Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

71–80 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#71
post #66

Earlier quoted context omitted.

> I get most of the attacks from US servers. Often times Google cloud or AWS. Yup. The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. These days most attacks originate from US/Western cloud and other rent-a-box providers. They are a gift to attackers because they can hop around at the click of the button and they know the victims can't block the IP ranges bec…

>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished. Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as…

> After blocking certain countries IP ranges

Alright, can we just put this one to bed ?

When RIPE/APNIC/ARIN allocate a range of IPs, there is NOTHING in the terms and conditions that says "you can only use this in this geography". The legal range holder must be in the geography, but where they announce it is nobody's business.

The range is held by a range holder who are listed on the relevant database. But there is nothing stopping them using it outside their geography and there is nothing stopping them allocating it to a customer outside of their geography.

So when people talk about "blocking a country's IP ranges" they are talking about "blocking a random range of IP addresses that may or may not be used at all in a given country".

There is also no real control on the databases. Yes you are supposed to keep them truthful and up to date, but we've all been there looking for abuse contacts and, well ....

So if a Russian range-holder decides to "allocate" a sub-range to a "French" customer and records it as such on the RIPE database what are you going to do ? And if you're buying your "security" data from a third-party, what's your third-party database telling you ? is that sub-range French or Russian ?

Not forgetting of course that IP range != provider. I could foreseeably get an IP range from $bad_country X but announce it over BGP over $isp_from_friendly_country Y, maybe even using their ASN. So that would easily defeat your ASN blocking.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#72

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

[flagged]

Indoctrination is real, just see below. This is not to say this is not a problem elsewhere, but we are now talking about russian:

https://novayagazeta.eu/articles/2022/09/05/kids-with-guns

Statistics seem to back up the fact that russians (and e.g. some other apac countries) are not the best netizens: https://time.com/3087768/the-worlds-5-cybercrime-hotspots/

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#73
post #66

Earlier quoted context omitted.

> I get most of the attacks from US servers. Often times Google cloud or AWS. Yup. The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. These days most attacks originate from US/Western cloud and other rent-a-box providers. They are a gift to attackers because they can hop around at the click of the button and they know the victims can't block the IP ranges bec…

>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished. Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as…

So you decided to punish average Belarusians (and "a few other countries" -- wtf???) because of actions of another country (whose military they're pretty much occupied by), which were initiated by the decision of one man. Got it.

From your incorrect spelling of the country's name (btw, your use of lowercase to demonstrate your contempt looks pathetic) I infer that you know close to nothing of Belarus and their relations with Russia and other countries.

I think I am beginning to understand what people in many Arab countries have been feeling for the past couple of decades. Your words about rule of law and human rights are cheap and, when it comes to the boogeyman of the day, mean nothing in practice. Have fun driving more people towards Putin and further balkanizing the internet. I know I lost a lot of respect for the West since the beginning of 2022.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#74
post #21

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

Just for a different perspective, here in the EU I get most of the attacks from US servers. Often times Google cloud or AWS. But we can't block the IP space of the US for obvious reasons

Most phishing attacks I've seen are hosted in the US too. I guess that's not only because the US is an absolute mammoth when it comes to Internet infrastructure that no one dares block its IPs, but also it has the cheapest rates for just about anything.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#75
post #53
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

Lots of garbage traffic comes from countries such as Russia, China, India, Brazil, etc and if you don't intend to sell anything to them it makes sense to just block them. If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

> If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

At that point, might as well rethink the engineering happening at your company well before considering blocking countries' IP spaces, no?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#76

Earlier quoted context omitted.

[flagged]

Indoctrination is real, just see below. This is not to say this is not a problem elsewhere, but we are now talking about russian: https://novayagazeta.eu/articles/2022/09/05/kids-with-guns Statistics seem to back up the fact that russians (and e.g. some other apac countries) are not the best netizens: https://time.com/3087768/the-worlds-5-cybercrime-hotspots/

Indoctrination is indeed real, but it isn't limited to "the other side"

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#77

Earlier quoted context omitted.

[flagged]

The reality is the world is filled with bad guys. “Bad” is subjective. From the western point of view, it is crystal clear who our enemies are.

> From the western point of view, it is crystal clear who our enemies are.

Myopic, no? I'm in the western world and see that as gross generalization.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#78

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

> which saves us about $50kper month in bandwidth charges.

How much is this in terabytes?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#79
post #53

Earlier quoted context omitted.

Lots of garbage traffic comes from countries such as Russia, China, India, Brazil, etc and if you don't intend to sell anything to them it makes sense to just block them. If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

> If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries. At that point, might as well rethink the engineering happening at your company well before considering blocking countries' IP spaces, no?

how dare you besmirch react on hn

edit: i'll say it again too, test me.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#80
post #66

Earlier quoted context omitted.

>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished. Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as…

So you decided to punish average Belarusians (and "a few other countries" -- wtf???) because of actions of another country (whose military they're pretty much occupied by), which were initiated by the decision of one man. Got it. From your incorrect spelling of the country's name (btw, your use of lowercase to demonstrate your contempt looks pathetic) I infer that you know close to nothing of Belarus and their relati…

not every american runs the country.
Post reply on HN