Earlier quoted context omitted.
At the end, if nation states are helpless on preventing this, and only being part of the problem, I say this - our benevolent feodal overlords - is the preferable solution.
That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289
Project Shield
111–116 of 116 posts
Re: Project Shield
#112Earlier quoted context omitted.
Completely down from here too. I may need to retract my comments about Akamai. Apparently 680gbps (or whatever it's at now) is the total amount of traffic the busiest site on the internet can be hosed with before the internet itself poops the bed. So, you know, we did learn something from this whole saga.
OVH got hit by a bigger than 1Tbps attack this week
I saw them report a cannon with 1.5tbps capacity (based on multiple sources), wasn't clear they were getting hit by that load though (it looked like 991gbps from what I could gather, which still I didn't know of and is mind-blowing!)
Re: Project Shield
#113Kudos to both Krebs and Google for their courage. I have profound admiration for Brian's work and Google's technology. I didn't know about Project Shield and I think it's an interesting initiative. However, for some reason it leaves me a bit unease (not as much as the idea of being taken down by a 650Gbps DDoS at will!) - not sure what it is, but we might be moving towards an Internet where only the "approved" would…
> I really hope ISP naming and shaming takes over, so we can make DDoS a little bit more difficult. I think naming and shaming would have little impact and whatever impact it did have would be short lived. Consumers tend to have short attention spans and zero long term memory. Take the banking/finance industry for example, were egregious, predatory and at times criminal tactics are par for the course. Banking institu…
Also, regular consumers have little recourse against large banks for many reasons (e.g many consumers have little direct contact or influence with investment banks), which is who it is up to governments and regulators. ISPs are similar in some ways, but are way more consumer controlled.
Re: Project Shield
#114Earlier quoted context omitted.
That's what the "benevolent feudal overlords" want everyone to think. From all the defeatist DDoS comments I'd say they're doing a good job at it. As Brian Krebs, myself and numerous other people have pointed out, Cloudflare could end almost all of the DDoS-for-hire attacks in an hour if they actually wanted to https://news.ycombinator.com/item?id=12577289
Yeah, that's pretty simplistic. There's no evidence at all that somehow removing DDOS protection for the payment part of blackmailers web presence will somehow make them go away. Sure, chase down how they do payment. But ultimately a web front end isn't the thing that makes the payment happen.
The "brochure" argument makes 100% sense to me for something like the distributed web, but not for a dynamic web application. Brochures just sit there and look at you. Brochures don't take payments and process callbacks, and send commands to attack.
Re: Project Shield
#115Earlier quoted context omitted.
The advertised bandwidth for the whole network is much lower than the 600+GBps that's attacking Kerbs it's a little under 200 GBps. https://metrics.torproject.org/bandwidth.html
Tor has too many friends. I dislike the trend of Tor being used to control botnets, but the upside is that an entire underworld now sees tor as an asset. Any non-state attacking Tor would make some very interesting enemies.
Re: Project Shield
#116Earlier quoted context omitted.
So... Tor?
A network like Freenet would be more appropriate for a situation like this. Its peer to peer nature is like bittorrent, so the more popular content is, the more it is replicated, and thus becomes easier to access. It shouldn't be impossible to design a distributed network that has a positive feedback loop that makes a DDOS counterproductive, by actually boosting the targeted materials.