[563] in Privacy_Forum

home help back first fref pref prev next nref lref last post

[ PRIVACY Forum ] Twitter outage was indeed DNS attack

daemon@ATHENA.MIT.EDU (privacy@vortex.com)
Fri Dec 18 13:17:08 2009

Date: Fri, 18 Dec 2009 09:50:05 -0800
To: privacy-list@vortex.com
Message-ID: <20091218175005.GJ13278@vortex.com>
MIME-Version: 1.0
Content-Disposition: inline
From: privacy@vortex.com
Reply-To: PRIVACY Forum Digest mailing list <privacy@vortex.com>
Content-Type: text/plain; charset="iso-8859-1"
Errors-To: privacy-bounces+privacy-forum=mit.edu@vortex.com
Content-Transfer-Encoding: 8bit



Greetings.  Twitter has not officially released details on last
night's hacking-related outage of their Web site, other than to state
that it was (as many of us suspected) a DNS-related attack.

There are some other details floating around unofficially.  Twitter's
DNS services are provided by Dyn Inc.'s Dynect Platform.  Dyn is
insisting that their systems were not compromised and that nobody
accessed Twitter's DNS data without appropriate (login) credentials.

This suggests (but again, this is *not* confirmed) that Twitter's
account on Dyn was somehow itself compromised, possibly through
"social engineering" or other techniques that resulted in the
attackers gaining login access to the Twitter account on Dynect,
allowing them to change the associated DNS data.  (From Dyn's
standpoint, this could still be considered to be "appropriate login
credentials.")

It goes without saying that the "Iranian Cyber Army" hack page is
almost certainly a fraud, and there are no indications that Iran
actually had anything to do with this attack (breathless statements
blaming Iran being made by some media points notwithstanding).  By the
way, I've seen this exact page resulting from various bot-based,
non-DNS attacks in the past.

Presumably more "official" statements about what transpired will be
forthcoming at some point, after the finger-pointing slows down a bit.

Of course this once again demonstrates the fragility of DNS, but
that's hardly a headline news revelation at this stage of the game.

--Lauren--
Lauren Weinstein
lauren@vortex.com
Tel: +1 (818) 225-2800
http://www.pfir.org/lauren
Co-Founder, PFIR
   - People For Internet Responsibility - http://www.pfir.org
Co-Founder, NNSquad
   - Network Neutrality Squad - http://www.nnsquad.org
Founder, GCTIP - Global Coalition 
   for Transparent Internet Performance - http://www.gctip.org
Founder, PRIVACY Forum - http://www.vortex.com
Member, ACM Committee on Computers and Public Policy
Lauren's Blog: http://lauren.vortex.com
Twitter: https://twitter.com/laurenweinstein

_______________________________________________
privacy mailing list
http://lists.vortex.com/mailman/listinfo/privacy


home help back first fref pref prev next nref lref last post