ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Bandwidth having issues

    News
    bandwidth outage voip.ms
    7
    34
    2.4k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller @krzykat
      last edited by

      @krzykat said in Bandwidth having issues:

      Why would you stay with a carrier that so badly created an infrastructure that was so easily compromised? I'd think you want to stay with someone that has thought about these measures ahead of time and stays in front of the curve and not be reactionary to it after the fact.

      Have to agree here. Voip.ms got exposed for not taking their infrastructure seriously. Profits above customers.

      syko24S JaredBuschJ 2 Replies Last reply Reply Quote 0
      • syko24S
        syko24 @scottalanmiller
        last edited by

        @scottalanmiller said in Bandwidth having issues:

        @krzykat said in Bandwidth having issues:

        Why would you stay with a carrier that so badly created an infrastructure that was so easily compromised? I'd think you want to stay with someone that has thought about these measures ahead of time and stays in front of the curve and not be reactionary to it after the fact.

        Have to agree here. Voip.ms got exposed for not taking their infrastructure seriously. Profits above customers.

        @scottalanmiller While I agree with you, it's hard to say who is ahead of the curve or has the proper security in place until something actually happens. Everyone can say they have the best mitigations in place, but no one really knows until an attack of this size happens.

        Voip.ms and others should have woken up after the UK companies were hit a couple weeks ago.

        JaredBuschJ 1 Reply Last reply Reply Quote 0
        • JaredBuschJ
          JaredBusch @syko24
          last edited by

          @syko24 said in Bandwidth having issues:

          but no one really knows until an attack of this size happens.

          Actually that is not true, because you plan around the largest DDoS ever recorded and go form there.

          This is just math. My firewall in front of my application can handle 10 gbps per second. Ok, great. The largest DDoS was something like 2 tbps. So yeah, your firewall is not able to handle it.

          Maybe make a plan to swap in AWS or GCP during an attack. Both platforms have firewall options for rent. I bet they can handle 2 tbps also.

          Now you say that AWS and GCP charge lots of money for that service? It will hurt your bottom line? Well they also have API and other tools to quickly spin things up on demand.

          That is the entire point of cloud computing, scalability on demand. No matter what marketing teams want to say about cloud.

          So you design your system to use your tools and have plans in place to implement other tools.

          1 Reply Last reply Reply Quote 2
          • JaredBuschJ
            JaredBusch @scottalanmiller
            last edited by

            @scottalanmiller said in Bandwidth having issues:

            Profits above customers.

            That is speculation. Not saying you are wrong, but it is speculation.

            1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @syko24
              last edited by

              @syko24 said in Bandwidth having issues:

              I am sure that VOIP.MS thought their system was secure prior to these events.

              VoIP.ms built their entire stack on top of Asterisk, and that is the main problem.

              Asterisk is a great PBX. It can handle a lot of shit. But I would never want to build a carrier on it.

              1 Reply Last reply Reply Quote 0
              • JaredBuschJ
                JaredBusch
                last edited by

                And the DDoS has resumed against Bandwidth.

                8d2a47c1-5cb5-484a-8f5a-448dcb1ba2fc-image.png

                DashrenderD 1 Reply Last reply Reply Quote 0
                • DashrenderD
                  Dashrender @JaredBusch
                  last edited by

                  @jaredbusch said in Bandwidth having issues:

                  And the DDoS has resumed against Bandwidth.

                  8d2a47c1-5cb5-484a-8f5a-448dcb1ba2fc-image.png

                  I was wondering if it was going to come back today.

                  JaredBuschJ 1 Reply Last reply Reply Quote 0
                  • JaredBuschJ
                    JaredBusch @Dashrender
                    last edited by JaredBusch

                    @dashrender said in Bandwidth having issues:

                    I was wondering if it was going to come back today.

                    I assume the attackers are smart enough not to waste resources attacking when the U.S. is not using the phone.

                    DashrenderD K 2 Replies Last reply Reply Quote 0
                    • DashrenderD
                      Dashrender @JaredBusch
                      last edited by Dashrender

                      @jaredbusch said in Bandwidth having issues:

                      @dashrender said in Bandwidth having issues:

                      I was wondering if it was going to come back today.

                      I assume the attackers are smart enough not to waste resources attacking when the U.S. is not using the phone.

                      that didn't stop them from running the attack agains VOIP.ms all night... or at least most of it...

                      And short of using the botnet to attack someone else during the US night, it's no skin off the hacker's teeth to keep it going all the time.

                      scottalanmillerS 1 Reply Last reply Reply Quote 0
                      • scottalanmillerS
                        scottalanmiller @Dashrender
                        last edited by

                        @dashrender said in Bandwidth having issues:

                        @jaredbusch said in Bandwidth having issues:

                        @dashrender said in Bandwidth having issues:

                        I was wondering if it was going to come back today.

                        I assume the attackers are smart enough not to waste resources attacking when the U.S. is not using the phone.

                        that didn't stop them from running the attack agains VOIP.ms all night... or at least most of it...

                        And short of using the botnet to attack someone else during the US night, it's no skin off the hacker's teeth to keep it going all the time.

                        Because, I assume, voip.ms was a proof of concept on low hanging, insecure fruit that took minimal effort. An attack on Bandwidth and Verizon is likely thousands of times more intense.

                        DashrenderD 1 Reply Last reply Reply Quote 0
                        • DashrenderD
                          Dashrender @scottalanmiller
                          last edited by

                          @scottalanmiller said in Bandwidth having issues:

                          @dashrender said in Bandwidth having issues:

                          @jaredbusch said in Bandwidth having issues:

                          @dashrender said in Bandwidth having issues:

                          I was wondering if it was going to come back today.

                          I assume the attackers are smart enough not to waste resources attacking when the U.S. is not using the phone.

                          that didn't stop them from running the attack agains VOIP.ms all night... or at least most of it...

                          And short of using the botnet to attack someone else during the US night, it's no skin off the hacker's teeth to keep it going all the time.

                          Because, I assume, voip.ms was a proof of concept on low hanging, insecure fruit that took minimal effort. An attack on Bandwidth and Verizon is likely thousands of times more intense.

                          what other side effects would we expect to see from an attack like that?

                          K scottalanmillerS 2 Replies Last reply Reply Quote 0
                          • SkyetelS
                            Skyetel
                            last edited by Skyetel

                            The rumors we are hearing is that these attacks are state-sponsored sized, and the attackers are torching everything well before it even gets to the target network (Verizon, Bandwidth, etc). This is not an ordinary attack, and everyone's spooked.

                            1 Reply Last reply Reply Quote 2
                            • K
                              krzykat @Dashrender
                              last edited by

                              @dashrender I've had issues with RFC2833 and had to change some systems with IVR front ends to inband signaling.

                              1 Reply Last reply Reply Quote 0
                              • K
                                krzykat @JaredBusch
                                last edited by

                                @jaredbusch I've got my PBX's pretty well locked down by using FQDN, but now all this is making me think ... do I need to add the DDoS feature set on all my Vultr instances? What's everyone else do?

                                scottalanmillerS 1 Reply Last reply Reply Quote 0
                                • scottalanmillerS
                                  scottalanmiller @Dashrender
                                  last edited by

                                  @dashrender said in Bandwidth having issues:

                                  @scottalanmiller said in Bandwidth having issues:

                                  @dashrender said in Bandwidth having issues:

                                  @jaredbusch said in Bandwidth having issues:

                                  @dashrender said in Bandwidth having issues:

                                  I was wondering if it was going to come back today.

                                  I assume the attackers are smart enough not to waste resources attacking when the U.S. is not using the phone.

                                  that didn't stop them from running the attack agains VOIP.ms all night... or at least most of it...

                                  And short of using the botnet to attack someone else during the US night, it's no skin off the hacker's teeth to keep it going all the time.

                                  Because, I assume, voip.ms was a proof of concept on low hanging, insecure fruit that took minimal effort. An attack on Bandwidth and Verizon is likely thousands of times more intense.

                                  what other side effects would we expect to see from an attack like that?

                                  not much, the telephony infrastructure is so small and fragile compared to the Internet.

                                  1 Reply Last reply Reply Quote 0
                                  • scottalanmillerS
                                    scottalanmiller @krzykat
                                    last edited by

                                    @krzykat said in Bandwidth having issues:

                                    @jaredbusch I've got my PBX's pretty well locked down by using FQDN, but now all this is making me think ... do I need to add the DDoS feature set on all my Vultr instances? What's everyone else do?

                                    No, why? WE are not targets. If someone decided to DDOS by a state, you are screwed. Period. Nothing is going to stop that at any of our scales.

                                    dbeatoD 1 Reply Last reply Reply Quote 2
                                    • scottalanmillerS
                                      scottalanmiller
                                      last edited by

                                      Also, no state would ever do that, because it's ridiculous. That's almost equivalent to a foreign government hiring assassins to go to your house and take you out. Unless you are someone insanely important, that is never going to happen. Too expensive, too much risk, no payback.

                                      Even at a state level, attacks are always an economic game.

                                      K 1 Reply Last reply Reply Quote 0
                                      • K
                                        krzykat @scottalanmiller
                                        last edited by

                                        @scottalanmiller I was thinking more of do they try to take down Vultr

                                        scottalanmillerS 1 Reply Last reply Reply Quote 0
                                        • dbeatoD
                                          dbeato @scottalanmiller
                                          last edited by

                                          @scottalanmiller Isn't that still something close to that that VoiP.MS experienced? and granted they didn't have CLoudflare setup on their main site ahead of this.

                                          scottalanmillerS 2 Replies Last reply Reply Quote 0
                                          • scottalanmillerS
                                            scottalanmiller @krzykat
                                            last edited by

                                            @krzykat said in Bandwidth having issues:

                                            @scottalanmiller I was thinking more of do they try to take down Vultr

                                            Then just move to another provider. Just have backups.

                                            Hard to imagine Vultr being a target, but plausible.

                                            1 Reply Last reply Reply Quote 1
                                            • 1
                                            • 2
                                            • 2 / 2
                                            • First post
                                              Last post