluish-gray: #abb8c3;--wp--preset--color--white: #ffffff;--wp--preset--color--pale-pink: #f78da7;--wp--preset--color--vivid-red: #cf2e2e;--wp--preset--color--luminous-vivid-orange: #ff6900;--wp--preset--color--luminous-vivid-amber: #fcb900;--wp--preset--color--light-green-cyan: #7bdcb5;--wp--preset--color--vivid-green-cyan: #00d084;--wp--preset--color--pale-cyan-blue: #8ed1fc;--wp--preset--color--vivid-cyan-blue: #0693e3;--wp--preset--color--vivid-purple: #9b51e0;--wp--preset--gradient--vivid-cyan-blue-to-vivid-purple: linear-gradient(135deg,rgba(6,147,227,1) 0%,rgb(155,81,224) 100%);--wp--preset--gradient--light-green-cyan-to-vivid-green-cyan: linear-gradient(135deg,rgb(122,220,180) 0%,rgb(0,208,130) 100%);--wp--preset--gradient--luminous-vivid-amber-to-luminous-vivid-orange: linear-gradient(135deg,rgba(252,185,0,1) 0%,rgba(255,105,0,1) 100%);--wp--preset--gradient--luminous-vivid-orange-to-vivid-red: linear-gradient(135deg,rgba(255,105,0,1) 0%,rgb(207,46,46) 100%);--wp--preset--gradient--very-light-gray-to-cyan-bluish-gray: linear-gradient(135deg,rgb(238,238,238) 0%,rgb(169,184,195) 100%);--wp--preset--gradient--cool-to-warm-spectrum: linear-gradient(135deg,rgb(74,234,220) 0%,rgb(151,120,209) 20%,rgb(207,42,186) 40%,rgb(238,44,130) 60%,rgb(251,105,98) 80%,rgb(254,248,76) 100%);--wp--preset--gradient--blush-light-purple: linear-gradient(135deg,rgb(255,206,236) 0%,rgb(152,150,240) 100%);--wp--preset--gradient--blush-bordeaux: linear-gradient(135deg,rgb(254,205,165) 0%,rgb(254,45,45) 50%,rgb(107,0,62) 100%);--wp--preset--gradient--luminous-dusk: linear-gradient(135deg,rgb(255,203,112) 0%,rgb(199,81,192) 50%,rgb(65,88,208) 100%);--wp--preset--gradient--pale-ocean: linear-gradient(135deg,rgb(255,245,203) 0%,rgb(182,227,212) 50%,rgb(51,167,181) 100%);--wp--preset--gradient--electric-grass: linear-gradient(135deg,rgb(202,248,128) 0%,rgb(113,206,126) 100%);--wp--preset--gradient--midnight: linear-gradient(135deg,rgb(2,3,129) 0%,rgb(40,116,252) 100%);--wp--preset--duotone--dark-grayscale: url('#wp-duotone-dark-grayscale');--wp--preset--duotone--grayscale: url('#wp-duotone-grayscale');--wp--preset--duotone--purple-yellow: url('#wp-duotone-purple-yellow');--wp--preset--duotone--blue-red: url('#wp-duotone-blue-red');--wp--preset--duotone--midnight: url('#wp-duotone-midnight');--wp--preset--duotone--magenta-yellow: url('#wp-duotone-magenta-yellow');--wp--preset--duotone--purple-green: url('#wp-duotone-purple-green');--wp--preset--duotone--blue-orange: url('#wp-duotone-blue-orange');--wp--preset--font-size--small: 13px;--wp--preset--font-size--medium: 20px;--wp--preset--font-size--large: 36px;--wp--preset--font-size--x-large: 42px;--wp--preset--spacing--20: 0.44rem;--wp--preset--spacing--30: 0.67rem;--wp--preset--spacing--40: 1rem;--wp--preset--spacing--50: 1.5rem;--wp--preset--spacing--60: 2.25rem;--wp--preset--spacing--70: 3.38rem;--wp--preset--spacing--80: 5.06rem;--wp--preset--shadow--natural: 6px 6px 9px rgba(0, 0, 0, 0.2);--wp--preset--shadow--deep: 12px 12px 50px rgba(0, 0, 0, 0.4);--wp--preset--shadow--sharp: 6px 6px 0px rgba(0, 0, 0, 0.2);--wp--preset--shadow--outlined: 6px 6px 0px -3px rgba(255, 255, 255, 1), 6px 6px rgba(0, 0, 0, 1);--wp--preset--shadow--crisp: 6px 6px 0px rgba(0, 0, 0, 1);}:where(.is-layout-flex){gap: 0.5em;}body .is-layout-flow > .alignleft{float: left;margin-inline-start: 0;margin-inline-end: 2em;}body .is-layout-flow > .alignright{float: right;margin-inline-start: 2em;margin-inline-end: 0;}body .is-layout-flow > .aligncenter{margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > .alignleft{float: left;margin-inline-start: 0;margin-inline-end: 2em;}body .is-layout-constrained > .alignright{float: right;margin-inline-start: 2em;margin-inline-end: 0;}body .is-layout-constrained > .aligncenter{margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > :where(:not(.alignleft):not(.alignright):not(.alignfull)){max-width: var(--wp--style--global--content-size);margin-left: auto !important;margin-right: auto !important;}body .is-layout-constrained > .alignwide{max-width: var(--wp--style--global--wide-size);}body .is-layout-flex{display: flex;}body .is-layout-flex{flex-wrap: wrap;align-items: center;}body .is-layout-flex > *{margin: 0;}:where(.wp-block-columns.is-layout-flex){gap: 2em;}.has-black-color{color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-color{color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-color{color: var(--wp--preset--color--white) !important;}.has-pale-pink-color{color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-color{color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-color{color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-color{color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-color{color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-color{color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-color{color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-color{color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-color{color: var(--wp--preset--color--vivid-purple) !important;}.has-black-background-color{background-color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-background-color{background-color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-background-color{background-color: var(--wp--preset--color--white) !important;}.has-pale-pink-background-color{background-color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-background-color{background-color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-background-color{background-color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-background-color{background-color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-background-color{background-color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-background-color{background-color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-background-color{background-color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-background-color{background-color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-background-color{background-color: var(--wp--preset--color--vivid-purple) !important;}.has-black-border-color{border-color: var(--wp--preset--color--black) !important;}.has-cyan-bluish-gray-border-color{border-color: var(--wp--preset--color--cyan-bluish-gray) !important;}.has-white-border-color{border-color: var(--wp--preset--color--white) !important;}.has-pale-pink-border-color{border-color: var(--wp--preset--color--pale-pink) !important;}.has-vivid-red-border-color{border-color: var(--wp--preset--color--vivid-red) !important;}.has-luminous-vivid-orange-border-color{border-color: var(--wp--preset--color--luminous-vivid-orange) !important;}.has-luminous-vivid-amber-border-color{border-color: var(--wp--preset--color--luminous-vivid-amber) !important;}.has-light-green-cyan-border-color{border-color: var(--wp--preset--color--light-green-cyan) !important;}.has-vivid-green-cyan-border-color{border-color: var(--wp--preset--color--vivid-green-cyan) !important;}.has-pale-cyan-blue-border-color{border-color: var(--wp--preset--color--pale-cyan-blue) !important;}.has-vivid-cyan-blue-border-color{border-color: var(--wp--preset--color--vivid-cyan-blue) !important;}.has-vivid-purple-border-color{border-color: var(--wp--preset--color--vivid-purple) !important;}.has-vivid-cyan-blue-to-vivid-purple-gradient-background{background: var(--wp--preset--gradient--vivid-cyan-blue-to-vivid-purple) !important;}.has-light-green-cyan-to-vivid-green-cyan-gradient-background{background: var(--wp--preset--gradient--light-green-cyan-to-vivid-green-cyan) !important;}.has-luminous-vivid-amber-to-luminous-vivid-orange-gradient-background{background: var(--wp--preset--gradient--luminous-vivid-amber-to-luminous-vivid-orange) !important;}.has-luminous-vivid-orange-to-vivid-red-gradient-background{background: var(--wp--preset--gradient--luminous-vivid-orange-to-vivid-red) !important;}.has-very-light-gray-to-cyan-bluish-gray-gradient-background{background: var(--wp--preset--gradient--very-light-gray-to-cyan-bluish-gray) !important;}.has-cool-to-warm-spectrum-gradient-background{background: var(--wp--preset--gradient--cool-to-warm-spectrum) !important;}.has-blush-light-purple-gradient-background{background: var(--wp--preset--gradient--blush-light-purple) !important;}.has-blush-bordeaux-gradient-background{background: var(--wp--preset--gradient--blush-bordeaux) !important;}.has-luminous-dusk-gradient-background{background: var(--wp--preset--gradient--luminous-dusk) !important;}.has-pale-ocean-gradient-background{background: var(--wp--preset--gradient--pale-ocean) !important;}.has-electric-grass-gradient-background{background: var(--wp--preset--gradient--electric-grass) !important;}.has-midnight-gradient-background{background: var(--wp--preset--gradient--midnight) !important;}.has-small-font-size{font-size: var(--wp--preset--font-size--small) !important;}.has-medium-font-size{font-size: var(--wp--preset--font-size--medium) !important;}.has-large-font-size{font-size: var(--wp--preset--font-size--large) !important;}.has-x-large-font-size{font-size: var(--wp--preset--font-size--x-large) !important;}
.wp-block-navigation a:where(:not(.wp-element-button)){color: inherit;}
:where(.wp-block-columns.is-layout-flex){gap: 2em;}
.wp-block-pullquote{font-size: 1.5em;line-height: 1.6;}
</style>
<link rel='stylesheet' id='contact-form-7-css' href='https://krebsonsecurity.com/wp-content/plugins/contact-form-7/includes/css/styles.css?ver=5.8.2' type='text/css' media='all' />
<link rel='stylesheet' id='publisho-style-css' href='https://krebsonsecurity.com/wp-content/themes/kos-mar2021/style.css?subver=1.2&#038;ver=6.2.2' type='text/css' media='all' />
<style id='publisho-style-inline-css' type='text/css'>
.themonic-nav .current-menu-item > a, .themonic-nav .current-menu-ancestor > a, .themonic-nav .current_page_item > a, .themonic-nav .current_page_ancestor > a {
background: #cc6600;
}
.themonic-nav ul.nav-menu, .themonic-nav div.nav-menu > ul {
border-bottom: 5px solid #cc6600;
}
#site-navigation .topheadmenu a {
background: rgba(0, 0, 0, 0);
}
.themonic-nav li a:hover {
background: #cc6600;
}
.themonic-nav li:hover {
background: #cc6600;
}.wrapper .flexslider {margin: 0 0 30px;}.frontp .btm-wrap {
border-top: 1px solid #e9e9e9;
}
.entry-summary {
border-top: none;
}.frontp .btm-wrap { margin-bottom: 30px;}.site { font-size:14px;}.site { font-family:'Roboto', arial ;}
</style>
<link rel='stylesheet' id='publisho-custom-style-css' href='https://krebsonsecurity.com/wp-content/themes/kos-mar2021/custom.css?subver=1.2&#038;ver=6.2.2' type='text/css' media='all' />
<!--[if lt IE 9]>
<link rel='stylesheet' id='publisho-ie-css' href='https://krebsonsecurity.com/wp-content/themes/kos-mar2021/css/ie.css?ver=20160606' type='text/css' media='all' />
<![endif]-->
<link rel='stylesheet' id='fontawesome-css-css' href='https://krebsonsecurity.com/wp-content/themes/kos-mar2021/fonts/font-awesome.min.css?ver=6.2.2' type='text/css' media='all' />
<link rel='stylesheet' id='publisho_custom_fonts-css' href='//fonts.googleapis.com/css?family=Roboto%3Aregular%2Citalic%2C500%26subset%3Dlatin%2C' type='text/css' media='screen' />
<script type='text/javascript' src='https://krebsonsecurity.com/wp-includes/js/jquery/jquery.min.js?ver=3.6.4' id='jquery-core-js'></script>
<script type='text/javascript' src='https://krebsonsecurity.com/wp-includes/js/jquery/jquery-migrate.min.js?ver=3.4.0' id='jquery-migrate-js'></script>
<script type='text/javascript' src='https://krebsonsecurity.com/wp-content/plugins/jquery-lightbox-for-native-galleries/colorbox/jquery.colorbox-min.js?ver=1.3.14' id='colorbox-js'></script>
<link rel="https://api.w.org/" href="https://krebsonsecurity.com/wp-json/" /><link rel="alternate" type="application/json" href="https://krebsonsecurity.com/wp-json/wp/v2/posts/36727" /><link rel="EditURI" type="application/rsd+xml" title="RSD" href="https://krebsonsecurity.com/xmlrpc.php?rsd" />
<link rel="wlwmanifest" type="application/wlwmanifest+xml" href="https://krebsonsecurity.com/wp-includes/wlwmanifest.xml" />
<meta name="generator" content="WordPress 6.2.2" />
<link rel="canonical" href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/" />
<link rel='shortlink' href='https://krebsonsecurity.com/?p=36727' />
<link rel="alternate" type="application/json+oembed" href="https://krebsonsecurity.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fkrebsonsecurity.com%2F2016%2F10%2Fddos-on-dyn-impacts-twitter-spotify-reddit%2F" />
<link rel="alternate" type="text/xml+oembed" href="https://krebsonsecurity.com/wp-json/oembed/1.0/embed?url=https%3A%2F%2Fkrebsonsecurity.com%2F2016%2F10%2Fddos-on-dyn-impacts-twitter-spotify-reddit%2F&#038;format=xml" />
<!-- JavaScript Pull-Quotes plugin v2.2 -->
<link rel="stylesheet" href="https://krebsonsecurity.com/wp-content/plugins/jspullquotes/resources/jspullquotes-core.css" type="text/css" />
<link rel="stylesheet" href="https://krebsonsecurity.com/wp-content/plugins/jspullquotes/resources/jspullquotes-default.css" type="text/css" />
<script type="text/javascript" src="https://krebsonsecurity.com/wp-content/plugins/jspullquotes/resources/jspullquotes.js"></script>
<script type="text/javascript">
var arrOptions = new Array("1", "1", "right", "1", "1", "blockquote", "pullquote", "pullquote pqRight");
pullQuoteOpts(arrOptions);
</script>
<!-- end pull-quote additions -->
<!-- jQuery Lightbox For Native Galleries v3.1.3 | http://www.viper007bond.com/wordpress-plugins/jquery-lightbox-for-native-galleries/ -->
<script type="text/javascript">
// <![CDATA[
jQuery(document).ready(function($){
$(".gallery").each(function(index, obj){
var galleryid = Math.floor(Math.random()*10000);
$(obj).find("a").colorbox({rel:galleryid, maxWidth:"95%", maxHeight:"95%"});
});
$("a.lightbox").colorbox({maxWidth:"95%", maxHeight:"95%"});
});
// ]]>
</script>
<style type="text/css" id="custom-background-css">
body.custom-background { background-color: #ffffff; }
</style>
</head>
<body class="post-template-default single single-post postid-36727 single-format-standard custom-background custom-background-white single-author">
<div id="page" class="site">
<!-- <div class="publisho-top-mobile-nav clear"></div> -->
<div class="themonic-logo themonic-ad3"><div class="a-statement">Advertisement</div><a href="https://flashpoint.io/ignite/vulnerability-intelligence/?utm_source=krebsonsecurity&amp;utm_medium=display&amp;utm_campaign=brand-vuln&amp;utm_content=vuln-a">
<img src="/b-flashpoint/1.png">
</a></div>
<div class="themonic-logo themonic-ad6"><div class="a-statement">Advertisement</div><a href="https://www.gartner.com/en/conferences/na/symposium-us/sessions?utm_medium=display&amp;utm_campaign=EVT_NA_2026_SYM36_PD_BN1_STAYAHEAD&amp;utm_term=krebs">
<img src="/b-gartner/12.png">
</a></div>
<nav id="site-navigation" class="themonic-nav" role="navigation">
</nav><!-- #site-navigation -->
<div class="clear"></div>
<header id="masthead" class="site-header" role="banner">
<div class="desktop-social">
<div class="socialmedia">
<a href="http://twitter.com/briankrebs" target="_blank"><i class="fa fa-twitter"></i></a>
<a class="rss" href="https://krebsonsecurity.com/feed/" target="_blank"><i class="fa fa-rss"></i></a>
<a class="rss" href="https://www.linkedin.com/in/bkrebs/" target="_blank"><i class="fa fa-linkedin"></i></a>
</div>
</div>
<div class="themonic-logo responsive-img-container">
<a href="https://krebsonsecurity.com/" title="Krebs on Security" rel="home"><img src="https://krebsonsecurity.com/wp-content/uploads/2021/03/kos-27-03-2021.jpg" alt="Krebs on Security"></a>
</div>
<div class="mobile-social">
<div class="socialmedia">
<a href="http://twitter.com/briankrebs" target="_blank"><i class="fa fa-twitter"></i></a>
<a class="rss" href="https://krebsonsecurity.com/feed/" target="_blank"><i class="fa fa-rss"></i></a>
<a class="rss" href="https://www.linkedin.com/in/bkrebs/" target="_blank"><i class="fa fa-linkedin"></i></a>
</div>
</div>
<!-- <div class="publisho-mobile-nav clear"></div> -->
<nav id="site-navigation" class="themonic-nav" role="navigation">
<a class="assistive-text" href="#content" title="Skip to content">Skip to content</a>
<div id="menu-top" class="nav-menu"><ul>
<li ><a href="https://krebsonsecurity.com/">Home</a></li><li class="page_item page-item-2"><a href="https://krebsonsecurity.com/about/">About the Author</a></li>
<li class="page_item page-item-645"><a href="https://krebsonsecurity.com/cpm/">Advertising/Speaking</a></li>
</ul></div>
</nav><!-- #site-navigation -->
<div class="clear"></div>
</header><!-- #masthead -->
<div id="main" class="wrapper">
<header class="entry-header">
<div class="singleentry">
<h1 class="entry-title">DDoS on Dyn Impacts Twitter, Spotify, Reddit</h1>
</div>
</header><!-- .entry-header -->
<div id="primary" class="site-content">
<div id="content" role="main">
<article id="post-36727" class="post-36727 post type-post status-publish format-standard hentry category-other tag-akamai tag-anna_senpai tag-ddos tag-dns tag-doug-madory tag-dyn tag-internet-of-things tag-iot tag-mirai tag-ovh tag-reddit tag-twitter">
<header class="entry-header">
<div class="clear"></div>
<div class="btm-wrap">
<div class="below-title-meta">
<div class="adt">
<span class="date updated">October 21, 2016</span>
</div>
<div class="adt-comment">
<span><a class="link-comments" href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/#comments">175 Comments</a></span>
</div> <div class="clear"></div>
</div><!-- below title meta end -->
</div>
</header><!-- .entry-header -->
<div class="entry-content">
<p>Criminals this morning massively attacked <a href="http://www.dyn.com" target="_blank">Dyn</a>, a company that provides core Internet services for Twitter, SoundCloud, Spotify, Reddit and a host of other sites, causing outages and slowness for many of Dyn&#8217;s customers.</p>
<div id="attachment_36729" style="width: 590px" class="wp-caption aligncenter"><img aria-describedby="caption-attachment-36729" decoding="async" class="size-medium wp-image-36729" src="https://krebsonsecurity.com/wp-content/uploads/2016/10/twitterapi-580x48.png" alt="Twitter is experiencing problems, as seen through the social media platform Hootsuite. " width="580" height="48" srcset="https://krebsonsecurity.com/wp-content/uploads/2016/10/twitterapi-580x48.png 580w, https://krebsonsecurity.com/wp-content/uploads/2016/10/twitterapi-768x63.png 768w, https://krebsonsecurity.com/wp-content/uploads/2016/10/twitterapi-940x78.png 940w" sizes="(max-width: 580px) 100vw, 580px" /><p id="caption-attachment-36729" class="wp-caption-text">Twitter is experiencing problems, as seen through the social media platform Hootsuite.</p></div>
<p>In a statement, Dyn said that this morning, October 21, Dyn received a global <strong>distributed denial of service</strong> (DDoS) attack on its DNS infrastructure on the east coast starting at around 7:10 a.m. ET (11:10 UTC).</p>
<p>&#8220;DNS traffic resolved from east coast name server locations are experiencing a service interruption during this time. Updates will be posted as information becomes available,&#8221; the company wrote.</p>
<p>DYN encouraged customers with concerns to check the company&#8217;s <a href="https://www.dynstatus.com/" target="_blank">status page</a> for updates and to reach out to its technical support team.</p>
<p>A DDoS is when crooks use a large number of hacked or ill-configured systems to flood a target site with so much junk traffic that it can no longer serve legitimate visitors.</p>
<p>DNS refers to <strong>Domain Name System</strong> services. DNS is an essential component of all Web sites, responsible for translating human-friendly Web site names like “example.com” into numeric, machine-readable Internet addresses. Anytime you send an e-mail or browse a Web site, your machine is sending a DNS look-up request to your Internet service provider to help route the traffic.</p>
<h4>ANALYSIS</h4>
<p>The attack on DYN comes just hours after DYN researcher <strong>Doug Madory</strong> presented a talk on DDoS attacks in Dallas, Texas at a meeting of the North American Network Operators Group (NANOG). Madory&#8217;s talk &#8212; available <a href="https://www.youtube.com/watch?v=LFJzu0AFDpU" target="_blank">here on Youtube.com</a> &#8212; delved deeper into research that he and I teamed up on to produce the data behind the story <a href="https://krebsonsecurity.com/2016/09/ddos-mitigation-firm-has-history-of-hijacks/" target="_blank">DDoS Mitigation Firm Has History of Hijacks</a>.<span id="more-36727"></span></p>
<p>That story (as well as one published earlier this week, <a href="https://krebsonsecurity.com/2016/10/spreading-the-ddos-disease-and-selling-the-cure/" target="_blank">Spreading the DDoS Disease and Selling the Cure</a>) examined the sometimes blurry lines between certain DDoS mitigation firms and the cybercriminals apparently involved in launching some of the largest DDoS attacks the Internet has ever seen. Indeed, the <a href="https://krebsonsecurity.com/2016/09/krebsonsecurity-hit-with-record-ddos/" target="_blank">record 620 Gbps DDoS against KrebsOnSecurity.com</a> came just hours after I published the story on which Madory and I collaborated.</p>
<p>The record-sized attack that hit my site last month was quickly superseded by a DDoS against <strong>OVH</strong>, a French hosting firm that reported being targeted by a DDoS that was roughly twice the size of the assault on KrebsOnSecurity. As I noted in <a href="https://krebsonsecurity.com/2016/09/the-democratization-of-censorship/" target="_blank">The Democratization of Censorship</a> &#8212; the first story published after bringing my site back up under the protection of <a href="https://projectshield.withgoogle.com/public/" target="_blank">Google&#8217;s Project Shield</a> &#8212; DDoS mitigation firms simply did not count on the size of these attacks increasing so quickly overnight, and are now scrambling to secure far greater capacity to handle much larger attacks concurrently.</p>
<p>The size of these DDoS attacks has increased so much lately thanks largely to the broad availability of tools for compromising and leveraging the <a href="https://krebsonsecurity.com/2016/10/who-makes-the-iot-things-under-attack/" target="_blank">collective firepower of so-called Internet of Things devices</a> &#8212; poorly secured Internet-based security cameras, digital video recorders (DVRs) and Internet routers. Last month, a hacker by the name of <strong>Anna_Senpai</strong> <a href="https://krebsonsecurity.com/2016/10/source-code-for-iot-botnet-mirai-released/" target="_blank">released the source code for Mirai</a>, a crime machine that enslaves IoT devices for use in large DDoS attacks. The 620 Gbps attack that hit my site last month was launched by a botnet built on Mirai, for example.</p>
<p>Interestingly, someone is now targeting infrastructure providers with extortion attacks and invoking the name Anna_senpai. According to <a href="http://www.webhostingtalk.com/showthread.php?t=1606018" target="_blank">a discussion thread</a> started Wednesday on <strong>Web Hosting Talk</strong>, criminals are now invoking the Mirai author&#8217;s nickname in a bid to extort Bitcoins from targeted hosting providers.</p>
<blockquote><p>&#8220;If you will not pay in time, DDoS attack will start, your web-services will<br />
go down permanently. After that, price to stop will be increased to 5 BTC<br />
with further increment of 5 BTC for every day of attack.</p>
<p>NOTE, i?m not joking.</p>
<p>My attack are extremely powerful now &#8211; now average 700-800Gbps, sometimes over 1 Tbps per second. It will pass any remote protections, no current protection systems can help.&#8221;</p></blockquote>
<p>Let me be clear: I have no data to indicate that the attack on Dyn is related to extortion, to Mirai or to any of the companies or individuals Madory referenced in his talk this week in Dallas. But Dyn is known for publishing detailed writeups on outages at other major Internet service providers. Here&#8217;s hoping the company does not deviate from that practice and soon publishes a postmortem on its own attack.</p>
<p><strong>Update, 3:50 p.m. ET:</strong> Security firm <strong>Flashpoint</strong> is now reporting that they have seen indications that a Mirai-based botnet is indeed involved in the attack on Dyn today. Separately, I have heard from a trusted source who&#8217;s been tracking this activity and saw chatter in the cybercrime underground yesterday discussing a plan to attack Dyn.</p>
<p><strong>Update, 10:22 a.m. ET:</strong> Dyn&#8217;s <a href="https://www.dynstatus.com/" target="_blank">status page</a> reports that all services are back to normal as of 13:20 UTC (9:20 a.m. ET). Fixed the link to Doug Madory&#8217;s talk on Youtube, to remove the URL shortener (which isn&#8217;t working because of this attack).</p>
<p><strong>Update, 1:01 p.m. ET:</strong> Looks like the attacks on Dyn have resumed and this event is ongoing. This, from the Dyn status page:</p>
<blockquote>
<div class="update">This DDoS attack may also be impacting Dyn Managed DNS advanced services with possible delays in monitoring. Our Engineers are continuing to work on mitigating this issue.<br />
<small>Oct 21, 16:48 UTC</small></div>
<div class="update"></div>
<div class="update">As of 15:52 UTC, we have begun monitoring and mitigating a DDoS attack against our Dyn Managed DNS infrastructure. Our Engineers are continuing to work on mitigating this issue.<br />
<small>Oct 21, 16:06 UTC</small></div>
</blockquote>
</div><!-- .entry-content -->
<footer class="entry-meta">
<p><i>
This entry was posted on Friday 21st of October 2016 09:59 AM
</i></p>
<div class="categories"><a href="https://krebsonsecurity.com/category/other/" rel="category tag">Other</a></div>
<div class="tags"><a href="https://krebsonsecurity.com/tag/akamai/" rel="tag">Akamai</a> <a href="https://krebsonsecurity.com/tag/anna_senpai/" rel="tag">Anna_Senpai</a> <a href="https://krebsonsecurity.com/tag/ddos/" rel="tag">DDoS</a> <a href="https://krebsonsecurity.com/tag/dns/" rel="tag">DNS</a> <a href="https://krebsonsecurity.com/tag/doug-madory/" rel="tag">Doug Madory</a> <a href="https://krebsonsecurity.com/tag/dyn/" rel="tag">Dyn</a> <a href="https://krebsonsecurity.com/tag/internet-of-things/" rel="tag">internet of things</a> <a href="https://krebsonsecurity.com/tag/iot/" rel="tag">IoT</a> <a href="https://krebsonsecurity.com/tag/mirai/" rel="tag">mirai</a> <a href="https://krebsonsecurity.com/tag/ovh/" rel="tag">OVH</a> <a href="https://krebsonsecurity.com/tag/reddit/" rel="tag">Reddit</a> <a href="https://krebsonsecurity.com/tag/twitter/" rel="tag">twitter</a></div>
</footer>
</article><!-- #post -->
<br><div class="themonic-ad4"></div>
<nav class="nav-single">
<div class="assistive-text">Post navigation</div>
<span class="nav-previous"><a href="https://krebsonsecurity.com/2016/10/spreading-the-ddos-disease-and-selling-the-cure/" rel="prev"><span class="meta-nav">&larr;</span> Spreading the DDoS Disease and Selling the Cure</a></span>
<span class="nav-next"><a href="https://krebsonsecurity.com/2016/10/hacked-cameras-dvrs-powered-todays-massive-internet-outage/" rel="next">Hacked Cameras, DVRs Powered Today&#8217;s Massive Internet Outage <span class="meta-nav">&rarr;</span></a></span>
</nav><!-- .nav-single -->
<div id="comments" class="comments-area">
<h2 class="comments-title">
175 thoughts on &ldquo;<span>DDoS on Dyn Impacts Twitter, Spotify, Reddit</span>&rdquo; </h2>
<ol class="commentlist">
<li class="comment even thread-even depth-1" id="li-comment-413197">
<article id="comment-413197" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">@law </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413197"><time datetime="2016-10-22T00:26:23-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>1.) I highly appreciate shane&#8217;s helpful posts.(and not the trolling of the knowbetter&#8217;s)<br />
2.) I also appreciate BK&#8217;s research into the underwear of these naughty kids.<br />
3.) I am sitting here waiting for the bust and the publication of the indictment.<br />
4.) I am waiting for news from Israel regarding the 2 kids released on bail.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-2" id="li-comment-413326">
<article id="comment-413326" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://worldaccordingbruce.blogspot.com" class="url" rel="ugc external nofollow">Bruce Hobbs</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413326"><time datetime="2016-10-22T12:56:33-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>&#8220;3.) I am sitting here waiting for the bust and the publication of the indictment.&#8221;</p>
<p>While you&#8217;re waiting, be sure to continue breathing, eating and sleeping. You may be waiting a long time and there may never be an indictment.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-413200">
<article id="comment-413200" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">MyyneGaime </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413200"><time datetime="2016-10-22T00:32:51-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>I am not a network expert. I have been reading Krebs for a long time however. I read frequently about other cybercrimes and the emmense quantity of monetary loss from financial insitutions and read daily about data theft.</p>
<p>If the internet was a physical lock.. it would be declared defective. Nobody would install a lock on their vault with the same record as the internet. </p>
<p>Nice try I say. It was fun.. But the current internet is a complete failure when comes to security. It shouldn&#8217;t be this hard to remain secure, and it shouldn&#8217;t be this hard to access Playstation Network, which is down monthly from ddos attacks. </p>
<p>What the world needs is Internet 2.0. I respect the work so many people have done.. but like any complex piece of software (I am a non-network programmer) you eventually reach a place where you admit, no amount of patching is going to fix your product.. </p>
<p>It&#8217;s time for a complete rewrite.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-2" id="li-comment-413250">
<article id="comment-413250" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">G9 </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413250"><time datetime="2016-10-22T07:57:22-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Agreed. The way forward is to use the architecture of the public switched telephone network (PSTN) in conjunction with broadband transmission, circuit-switched with time-division multiplex (TDM) rather than packet-switched, and with a 12-digit geographically fixed numbering plan plus three-digit country codes, and with four-digit extensions for customer premises devices. Think ISDN with expanded numbering space and high bandwidth.</p>
<p>Yes this will still enable Netflix and online gaming, since those things appear to be more important to &#8220;consumers&#8221; than whether their bank accounts get cleaned out or the power grid gets taken down. The difference being that bank accounts won&#8217;t be getting cleaned out by the millions, and critical infrastructure won&#8217;t be vulnerable to sociopaths.</p>
<p>It will also put an end to spam, domain name squatting, DDoS attacks, phishing, and a host of other evils spawned by the present Ayn Randian dream turned nightmare.</p>
<p>Hobbyist infrastructure and libertarian grudges against government, do not a vital utility make. It&#8217;s time to get serious.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment even depth-3" id="li-comment-413298">
<article id="comment-413298" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">bz8ltr </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413298"><time datetime="2016-10-22T10:57:14-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Are you serious? You want to ditch packet switched networks and go back to the way we had (still have in some cases) data transferred in the past? Using TDM will do nothing for security and will further complicate the way data flows. </p>
<p>We had ISDN and TDM based internet connections as a standard back in the 90&#8217;s, and ya know what? They were still connected to routers that could have been vulnerable. Good luck trying to get AT&amp;T or any ISP to extend their support for TDM based technologies. They are trying to ditch DS1/DS3&#8217;s as quickly as possible. Most ISP&#8217;s don&#8217;t even offer true TDM networks anymore. It is a TDM to fiber handoff that the ISP uses packet based switching on the backend to route.</p>
<p>The security needs to come in common sense management of devices that are plugged in the internet. Coding that doesn&#8217;t suck and wasn&#8217;t produced by companies paying developers pennies on the hour. The standardization and an ease of use for DNSSEC.</p>
<p>Your suggestion of rolling back the clock is just unrealistic sir.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment odd alt depth-2" id="li-comment-413261">
<article id="comment-413261" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">ryan </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413261"><time datetime="2016-10-22T08:37:45-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>lol really, the NSA/america are the reason it insecure in first place and if there was a rewrite they would insist on having backdoors rendering it insecure while theres NSA and other state based security apparatus the net wont be secure.<br />
they will make sure of it by hook or by crook</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even depth-2" id="li-comment-413449">
<article id="comment-413449" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://quickblocks.io" class="url" rel="ugc external nofollow">Thomas Rush</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413449"><time datetime="2016-10-23T08:17:35-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>The new Internet is already being built. It&#8217;s called web3.0 (not 2.0&#8211;you&#8217;re already on web2.0). Search web3.0 and check out the Ethereum blockchain.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-3" id="li-comment-413544">
<article id="comment-413544" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Christoph </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413544"><time datetime="2016-10-24T04:13:41-04:00">October 24, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>You mean an infrastructure that gets hard-forked every few weeks and where &#8220;the code is the contract&#8221; only applies as long as nobody actually uses it to that effect?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment even depth-2" id="li-comment-414568">
<article id="comment-414568" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://commercialventvac.com" class="url" rel="ugc external nofollow">Jeff Silverman</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-414568"><time datetime="2016-11-03T22:24:43-04:00">November 3, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Mynne,</p>
<p>With all due respect, I think what you are advocating ain&#8217;t gonna happen. I look at how much trouble we&#8217;re having migrating the entire planet to IPv6, and I just despair. Furthermore, a lot of those IoT devices have no way to be updated, so if we tried to do as you suggest, those IoT thingys would still be out there, and there would have to be some backwards compatibility functionality, which could still be exploited. Furthermore, look at how much trouble we have getting the ISPs to implement RFC 3704 or BCP 84. It seems the ISPs have no trouble filtering content from their competitors, but they don&#8217;t have the cycles to stop packets from Mars.</p>
<p>However, you&#8217;re not the first person who has suggested re-writing the Internet to make it more secure. So, and I really want to bend over backwards not to sound rude, because that&#8217;s not my intent at all, if you could re-write the internet to make it more secure, how would you do that? Would widespread adoption of IPsec be sufficient for you? Do you have something else in mind?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-even depth-1" id="li-comment-413215">
<article id="comment-413215" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">john </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413215"><time datetime="2016-10-22T02:26:54-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>norse attack map was down as well</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-413255">
<article id="comment-413255" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://www.spoofit.org" class="url" rel="ugc external nofollow">spoofit</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413255"><time datetime="2016-10-22T08:07:24-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>For those of you interested to know more about other actors connected to VDOS, we wil be releasing information about other stressers including booter.xyz, stressit.org in the next days at <a href="http://www.spoofit.org" rel="nofollow ugc">http://www.spoofit.org</a></p>
<p>We just recovered from a 36h non stop denial of service attack but the stories will keep flowing.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-2" id="li-comment-413313">
<article id="comment-413313" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://www.spoofit.org" class="url" rel="ugc external nofollow">spoofit</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413313"><time datetime="2016-10-22T11:46:50-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>In the article &#8220;Ponies in the Mist&#8221;, we undercover one more member of the Ponies Squad connected to VDOS and Applej4ck. Don&#8217;t miss how we found who hosted booter.xyz and now hosts stressit.org!<br />
<a href="http://www.spoofit.org/ponies-in-the-mist-stressit/" rel="nofollow ugc">http://www.spoofit.org/ponies-in-the-mist-stressit/</a></p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment even depth-3" id="li-comment-413550">
<article id="comment-413550" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Oz </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413550"><time datetime="2016-10-24T07:02:05-04:00">October 24, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Spoof IT: The articles seem good, but why is your site not set up with HTTPS? Try Let&#8217;s Encrypt, it&#8217;s free 🙂</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-even depth-1" id="li-comment-413278">
<article id="comment-413278" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Gerry </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413278"><time datetime="2016-10-22T09:19:30-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Consider this: What will happen if a similar or larger attack occurs between November 7th and 9th?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-413283">
<article id="comment-413283" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://@fcharlenewatson" class="url" rel="ugc external nofollow">Charlene</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413283"><time datetime="2016-10-22T09:54:03-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>I was just at the #ISACA #CSXNA 2016 conference and heard your speach. The entire conference was fantastic. What I&#8217;m about to say is probably not new but I&#8217;ll put it on here anyway. I tell my students &#8220;Data is the new currency.&#8221; This is my personal quote. Taking the topics from the #CSXNA 2016 here&#8217;s my take: we have #FIRMWARE in many of these devices that dates back to the late 90s. We have kids that can get Raspberry Pi&#8217;s v.3 with wired and wireless connectivity and they&#8217;re curious, excited, smart, and tech savvy. We have an #ICS, #SCADA, #SMARTGRID technology power system which is IP addressable that is virtually open to the public. We have state sponsored players and crime syndicate players who know these things also. And we have a school, college, and university system of education stuck in the 1980&#8217;s where these students are board stiff and disillusioned. Finally this is the second or third attack if I&#8217;m not mistaken. Now look at the US attack map. See a pattern? It hit the upper east coast, then the Nevada and CA area. Anyone remember last year&#8217;s brutally cold winter on the east coast? Anyone remember where they had to draw extra power from to support keeping the east coast going and people warm? Anyone see a pattern here? Just my thoughts. Jump in anyone at anytime to pose an alternative view point. Universities/Colleges/K-12 HAVE to come down out of their Ivory Towers and get in the trenches with the rest of us so we can work together to start utilizing the innate talent in these next generations so we can protect and defend our nation and those of other nations who are fighting the same battles.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-even depth-1" id="li-comment-413287">
<article id="comment-413287" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">dmacleo </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413287"><time datetime="2016-10-22T10:05:29-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>lot of smaller sites whose dns was handled by them affected too.<br />
I have host file so my sites always resolve for me but for others they were down.<br />
pingdom alerter kept bugging me yesterday</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-413289">
<article id="comment-413289" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">放牛娃 </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413289"><time datetime="2016-10-22T10:11:44-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Do you known Chinese?<br />
先生/女士:<br />
你好!很抱歉听闻你们公司遭到 DDoS攻击。我在中国从事僵尸网络监控的,我们在北京时间&#8221;2016-10-21 23:48:17&#8243;监控到,来自你的国家(美国)境内的C2,对美国进行DDoS攻击,我不知道对公司网络的IP范围,所以特意向先生你确认{&#8220;ID&#8221;: 37, &#8220;Time_Modify&#8221;: &#8220;2016-10-21 23:48:17&#8221;, &#8220;Time_Create&#8221;: &#8220;2016-10-21 23:48:17&#8221;, &#8220;Threat_Name&#8221;: &#8220;Trajon/Linux.Mayday&#8221;, &#8220;C2_IP&#8221;: &#8220;205.164.……&#8221;, &#8220;C2_Port&#8221;:……, &#8220;C2_Domain&#8221;: &#8220;&#8221;, &#8220;Command_Type&#8221;: &#8220;DDoS&#8221;, &#8220;Atk_Detailed&#8221;: {&#8220;Atk_Time&#8221;: &#8220;10s&#8221;, &#8220;Payload_Size&#8221;: 75, &#8220;Reserve&#8221;: &#8220;&#8221;, &#8220;Num_threads&#8221;: 1, &#8220;Atk_Count&#8221;: 1, &#8220;Atk_Type&#8221;: &#8220;tcp flood&#8221;, &#8220;Atk_Info&#8221;: [{&#8220;Atk_Domain&#8221;: &#8220;&#8221;, &#8220;Atk_IP&#8221;: &#8220;104.223.133.43&#8221;, &#8220;Atk_Port&#8221;: 80}]}}<br />
{&#8220;ID&#8221;: 38, &#8220;Time_Modify&#8221;: &#8220;2016-10-21 23:48:17&#8221;, &#8220;Time_Create&#8221;: &#8220;2016-10-21 23:48:17&#8221;, &#8220;Threat_Name&#8221;: &#8220;Trajon/Linux.Mayday&#8221;, &#8220;C2_IP&#8221;: &#8220;104.37……&#8221;, &#8220;C2_Port&#8221;: ……, &#8220;C2_Domain&#8221;: &#8220;&#8221;, &#8220;Command_Type&#8221;: &#8220;DDoS&#8221;, &#8220;Atk_Detailed&#8221;: {&#8220;Atk_Time&#8221;: &#8220;10s&#8221;, &#8220;Payload_Size&#8221;: 75, &#8220;Reserve&#8221;: &#8220;&#8221;, &#8220;Num_threads&#8221;: 4, &#8220;Atk_Count&#8221;: 1, &#8220;Atk_Type&#8221;: &#8220;tcp flood&#8221;, &#8220;Atk_Info&#8221;: [{&#8220;Atk_Domain&#8221;: &#8220;&#8221;, &#8220;Atk_IP&#8221;: &#8220;104.223.133.43&#8221;, &#8220;Atk_Port&#8221;: 80}]}}<br />
或者你也可以提供你们IP给我们,让我们对我们的监控数据进行匹配查询<br />
PS:也是想证明,攻击你们网络的幕后C2并非,来自我们国家<br />
如果回复,请发信至1483122458@qq.com,谢谢!<br />
祝君 顺利平安!</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-2" id="li-comment-413334">
<article id="comment-413334" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Bruce Hobbs </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413334"><time datetime="2016-10-22T14:07:18-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>I can&#8217;t read Chinese, but I have access to something called Google Translate. I&#8217;m not going to post the translation because this appears to be spam.</p>
<p>Brian, I would delete the comment.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment even depth-3" id="li-comment-413410">
<article id="comment-413410" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">CowBoy </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413410"><time datetime="2016-10-23T01:43:31-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Hi Bruce Hobbs!Thanks for your delete the comment,but I want to say it is not spam!It is my botnet of auto monitor data, please respect my achievements,thank you!</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-4" id="li-comment-413523">
<article id="comment-413523" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Bruce Hobbs </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413523"><time datetime="2016-10-23T22:04:41-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>CowBoy, maybe you should translate the Chinese into English then.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413351">
<article id="comment-413351" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Lewis De Payne </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413351"><time datetime="2016-10-22T17:05:42-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>What I find particularly interesting and ironic is that DYN&#8217;s status page (dynstatus.com) has DNS for its domain hosted by HE.NET. As a result, when DYN&#8217;s so-called DNS infrastructure was being DDoS&#8217;d, their status page remained resolvable.</p>
<p>This lead me to reflect on the original silicon-valley days when these &#8220;DNS infrastructure&#8221; companies were first coming into vogue, and I resisted (and resented) their marketing via fear-mongering and scare tactics. In my opinion, the basic anycast DNS services these companies provide are no better than, if not inferior to, the free DNS services HE.NET provides anyone who wishes to sign up for it. In fact, third-party performance stats indicate that he.net&#8217;s free (as in zero cost) DNS offering is among the top three, performance-wise.</p>
<p>Which just confirms my belief that the old adage of &#8220;you get what you pay for&#8221; falls apart when whimsical technology is involved.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-odd thread-alt depth-1" id="li-comment-413387">
<article id="comment-413387" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Insanity Repeated </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413387"><time datetime="2016-10-22T21:20:50-04:00">October 22, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>We can&#8217;t rely on users to secure their equipment. We keep preaching &#8216;security&#8217; but the average Joe has no idea what we are talking about, or don&#8217;t care. Security MUST be baked into everything with a MAC. Everything! Set complex passwords on first power-up. Encryption enabled before connecting to anything automatically. If we expect users to &#8216;get it&#8217; we really are doing the same thing over and over while expecting a different result.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413427">
<article id="comment-413427" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">KT Yang </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413427"><time datetime="2016-10-23T03:26:40-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>What if we configure to reply all unknown prefixes with 127.0.0.1? Will that help in DNS Water Torture Technique?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-odd thread-alt depth-1" id="li-comment-413446">
<article id="comment-413446" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://www.harppddos.com" class="url" rel="ugc external nofollow">Oguz YILMAZ</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413446"><time datetime="2016-10-23T07:46:57-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Brian,<br />
Do you have any exact information on why bgp routes changed heavily during the Dyn DDoS attack? Is it by Dyn self healing or is there any simultaneous hijacking attempt?<br />
<a href="https://stat.ripe.net/widget/bgplay#w.resource=208.78.70.16" rel="nofollow ugc">https://stat.ripe.net/widget/bgplay#w.resource=208.78.70.16</a></p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413494">
<article id="comment-413494" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://onearmedpushup.libsyn.com" class="url" rel="ugc external nofollow">Push Up</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413494"><time datetime="2016-10-23T17:16:57-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Interesting read, we recently discussed online privacy on our latest podcast episode. Let us know what you think. </p>
<p><a href="http://onearmedpushup.libsyn.com" rel="nofollow ugc">http://onearmedpushup.libsyn.com</a></p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-odd thread-alt depth-1" id="li-comment-413498">
<article id="comment-413498" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://realmofvincent.com/" class="url" rel="ugc external nofollow">Realm of Vincent</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413498"><time datetime="2016-10-23T17:51:29-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Yes, there are some things users can do to reduce the chances their IoT devices are used in DDoS attacks, but laying the blame solely on them is like blaming drivers for accidents caused by manufacturing defects in their car&#8217;s brakes. Analysis here: <a href="http://realmofvincent.com/2016/10/23/how-responsible-are-consumers-for-the-insecurity-of-iot/" rel="nofollow ugc">http://realmofvincent.com/2016/10/23/how-responsible-are-consumers-for-the-insecurity-of-iot/</a></p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413518">
<article id="comment-413518" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Hayton </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413518"><time datetime="2016-10-23T21:22:44-04:00">October 23, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>The DDoS attack against Dyn last Friday was by no means the first one Dyn has reported. The logs from <a href="https://www.dynstatus.com/" rel="nofollow ugc">https://www.dynstatus.com/</a> show 94 occasions when a DDoS was attempted; the most recent before Friday was on Monday 17th.</p>
<p>What sets this one apart seems to be the size of the attack and its impact on heavily-used websites and services. If Twitter had not been affected would this have received as much publicity?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-odd thread-alt depth-1" id="li-comment-413579">
<article id="comment-413579" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://antiquant.org" class="url" rel="ugc external nofollow">Rajesh Kanungo</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413579"><time datetime="2016-10-24T11:57:09-04:00">October 24, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Financial dis-incentives for security in IoT devices vs. Set Top boxes and smart meters:<br />
Turns out that there are NO financial incentives for companies to have strong security in IoT devices.<br />
Once a device is shipped, the customer and the manufactures only care if the device works, not if it can be used to attack other nodes. Secure login, secure boot, secure installation, design and code verification, vulnerability testing, etc. all get in the way of quick development/manufacturing and shipment.</p>
<p>These IOT companies simply don&#8217;t care about security: there is no forcing function.</p>
<p>OTOH, setup boxes had to be secure because pirated content would result in lost revenue for Dish and Direct TV (the two companies I did security work for).</p>
<p>Similarly, smart meter security has become a requirement (I ran North America product security for Itron), because electricity/gas/water could be stolen, service interruption could even kill people on life support, etc. i.e. there was a direct correlation between the impact on the customer, manufacture and the service provider.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413581">
<article id="comment-413581" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Jose </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413581"><time datetime="2016-10-24T12:35:31-04:00">October 24, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>How big was the DDoS attack on Dyn from 21st October 2016&#8230; Can&#8217;t seem to find it anywhere&#8230; I am guessing that it&#8217;s much bigger than 662gbps that hit your site&#8230; Can you put a number on it??</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-odd thread-alt depth-1" id="li-comment-413592">
<article id="comment-413592" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Albert Liu </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413592"><time datetime="2016-10-24T14:01:02-04:00">October 24, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>While I understand that <a href="http://dyn.com/blog/dyn-statement-on-10212016-ddos-attack/" rel="nofollow ugc">http://dyn.com/blog/dyn-statement-on-10212016-ddos-attack/</a> on 10/22 by Dyn Chief Strategy Officer Kyle York is just that, a &#8220;statement,&#8221; the claim:</p>
<p> &#8220;service was restored at approximately 1:00 pm ET. [17:00 UTC]&#8230; While there was a third attack attempted, we were able to successfully mitigate it without customer impact&#8221;</p>
<p>seems not to be supported by Dyn&#8217;s own incident timeline at <a href="https://www.dynstatus.com/incidents/nlr4yrr162t8" rel="nofollow ugc">https://www.dynstatus.com/incidents/nlr4yrr162t8</a> appears to show issues until at least 22:00 UTC?</p>
<p>OpenDNS&#8217;s SmartCache makes sense to me (since my first thought after learning this was DNS lookup related was creating a cache table of my own).</p>
<p>However, I wonder how OpenDNS (and others, like OpenNIC) would fare if targeted?</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-even depth-1" id="li-comment-413680">
<article id="comment-413680" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://darrenchaker.us/" class="url" rel="ugc external nofollow">Darren Chaker</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413680"><time datetime="2016-10-25T04:31:20-04:00">October 25, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>I agree with Insanity Repeated, and add that although security should be at the forefront of our thoughts, it is often in the closet. Virtually every person I know has pending Windows updates, has expired trial anti-virus, doesn&#8217;t use a firewall, and has the default PW set on there webcam. It&#8217;s kind of like you do not get a car alarm until you have a stereo stolen, but in the cyber world a lot more than a couple of items can get taken from your computer &#8211; from personal photos, to corporate secrets, to turning on your webcam. No body understands (except us few who live and breath security) until its too late.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
<ol class="children">
<li class="comment odd alt depth-2" id="li-comment-413793">
<article id="comment-413793" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">David Spector </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413793"><time datetime="2016-10-25T18:00:21-04:00">October 25, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Darren, I have black tape over both of my webcams except when in actual use, just in case a malicious user takes control and tries to look at my living room. It is not hard to anticipate almost any &#8220;reasonable&#8221; attack.</p>
<p>But the DoS attack described here takes advantage of an unreasonable feature of the Internet: the insecurity of DNS lookups, which assume that everyone will cooperate and be reasonable. Such cooperation can&#8217;t ever be assumed in 2016 or beyond.</p>
<p>The Internet needs to be redesigned so that malicious use is made more difficult and made better traceable. A few more security bits here and there to enforce these features would not increase cost much, but would make life easier. Imagine being able to publish email addresses in the clear without fear of spamming. That would be easy through assymmetric encryption and/or signing on each email message. A few more bits to point at a public key and security is dramatically better.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .children -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-413690">
<article id="comment-413690" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">Sheds </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413690"><time datetime="2016-10-25T06:51:47-04:00">October 25, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Trying to buy a DVR 16 for a company CCTV system right now is tricky!</p>
<p>Can&#8217;t buy AVTech&#8230;<br />
<a href="http://www.zdnet.com/article/thousands-of-dvrs-could-be-drafted-into-the-next-iot-botnet/" rel="nofollow ugc">http://www.zdnet.com/article/thousands-of-dvrs-could-be-drafted-into-the-next-iot-botnet/</a></p>
<p>&#8230;or Swann&#8230;<br />
<a href="https://krebsonsecurity.com/2016/02/this-is-why-people-fear-the-internet-of-things/" rel="ugc">https://krebsonsecurity.com/2016/02/this-is-why-people-fear-the-internet-of-things/</a></p>
<p>&#8230;KGuard &amp; lots of others related to Swann have had insecurities so ruled out&#8230;<br />
<a href="http://www.theregister.co.uk/2013/01/29/cctv_vuln/" rel="nofollow ugc">http://www.theregister.co.uk/2013/01/29/cctv_vuln/</a></p>
<p>Running out of options here</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-even depth-1" id="li-comment-413791">
<article id="comment-413791" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn">David Spector </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-413791"><time datetime="2016-10-25T17:48:08-04:00">October 25, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>In your blog &#8220;21 DDoS on Dyn Impacts Twitter, Spotify, Reddit&#8221; you state, &#8220;Anytime you send an e-mail or browse a Web site, your machine is sending a DNS look-up request to your Internet service provider to help route the traffic.&#8221;</p>
<p>As you know this is incorrect. DNS data associated with browsing is usually cached at several levels, so the lookup of a popular domain name would most likely be satisfied right in the local computer system&#8217;s implicit DNS server or HOSTS file, and if not, only then in the Internet Service Provider&#8217;s DNS server.</p>
<p>This DoS attack was not caused by browsing, as you explained in detail already.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-414741">
<article id="comment-414741" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://sgalyrkw.com" class="url" rel="ugc external nofollow">Lele</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-414741"><time datetime="2016-11-05T04:16:39-04:00">November 5, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>This is way better than a brick &amp; mortar esanhlisbmett.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment odd alt thread-even depth-1" id="li-comment-416668">
<article id="comment-416668" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://devaprise.com/nationwide-insurance-king-nc.html" class="url" rel="ugc external nofollow">nationwide insurance king nc</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-416668"><time datetime="2016-11-11T09:26:39-05:00">November 11, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>Exactly. I break down the game into every single one of its individual components and analyze them. I&#8217;m not writing a lot about one thing, but rather a little bit (well, I consider 2-4 paragraphs to be &#8220;a little bit,&#8221; anyway). I leave no stone unturned. All my major Halo-themed articles are like this, from this one to my &#8220;Open Letter to Bungie&#8221; from 2006 to my reviews of Halo 3, ODST, and Reach. Each weapon, each enemy, each aspect of the core gameplay and all the extra features and other miscellany gets its turn to be dissected. That&#8217;s how I roll.</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
<li class="comment even thread-odd thread-alt depth-1" id="li-comment-417417">
<article id="comment-417417" class="comment">
<header class="comment-meta comment-author vcard">
<cite class="fn"><a href="http://www.kfzversicherungstarife.top/" class="url" rel="ugc external nofollow">http://www.kfzversicherungstarife.top/</a> </cite><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-3/#comment-417417"><time datetime="2016-11-12T15:16:17-05:00">November 12, 2016</time></a> </header><!-- .comment-meta -->
<section class="comment-content comment">
<p>By February 6, 2013 &#8211; 6:38 amI&#8217;m truly enjoying the design and layout of your site. It&#8217;s a very easy on the eyes which makes it much more enjoyable for me to come here and visit more often. Did you hire out a designer to create your theme? Excellent work!</p>
</section><!-- .comment-content -->
<div class="reply">
</div><!-- .reply -->
</article><!-- #comment-## -->
</li><!-- #comment-## -->
</ol><!-- .commentlist -->
<nav id="comment-nav-below" class="navigation" role="navigation">
<h1 class="assistive-text section-heading">Comment navigation</h1>
<div class="nav-previous"><a href="https://krebsonsecurity.com/2016/10/ddos-on-dyn-impacts-twitter-spotify-reddit/comment-page-2/#comments" >&larr; Older Comments</a></div>
<div class="nav-next"></div>
</nav>
<p class="nocomments">Comments are closed.</p>
</div><!-- #comments .comments-area -->
</div><!-- #content -->
</div><!-- #primary -->
<div id="secondary" class="widget-area" role="complementary">
<div id="sidebar_ad" class="widget themonic-ad5"><div class="a-statement">Advertisement</div><a href="https://www.gartner.com/en/conferences/na/symposium-us/sessions?utm_medium=display&amp;utm_campaign=EVT_NA_2026_SYM36_PD_BN1_STAYAHEAD&amp;utm_term=krebs">
<img src="/b-gartner/13.png">
</a></div>
<br><div class="widget themonic-ad1"><div class="a-statement">Advertisement</div></div><br>
<aside id="custom_html-2" class="widget_text widget widget_custom_html"><p class="widget-title">Mailing List</p><div class="textwidget custom-html-widget"><a href="/subscribe/">Subscribe here</a></div></aside><aside id="search-2" class="widget widget_search"><p class="widget-title">Search KrebsOnSecurity</p><form role="search" method="get" id="searchform" class="searchform" action="https://krebsonsecurity.com/">
<div>
<label class="screen-reader-text" for="s">Search for:</label>
<input type="text" value="" name="s" id="s" />
<input type="submit" id="searchsubmit" value="Search" />
</div>
</form></aside>
<aside id="recent-posts-3" class="widget widget_recent_entries">
<p class="widget-title">Recent Posts</p>
<ul>
<li>
<a href="https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/">Microsoft Plugs Nearly 1,000 Security Holes</a>
</li>
<li>
<a href="https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/">FBI Probes Service Selling 153M+ Drivers Licenses</a>
</li>
<li>
<a href="https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/">Two Alleged &#8216;TeamPCP&#8217; Hackers Arrested in Australia</a>
</li>
<li>
<a href="https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/">Who&#8217;s Tracking You? Use This New Service to Find Out</a>
</li>
<li>
<a href="https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/">Microsoft Plugs Nearly 400 Security Holes</a>
</li>
</ul>
</aside><aside id="text-2" class="widget widget_text"> <div class="textwidget"><a name="subscribe2"></a></div>
</aside><aside id="categories-2" class="widget widget_categories"><p class="widget-title">Story Categories</p>
<ul>
<li class="cat-item cat-item-5"><a href="https://krebsonsecurity.com/category/sunshine/">A Little Sunshine</a>
</li>
<li class="cat-item cat-item-2240"><a href="https://krebsonsecurity.com/category/all-about-skimmers/">All About Skimmers</a>
</li>
<li class="cat-item cat-item-9085"><a href="https://krebsonsecurity.com/category/ashley-madison-breach/">Ashley Madison breach</a>
</li>
<li class="cat-item cat-item-3191"><a href="https://krebsonsecurity.com/category/breadcrumbs/">Breadcrumbs</a>
</li>
<li class="cat-item cat-item-3771"><a href="https://krebsonsecurity.com/category/data-breaches/">Data Breaches</a>
</li>
<li class="cat-item cat-item-4624"><a href="https://krebsonsecurity.com/category/ddos-for-hire/">DDoS-for-Hire</a>
</li>
<li class="cat-item cat-item-11540"><a href="https://krebsonsecurity.com/category/doge/">DOGE</a>
</li>
<li class="cat-item cat-item-9173"><a href="https://krebsonsecurity.com/category/employment-fraud/">Employment Fraud</a>
</li>
<li class="cat-item cat-item-2151"><a href="https://krebsonsecurity.com/category/how-to-break-into-security/">How to Break Into Security</a>
</li>
<li class="cat-item cat-item-10357"><a href="https://krebsonsecurity.com/category/internet-of-things-iot/">Internet of Things (IoT)</a>
</li>
<li class="cat-item cat-item-87"><a href="https://krebsonsecurity.com/category/latest-warnings/">Latest Warnings</a>
</li>
<li class="cat-item cat-item-4071"><a href="https://krebsonsecurity.com/category/neer-do-well-news/">Ne&#039;er-Do-Well News</a>
</li>
<li class="cat-item cat-item-9"><a href="https://krebsonsecurity.com/category/other/">Other</a>
</li>
<li class="cat-item cat-item-1306"><a href="https://krebsonsecurity.com/category/pharma-wars/">Pharma Wars</a>
</li>
<li class="cat-item cat-item-8240"><a href="https://krebsonsecurity.com/category/ransomware/">Ransomware</a>
</li>
<li class="cat-item cat-item-9635"><a href="https://krebsonsecurity.com/category/russias-war-on-ukraine/">Russia&#039;s War on Ukraine</a>
</li>
<li class="cat-item cat-item-599"><a href="https://krebsonsecurity.com/category/security-tools/">Security Tools</a>
</li>
<li class="cat-item cat-item-8298"><a href="https://krebsonsecurity.com/category/sim-swapping/">SIM Swapping</a>
</li>
<li class="cat-item cat-item-4079"><a href="https://krebsonsecurity.com/category/spam-nation/">Spam Nation</a>
</li>
<li class="cat-item cat-item-1"><a href="https://krebsonsecurity.com/category/smallbizvictims/">Target: Small Businesses</a>
</li>
<li class="cat-item cat-item-5167"><a href="https://krebsonsecurity.com/category/tax-refund-fraud/">Tax Refund Fraud</a>
</li>
<li class="cat-item cat-item-3"><a href="https://krebsonsecurity.com/category/comingstorm/">The Coming Storm</a>
</li>
<li class="cat-item cat-item-4"><a href="https://krebsonsecurity.com/category/patches/">Time to Patch</a>
</li>
<li class="cat-item cat-item-21"><a href="https://krebsonsecurity.com/category/web-fraud-2-0/">Web Fraud 2.0</a>
</li>
</ul>
</aside><aside id="media_image-2" class="widget widget_media_image"><p class="widget-title">Why So Many Top Hackers Hail from Russia</p><a href="https://krebsonsecurity.com/2017/06/why-so-many-top-hackers-hail-from-russia/"><img width="580" height="389" src="https://krebsonsecurity.com/wp-content/uploads/2017/06/computered-580x389.png" class="image wp-image-39684 attachment-medium size-medium" alt="" decoding="async" loading="lazy" style="max-width: 100%; height: auto;" srcset="https://krebsonsecurity.com/wp-content/uploads/2017/06/computered-580x389.png 580w, https://krebsonsecurity.com/wp-content/uploads/2017/06/computered-768x514.png 768w, https://krebsonsecurity.com/wp-content/uploads/2017/06/computered-940x630.png 940w, https://krebsonsecurity.com/wp-content/uploads/2017/06/computered.png 1551w" sizes="(max-width: 580px) 100vw, 580px" /></a></aside> </div><!-- #secondary -->
</div><!-- #main .wrapper -->
<div id="publisho-footer" class="widget-area">
<div class="footer-widget">
</div>
<div class="footer-widget">
</div>
<div class="footer-widget">
</div>
</div>
<div class="site-wordpress">
&copy; Krebs on Security - <a rel="me" href="https://infosec.exchange/@briankrebs">Mastodon</a> <br />
</div>
<!-- .site-info --><div class="clear"></div>
</div><!-- #page -->
<script type='text/javascript' src='https://krebsonsecurity.com/wp-content/themes/kos-mar2021/js/slicknav.js?ver=6.2.2' id='publisho-mobile-navigation-js'></script>
</body>
</html>
<!--
Performance optimized by W3 Total Cache. Learn more: https://www.boldgrid.com/w3-total-cache/
Object Caching 153/193 objects using memcached
Page Caching using memcached
Database Caching using memcached
Served from: krebsonsecurity.com @ 2026-09-10 22:49:07 by W3 Total Cache
-->