create account

RE: Update Regarding DDoS Attack on Steemit.com by lukestokes

View this thread on: hive.blogpeakd.comecency.com

Viewing a response to: @steemitblog/update-regarding-ddos-attack-on-steemit-com

· @lukestokes ·
How about a <a href="https://busy.org/steemit/@lukestokes/steemit-needs-its-own-mascot-of-failure">fail mascot</a>? Or at least something other than a 5XX default browser error page? Why not put up a static page on a CDN explaining things and change the DNS to point to that?
👍  
properties (23)
authorlukestokes
permlinkre-steemitblog-update-regarding-ddos-attack-on-steemit-com-20171006t202124676z
categorysteemit
json_metadata{"tags":["steemit"],"app":"busy/1.0.0"}
created2017-10-06 20:21:24
last_update2017-10-06 20:21:24
depth1
children3
last_payout2017-10-13 20:21:24
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length275
author_reputation554,601,966,217,919
root_title"Update Regarding DDoS Attack on Steemit.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id16,945,286
net_rshares0
author_curate_reward""
vote details (1)
@bashadow ·
I like that idea. Then after it is fixed or while it is being fixed, a promoted page explaining what happened, and when full recovery is expected. I know your all busy, but I think lukes idea is good.
properties (22)
authorbashadow
permlinkre-lukestokes-re-steemitblog-update-regarding-ddos-attack-on-steemit-com-20171006t204944081z
categorysteemit
json_metadata{"tags":["steemit"],"app":"steemit/0.1"}
created2017-10-06 20:49:36
last_update2017-10-06 20:49:36
depth2
children0
last_payout2017-10-13 20:49:36
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length200
author_reputation100,388,692,638,882
root_title"Update Regarding DDoS Attack on Steemit.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id16,946,420
net_rshares0
@sneak ·
This allows that CDN to replace that page if they are malicious with a login form and steal keys. Do you wish to take that risk?

Also, we use HSTS and they would have to have some valid TLS keys, as well, which would let them MITM traffic even when we aren’t down. 

There is a lot of cost/benefit to these sorts of things. We’re just going to focus on not going down in the future.
properties (22)
authorsneak
permlinkre-lukestokes-re-steemitblog-update-regarding-ddos-attack-on-steemit-com-20171006t211138622z
categorysteemit
json_metadata{"tags":["steemit"],"app":"steemit/0.1"}
created2017-10-06 21:11:39
last_update2017-10-06 21:11:39
depth2
children1
last_payout2017-10-13 21:11:39
cashout_time1969-12-31 23:59:59
total_payout_value0.000 HBD
curator_payout_value0.000 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length383
author_reputation28,694,344,106,492
root_title"Update Regarding DDoS Attack on Steemit.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id16,947,429
net_rshares0
@lukestokes · (edited)
$0.29
> This allows that CDN to replace that page if they are malicious with a login form and steal keys.

That's a bit paranoid, IMO. You're using Amazon Web Services already, right? Do you trust them? CDN and DNS providers do introduce risk, sure, but that's part of being a professional company on the Internet. If you can't trust your service providers, you have the wrong service providers.

I'm somewhat familiar with the risks. Running FoxyCart for the last 10 years, we've processed over a billion dollars in credit card transactions. There will always be risks when dealing with TLS, you have to trust the service providers you use and be quick to change things if needed. Again, this is part of how the Internet works today. I'm not telling you anything new. You have to trust someone.

If the alternative is your business being offline for 10+ hours... well, just don't miss the forest for the trees.

"Not going down in the future" is quite a tough task. Good luck. I really hope you succeed in that, but given the current structure of the Internet, I find that difficult to do without global redundancy through a major CDN provider.
👍  , , ,
properties (23)
authorlukestokes
permlinkre-sneak-re-lukestokes-re-steemitblog-update-regarding-ddos-attack-on-steemit-com-20171006t215938224z
categorysteemit
json_metadata{"tags":["steemit"],"app":"busy/1.0.0"}
created2017-10-06 21:59:36
last_update2017-10-09 15:59:21
depth3
children0
last_payout2017-10-13 21:59:36
cashout_time1969-12-31 23:59:59
total_payout_value0.262 HBD
curator_payout_value0.032 HBD
pending_payout_value0.000 HBD
promoted0.000 HBD
body_length1,139
author_reputation554,601,966,217,919
root_title"Update Regarding DDoS Attack on Steemit.com"
beneficiaries[]
max_accepted_payout1,000,000.000 HBD
percent_hbd10,000
post_id16,950,283
net_rshares119,308,639,060
author_curate_reward""
vote details (4)