*** UPDATE *** Twitter appears to be accessible again, as is Constant Contact, which handles my subscriber e-mails. The afternoon edition has just been sent.
[ *** End Of Update *** ]
* Washington Post…
Someone attacked a key part of the Internet’s infrastructure Friday morning, causing some major services such as Twitter, Spotify and Airbnb to be inaccessible for some users.
The attack targeted Dyn, a company that helps people connect to websites, with a huge amount of traffic in an attempt to knock the service offline, according to Dyn’s director of internet analysis, Doug Madory. The digital assault appears to have started around 7:30 a.m. ET, and Dyn said it was resolved at roughly 9:20 a.m.
The service Dyn provides is called the Domain Name System. It works sort of like a phone book for the Internet - it translates URLs into the numerical IP addresses for the servers that actually host sites so your browser can connect to them.
This type of attack is commonly known as a distributed denial of service, or DDoS attack. The effects of the attack were intermittent, and many of the details remain scarce, although it appears to have primarily affected users on the East Coast, according to Dyn.
The initial attack came at 7:10 Eastern time, lasted about two hours and then started again around noon. I can still pull up Twitter on my phone, but I can’t get to it to load on my desktop as I write this.
* TechnoBuffalo…
Is it possible this is the latest from the Mirai botnet? Mirai, if you’re unfamiliar, was a botnet that used unsecured devices in the internet of things – printers, coffee machines, IP cameras, open Linux computers and the like – to send an unprecedented 620 Gbps of data at security researcher Brian Krebs’ website. We talked to hackers following that attack and, now that the Mirai code is open sourced, learned that these sorts of threats are only going to continue and increase in size.
“Once they’ve been hijacked, the devices can be switched from sending normal amounts of data to and from your computer, to sending massive amounts of data at a single target,” I explained in my report about DDoS attacks this month. ” Ultimately, the traffic from hundreds or thousands of these devices can exceed the throughput available to a website or a service, denying additional requests access.”
Dyn provided assistance to Krebs, which is why some think the two attacks are connected.
* TechCrunch…
After the attack on Krebs’ website, the code used to build the botnet leaked online, making more massive DDoS attacks all but inevitable. Although it’s not clear yet whether an IoT botnet is behind the attack on Dyn, it certainly would not be surprising.
Oof.
* More from Krebs…
“The size of these DDoS attacks has increased so much lately thanks largely to the broad availability of tools for compromising and leveraging the collective firepower of so-called Internet of Things devices — poorly secured Internet-based security cameras, digital video recorders (DVRs) and Internet routers,” Krebs said today.
What all these connected devices have in common is the existence of security vulnerabilities caused by a flawed software design or gross negligence on the part of their manufacturers that all often use the same factory passwords for all their devices, OVH said in a recent post about the attack on its networks.
“While our internal investigation (which is still ongoing) has identified close to 145,000 infected connected devices as the source of the recent attacks, network service provider Level3 has recently assessed their number at more than a million,” according to OVH. “So we’re only at the beginning of the problem, not to mention the fact that Internet connection rates are constantly growing, notably due to the ever-increasing availability of VDSL, SDSL, and fiber optics.”
Ugh.
* So, why is this relevant to us? Well, I’m hearing and reading about how some tech types are growing worried that this sort of attack could be launched against election authorities on November 8th.
A massive hit like this wouldn’t alter the results, but it could delay the results from being posted online for several hours or even a few days.
Brace yourselves. We’re in a new world.