Large DDoS attacks cause outages at Twitter, Spotify, and other sites

Comment

Several waves of major cyberattacks against an internet directory service knocked dozens of popular websites offline today, with outages continuing into the afternoon.

Twitter, SoundCloud, Spotify, Shopify, and other websites have been inaccessible to many users throughout the day. The outages are the result of several distributed denial of service (DDoS) attacks on the DNS provider Dyn, the company confirmed. The outages were first reported on Hacker News.

“We are actively in the third flank of this attack,” Dyn’s chief strategy officer Kyle York told reporters around 4:30 p.m. ET today. “It’s a very smart attack. As we mitigate, they react.”

Dyn’s general counsel Dave Allen added that, with the help of other infrastructure companies Akamai and Flashpoint, Dyn has determined that some of the traffic used in the attacks comes from the Mirai botnet, a network of infected Internet of Things devices used in other recent large-scale DDoS attacks.

Dyn and other DNS providers operate as a link between the URLs you type into your browser and the corresponding IP addresses. DDoS attacks are frequently used to censor specific websites by overwhelming them with junk traffic and knocking them offline. However, by attacking Dyn, it’s possible to overwhelm that directory function and cause outages and loading problems across a large swath of the internet.

Other sites experiencing issues include Box, Boston Globe, New York Times, Github, Airbnb, Reddit, Freshbooks, Heroku and Vox Media properties. Users in Europe and Asia may experience fewer problems than those in the U.S. — according to DownDectector’s outage map, the DDoS attacks against Dyn are primarily impacting U.S. users.

screen-shot-2016-10-21-at-10-07-47-am

The DDoS attacks on Dyn began this morning. Service was temporarily restored around 9:30 a.m. ET, but a second attack began around noon, knocking sites offline once again.The DNS provider said engineers were working on “mitigating” the issue, but a third wave began around 4:30 p.m. ET before being resolved roughly two hours later.

“The complexity of the attacks is making it complicated for us. It’s so distributed, coming from tens of millions of source IP addresses around the world. What they’re doing is moving around the world with each attack,” Dyn’s York explained.York said that the DDoS attack initially targeted the company’s data centers on the East Coast, then moved to international data centers. The attack contained “specific nuance to parts of our infrastructure,” he added.

The White House press secretary told members of the press this morning that the Department of Homeland Security is looking into the attacks. Dyn employees said the company is working with law enforcement to investigate the attacks and has received support from customers, competitors, and the State Department.

Dyn said it has not yet attributed the attack to any group or country, and that the DDoS traffic has been coming from tens of millions of discrete IP addresses around the globe. Although DDoS attacks are sometimes accompanied by extortion letters that ask a company to hand over bitcoin in exchange for ceasing an attack, Dyn said it has not received any messages from its attackers. “We are working incredibly diligently on that with the law enforcement community and infrastructure community,” York said of the attribution process. “No one wants to be next.”

The DDoS attack on Dyn follows on the heels of one of the largest DDoS attack in history, which used the Mirai botnet to target the website of independent cybersecurity journalist Brian Krebs. Although DDoS attacks have historically used large networks of compromised computers called botnets to send junk traffic to sites, overwhelming them and making them inaccessible to legitimate users, the Krebs attack expanded in scale by using compromised Internet of Things devices like security cameras to build a botnet. IoT devices are cheaply manufactured and notoriously insecure, making them easy to compromise.

After the attack on Krebs’ website, the code used to build the botnet leaked online, making more massive DDoS attacks all but inevitable.

“There are 3.4 billion internet users globally and 10 to 15 billion IoT devices. It’s a complex world. All we can do is lock arms together and see how we can rectify this,” York said.

Security researcher Bruce Schneier reported in September that several internet infrastructure companies had been targeted with DDoS attacks, although they had not caused the kind of widespread outages experienced today. Shneier wrote that the attacks seemed designed to test companies’ defensive capabilities:

“These attacks are significantly larger than the ones they’re used to seeing. They last longer. They’re more sophisticated. And they look like probing. One week, the attack would start at a particular level of attack and slowly ramp up before stopping. The next week, it would start at that higher point and continue. And so on, along those lines, as if the attacker were looking for the exact point of failure.”

“Someone is extensively testing the core defensive capabilities of the companies that provide critical Internet services,” Schneier added.

If you’re experiencing connection problems, you can try changing your DNS settings (instructions for how to do this on Mac and Windows are here). Anecdotally, our staff has used OpenDNS (208.67.222.222 and 208.67.220.220) and OpenNIC servers and seen connectivity improve.

Developing…

More TechCrunch

Flow, Adam Neumann’s co-living startup, opened a compound with 238 apartments in Saudi Arabia’s capital, Riyadh, and Forbes has some details. The opening included an Aztec-themed hot chocolate ceremony and…

Adam Neumann’s startup Flow opens co-living community in Saudi Arabia

X went back online in Brazil earlier this week, three weeks after Elon Musk’s platform was blocked under orders from Brazil’s Supreme Court. That prompted Brazil’s top court to fine…

Musk dodged Brazil’s X ban by ‘coincidence,’ says Cloudflare CEO

Cards Against Humanity (CAH) is suing Elon Musk’s space exploration company, SpaceX, for $15 million after it allegedly dumped construction equipment all over the game company’s private land in Texas. …

Cards Against Humanity sues Elon Musk’s SpaceX  for trespassing

Black Forest Labs, an image GenAI startup that only came out of stealth two months ago, has closed a a monster new round, sources say.

Grok’s image generator, Black Forest Labs, is raising $100M at a $1B valuation, say sources

We’ve poked through the many product announcements made by the biggest tech companies and product trade shows of the year, so far, and compiled them into this list.

Here are the hottest product announcements from Apple, Google, Microsoft and others so far in 2024

Apple published step-by-step instructions for swapping out the new handset’s battery.

Apple breaks down iPhone 16 repair process

This tranche of funding went to startups across 14 states, but there were certain winners that will see the bulk of the expected 18,000 jobs to be created as a…

The 25 battery tech startups that just got a piece of $3B in federal funds  

The iPhone 16 officially goes on sale Friday. But for its earliest adopters, it arrives with a fundamental compromise baked into the deal. Put simply, this is not the iPhone…

The iPhone 16 launches today without its most hyped feature: Apple Intelligence

Sandvine sold its internet surveillance products to authoritarian regimes, including Belarus, Egypt, Eritrea, the United Arab Emirates, and Uzbekistan.

Internet surveillance firm Sandvine says it’s leaving 56 ‘non-democratic’ countries

Featured Article

Plaud’s $169 ChatGPT-powered NotePin has a permanent place in my travel bag

The $169 Plaud NotePin is a tiny magnetic recording device. Recordings are transcribed and AI provide summaries of meetings.

Plaud’s $169 ChatGPT-powered NotePin has a permanent place in my travel bag

This week brought reassuring signs that dealmaking is still happening on both sides of the table. New unicorns are being minted, and more capital is flowing into AI.

M&As and AI are in the spotlight, but there’s still capital left for quick commerce and more

Keep the energy of TechCrunch Disrupt 2024 alive and leverage your brand by hosting an after-hours Side Event.  Act fast — today is your last chance to apply! Showcase your…

Last day to apply: Boost your brand at TechCrunch Disrupt 2024

If you’re not using the beta version of Apple Intelligence, here’s when you can expect to get the new features.

Apple Intelligence: Its biggest features and when you can expect them

Featured Article

A comprehensive list of 2024 tech layoffs

A complete list of all the known layoffs in tech, from Big Tech to startups, broken down by month throughout 2024.

A comprehensive list of 2024 tech layoffs

YouTube is now testing a new feature that will let creators edit their videos to remove age restrictions and restore videos that had been impacted due to certain Community Guidelines…

YouTube tests a new way for creators to avoid takedowns

According to Tumblr, in the days since the X ban in Brazil, the site saw 222.99% growth in communities and 349.55% growth in users.

After X’s ban in Brazil, Tumblr reports ~350% user growth

The U.K.’s data protection watchdog has confirmed that Microsoft-owned LinkedIn has stopped processing user data for AI model training for now. Stephen Almond, executive director of regulatory risk for the…

LinkedIn has stopped grabbing UK users’ data for AI

As the startup landscape evolves, so do hiring strategies. With Big Tech downsizing and the labor market tightening, founders must navigate a conservative job market to attract and retain top…

SignalFire, CapitalG, and Comprehensive.io coming to TechCrunch Disrupt 2024

We’ve rebooted regular ticket prices for TechCrunch Disrupt 2024, giving you one last chance to save big before the event. Enjoy up to $600 off individual tickets until September 27.…

Ticket Reboot Week: TechCrunch Disrupt 2024’s last sale has begun

Sitting in Athens during the first COVID-19 lockdown, entrepreneur Rania Lamprou watched online e-commerce exploding because of social distancing. But merchants still struggled with low conversion rates because their checkout…

She sat down during the COVID lockdown and started coding — now she’s taking on Bolt

The data centers that train the large language models behind AI consume unimaginable amounts of energy, and the stakes are high for big tech companies to ensure they have enough…

Microsoft taps Three Mile Island nuclear plant to power AI

Belfius is leading Alan’s Series F funding round of €173 million (around $193 million at current exchange rates).

Health insurance startup Alan reaches $4.5B valuation with new $193M funding round

An Indian edtech startup has secured $210 million in fresh financing amid a tough funding environment for edtech companies in the country.

India’s Physics Wallah raises $210M at $2.8B valuation even as edtech funding remains scarce

Attendees of the giant, annual Dreamforce conference in San Francisco love being the butt of the joke. Last year, Seth Meyers entertained them during a 40-minute set that poked fun…

John Mulaney skewers San Francisco tech crowd at Dreamforce

Indian filmmaker Ram Gopal Varma is ditching human musicians for artificial intelligence, saying he’ll use only AI-generated tunes in future projects, a move that underscores AI’s growing reach in creative…

Indian filmmaker Ram Gopal Varma abandons human musicians for AI-generated music

California Governor Gavin Newsom is currently considering 38 AI-related bills, including the highly contentious SB 1047, which the state’s legislature sent to his desk for final approval. These bills try…

Here is what’s illegal under California’s 8 (and counting) new AI laws

A New York Times article Thursday highlighted a lucrative side hustle that is emblematic of the times we live in: gaming algorithms to earn money. In this case, folks figured…

Gaming Lyft’s Citi Bike algos was a lucrative side hustle for a while

This is the chipmaker’s second round of layoffs over the past year, while the company recorded billions in revenue.

Chipmaker Qualcomm lays off hundreds of workers in San Diego

SpaceX sent a letter to top congressional leaders on Wednesday denying allegations that it violated its launch licenses on two separate occasions last year, which has resulted in regulators seeking…

SpaceX disputes $633K FAA fine, citing ‘systematic challenges’ with agency

California’s newest law could land social media users who post, or repost, AI deepfakes that deceive voters about upcoming elections in legal trouble. Governor Gavin Newsom suggests that AB 2839,…

Elon Musk’s reposts of Kamala Harris deepfakes may not fly under new California law