Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

61–70 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#61

Earlier quoted context omitted.

> I get most of the attacks from US servers. Often times Google cloud or AWS. Yup. The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. These days most attacks originate from US/Western cloud and other rent-a-box providers. They are a gift to attackers because they can hop around at the click of the button and they know the victims can't block the IP ranges bec…

I agree that cloud providers are a blessing to attackers, but blocking russian, chinese and even generally SEA ip space is still a very effective way of stopping the bottom 70% of all attacks. Sure, they're trying such outdated methods that there is very little chance of them suceeding, but honestly when just banning china reduces sshd logs by 50% you wonder why you didn't do it sooner.

Are you sure you're blocking 70% of attacks? Or are attackers just starting there, and when they realise their attacks aren't working they go via AWS instead?

I can't imagine many people sufficiently motivated to launch a DDoS attack against you, yet not sufficiently motivated to switch to an attack method that will actually work.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#62

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

Doesn’t deserve the downvotes. All of it is truth. So much garbage connections originate from the mentioned countries. Worst yet, these countries have poor connections in some cases and generate so many retires that also waste resources.

[flagged]

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#63

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

[flagged]

The reality is the world is filled with bad guys. “Bad” is subjective. From the western point of view, it is crystal clear who our enemies are.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#64

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

[dead]

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#65

Earlier quoted context omitted.

[flagged]

The reality is the world is filled with bad guys. “Bad” is subjective. From the western point of view, it is crystal clear who our enemies are.

[flagged]

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#66
post #21

Earlier quoted context omitted.

Just for a different perspective, here in the EU I get most of the attacks from US servers. Often times Google cloud or AWS. But we can't block the IP space of the US for obvious reasons

> I get most of the attacks from US servers. Often times Google cloud or AWS. Yup. The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. These days most attacks originate from US/Western cloud and other rent-a-box providers. They are a gift to attackers because they can hop around at the click of the button and they know the victims can't block the IP ranges bec…

>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's.

Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished.

Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as a matter of principle (and because of sanctions).

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#67

Earlier quoted context omitted.

Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints? I suppose that would put cloudflare and anyone else doing ddos mitigation out of business. When I worked at a small ISP and we would get complaints, we would block the user until we could reach them. Then let them online long enough to update their antivirus. I can't imagine Comcast committing to…

I'd love to see that, but I don't think it'd work because most people aren't capable enough to disinfect their machines and you can't just block their access to the internet. I expect locked down devices like cell phones and tablets to be less problematic in that regard (but maybe that's not true at all), so maybe the home-botnet-issue will resolve itself as more and more people stop using personal computers? I have…

> you can't just block their access to the internet

Or maybe that's the best thing you can do for them, perhaps preventing them from revealing even more passwords etc to the attacker.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#68

Earlier quoted context omitted.

30k isn’t even noteworthy in size for botnets thanks to shitty iot stuff. Mirai attacked Dyn with 100k unique devices.

Comma in odd place. Could be typo of 30,000 or 300,000. Written the same way in the article

Fixed the comma, it's 30,000!

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#69
post #48

Earlier quoted context omitted.

Comma in odd place. Could be typo of 30,000 or 300,000. Written the same way in the article

Fun fact: how many digits get lumped together in a digit grouping is not universal and varies between different languages and cultures globally: https://en.wikipedia.org/wiki/Decimal_separator#Digit_groupi...

I used to work on bizdev with a German group and it took me a long time to catch on:

"The character used as the thousands separator In the United States, this character is a comma (,). In Germany, it is a period (.). Thus one thousand and twenty-five is displayed as 1,025 in the United States and 1.025 in Germany. In Sweden, the thousands separator is a space.

The character used as the decimal separator In the United States, this character is a period (.). In Germany, it is a comma (,). Thus one thousand twenty-five and seven tenths is displayed as 1,025.7 in the United States and 1.025,7 in Germany."

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#70
post #16

Earlier quoted context omitted.

Usually I wouldn't post a Cloudflare mitigates blah blah blah blog, but I thought this one was particularly interesting because of the range of addresses, an attack that large spawning from over 30,000 IPs is a pretty well orchestrated attack. The most I've read pervious was well under half that (granted I've been out of networking for a long time).

30k isn’t even noteworthy in size for botnets thanks to shitty iot stuff. Mirai attacked Dyn with 100k unique devices.

I think 30k 71m request per second http attack is pretty unique? Could certainly be wrong though!
Post reply on HN