Live data from Hacker News

Project Shield

jigsaw.google.com

111–116 of 116 posts

Re: Project Shield

#111
post #48

Earlier quoted context omitted.

At the end, if nation states are helpless on preventing this, and only being part of the problem, I say this - our benevolent feodal overlords - is the preferable solution.

That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289

Interestingly, you link into a thread where you yourself agree that it would be harder than it sounds.

Re: Project Shield

#112
post #21

Earlier quoted context omitted.

Completely down from here too. I may need to retract my comments about Akamai. Apparently 680gbps (or whatever it's at now) is the total amount of traffic the busiest site on the internet can be hosed with before the internet itself poops the bed. So, you know, we did learn something from this whole saga.

OVH got hit by a bigger than 1Tbps attack this week

Did they?

I saw them report a cannon with 1.5tbps capacity (based on multiple sources), wasn't clear they were getting hit by that load though (it looked like 991gbps from what I could gather, which still I didn't know of and is mind-blowing!)

Re: Project Shield

#113

Kudos to both Krebs and Google for their courage. I have profound admiration for Brian's work and Google's technology. I didn't know about Project Shield and I think it's an interesting initiative. However, for some reason it leaves me a bit unease (not as much as the idea of being taken down by a 650Gbps DDoS at will!) - not sure what it is, but we might be moving towards an Internet where only the "approved" would…

> I really hope ISP naming and shaming takes over, so we can make DDoS a little bit more difficult. I think naming and shaming would have little impact and whatever impact it did have would be short lived. Consumers tend to have short attention spans and zero long term memory. Take the banking/finance industry for example, were egregious, predatory and at times criminal tactics are par for the course. Banking institu…

The banking industry is heavily regulated, and getting more so. Described criminal tactics as being "par for the course" is not true.

Also, regular consumers have little recourse against large banks for many reasons (e.g many consumers have little direct contact or influence with investment banks), which is who it is up to governments and regulators. ISPs are similar in some ways, but are way more consumer controlled.

Re: Project Shield

#114
post #110

Earlier quoted context omitted.

That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289

Yeah, that's pretty simplistic. There's no evidence at all that somehow removing DDOS protection for the payment part of blackmailers web presence will somehow make them go away. Sure, chase down how they do payment. But ultimately a web front end isn't the thing that makes the payment happen.

> But ultimately a web front end isn't the thing that makes the payment happen.

The "brochure" argument makes 100% sense to me for something like the distributed web, but not for a dynamic web application. Brochures just sit there and look at you. Brochures don't take payments and process callbacks, and send commands to attack.

Re: Project Shield

#115
post #70

Earlier quoted context omitted.

The advertised bandwidth for the whole network is much lower than the 600+GBps that's attacking Kerbs it's a little under 200 GBps. https://metrics.torproject.org/bandwidth.html

Tor has too many friends. I dislike the trend of Tor being used to control botnets, but the upside is that an entire underworld now sees tor as an asset. Any non-state attacking Tor would make some very interesting enemies.

Enemies? Hah, you mean extortion targets!

Re: Project Shield

#116

Earlier quoted context omitted.

So... Tor?

A network like Freenet would be more appropriate for a situation like this. Its peer to peer nature is like bittorrent, so the more popular content is, the more it is replicated, and thus becomes easier to access. It shouldn't be impossible to design a distributed network that has a positive feedback loop that makes a DDOS counterproductive, by actually boosting the targeted materials.

I2P + Tahoe-LAFS, IPFS
Post reply on HN