logoalt Hacker News

cube00 • today at 2:32 PM • 2 replies • view on HN

> There was no unauthorised access and no compromised systems. This was an overload attack, not an intrusion.

Hopefully your logging infra is rock solid and nothing has been dropped in the flood. It wouldn't be the first time a DOS was used to mask the actual attack by overwhelming the monitoring infra.

> Use a CNAME or ALIAS record instead of an A record. An A record ties your domain to one specific IP address on our platform. That fixed binding was exactly the problem during the attack: wherever we could change the address on short notice, availability could be restored, wherever we could not, only the blunt measure remained.

I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?


Replies

beecasthurlbow • today at 2:43 PM

> I don't understand how this helps. CNAMES have TTLs like A records and they eventually have to terminate at an A record somewhere so why pay for an extra hop?

I assume the customer controls the domain DNS records here rather than the hosting provider.

CNAME record: hosting provider can change underlying IP freely.

A record: hosting provider must get in touch with customer to change DNS.

➕ show 1 reply
nine_ch • today at 2:57 PM

[dead]