Earlier quoted context omitted.
I follow your link https://krebsonsecurity.com/2016/09/the-democratization-of-c... and I get this: 503 Service Temporarily Unavailable shield So it seems to be running shield, but at least part of the attacks are still getting through? :( Would be very nice to know what kind of attacks Shield doesn't shield against etc.
Completely down from here too. I may need to retract my comments about Akamai. Apparently 680gbps (or whatever it's at now) is the total amount of traffic the busiest site on the internet can be hosed with before the internet itself poops the bed. So, you know, we did learn something from this whole saga.
Project Shield
21–30 of 116 posts
Re: Project Shield
#22Re: Project Shield
#23This is going to play into the hands of authoritarian regimes like China and Russia. They will simply block Google.
Re: Project Shield
#24If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. It also makes sense that material one person is spending resource trying to suppress is extremely likely to be interesting to others, so it's not necessarily a bad experience for someone using the Google news.
Obviously, in the short term it's also useful if they can link to a cached copy that is still working. A systemic Streisand effect.
Re: Project Shield
#25Good. Host a mirror of wikileaks and let's talk.
Re: Project Shield
#26This is going to play into the hands of authoritarian regimes like China and Russia. They will simply block Google.
Ideally, we should use some kind of P2P network against censorship, but such networks aren't mature enough.
BUT, if you consider the other way: China's attack on western sites, then this "shield" is valuable.
I remember no long ago China uses GFW to inject malicious code in some analytics javascript. Then all of a sudden millions of internet users started ddosing Github. It was probably because someone put something Chinese gov didn't like on Github. Github for some reason is not banned in China , but China was using this kind of ddos to force Github to take down the pages it didn't like.
Re: Project Shield
#27Rather than seeking a technical solution, I wonder if there is a social one. If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. It also makes sense that material one person is spending resource trying to suppress is extremely likely to be interesting to others, so it's not necessarily a bad experience for someone using the Google news. Obvious…
That would actually be a strong incentive to DDOS yourself!
Re: Project Shield
#28Rather than seeking a technical solution, I wonder if there is a social one. If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. It also makes sense that material one person is spending resource trying to suppress is extremely likely to be interesting to others, so it's not necessarily a bad experience for someone using the Google news. Obvious…
> If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. That would actually be a strong incentive to DDOS yourself!
Re: Project Shield
#29Re: Project Shield
#30Rather than seeking a technical solution, I wonder if there is a social one. If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. It also makes sense that material one person is spending resource trying to suppress is extremely likely to be interesting to others, so it's not necessarily a bad experience for someone using the Google news. Obvious…
> If Google promised to upweight DDOSed articles in their (news) rankings in perpetuity, that's a strong incentive not to DDOS. That would actually be a strong incentive to DDOS yourself!
Perhaps sites uprated for having been DDOSed could be marked as such. We already have to make many decisions about the trustworthiness of news sources, so maybe it's just another factor.
I can also see why Google would just like to make DDOSing very hard and make the whole problem go away, rather than the mechanism I'm proposing.
That said, I think there's something gratifying about using an attacker's willingness and ability to commit resource to removing information as a signal about the value of that information. Judo chop!