Earlier quoted context omitted.
Indoctrination is real, just see below. This is not to say this is not a problem elsewhere, but we are now talking about russian: https://novayagazeta.eu/articles/2022/09/05/kids-with-guns Statistics seem to back up the fact that russians (and e.g. some other apac countries) are not the best netizens: https://time.com/3087768/the-worlds-5-cybercrime-hotspots/
Indoctrination is indeed real, but it isn't limited to "the other side"
Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
81–90 of 151 posts
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#82The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
Internet is decentralized in nature. Even if you tried to undo that, what's stopping anyone from bridging a non-CN/RU Intranet to CN/RU-Intranet.
More importantly: who is to decide that? Should now a US-based organization dictate who EU/JP/Africa can communicate with? Applying such decisions at such a low level will only result in the balkanization of the Internet.
And I totally agree with your approach, cost-reward of CN/RU links don't make sense for 99% of people. But blocking should *still* be optional (opt-in vs opt-out is another debate), becase for some (e.g. hardware, financial firms), the benefits of being able to communicate with China and Russia might outweigh the constant spam/attacks.
On a general note, why do people constantly try to impose their perspective on others? "This is bad for me/most, therefore should be banned for all."
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#83Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#84The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
Just for a different perspective, here in the EU I get most of the attacks from US servers. Often times Google cloud or AWS. But we can't block the IP space of the US for obvious reasons
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#85Cloudflare ddos mitigation is overrated. First they force you to upgrade your plan, if that does not help, anotyer upgrade, if that fails, chances are you will get a termination notice.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#86Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#87Earlier quoted context omitted.
indeed I suspect a single machine could put out 71M HTTP requests/second without too much difficulty (but cloudflare never misses an opportunity for a blog post)
>I suspect a single machine could put out 71M HTTP requests/second without too much difficulty PacketsPerSecond=TransferRate(bytes/second)/PacketSize(bytes/packet) https://community.arubanetworks.com/community-home/digestvie... A single 24port switch with 1Gbps ports would see 48Gbps so with 64byte packets would see 71M packets, 1518byte packets would drop to 3.9M packets. If you are in the business of being the main…
This is not correct. An interface doesn't handle more packets per second with smaller packet sizes it handles less, much less. Getting the full 48 Gbps of 24 ports at line rate would only be possible if the packets were full size packets(1500 bytes). The PPS bottleneck with small packets(64 bytes) would mean you would never see line rate on those 24 interfaces as your throughput would fall off a cliff. Network hardware vendors quote PPS using the lower bound of packet size and line rate at full packet size. The PPS bottleneck on a network device is incurred long before the line rate limit is ever reached.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#88The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…
The US' foreign policy is to disrupt and steal as well, even to allies (the NSA engaged in industrial espionage on the Germany company Siemens). Moreover, DDoS attacks orginating from the US are sometimes greater than Chinese originated attacks -- as recently as a year ago [1] Also don't forget that some of the sketchiest providers on the internet are American, who routinely ignore abuse reports. NameCheap's abuse re…
No mention of Russia, and the original poster probably has nothing to do with the US.
Here's the thing, China and Russia are the wild west of the internet. Someone starts to DDoS a UK IP from the US, and it gets shut down hard and fast.
Someone starts to DDoS from Russia or China, and reports are dropped on the floor. Same for hacking attempts.
And yes, if someone from Russia or China reports to me, errant acitivty, they are listened to.
There is absolutely no comparison. These zones are useless for most companies. No one in China or Russia is buying anything from much of the rest of the world. Russia spews more spam that the rest of the planet combined.
Dropping their IP space on the floor, is the smartest thing a startup can do.
And the manufactured outrage is hilarious. These two countries block everything they can already, meaning legit traffic is rare. The great firewall of China means few will visit your site anyhow.
Drop Russia, China, and even Brazil (whos network ops never ever ever respond to spam reports).
Your admin life will be immensely better, and it will cost you nothing, nada, zilch. All upside, zero downside.
Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack
#89Earlier quoted context omitted.
>> The block $insert_country IP range "solution" is an outdated mentality that should have died off in the 90's. Maybe so. But it works really well. After blocking certain countries IP ranges / ASes, >70% of abuse we had to deal with just vanished. Also there are other reasons to block: since the russians attacked Ukraine, business I work with no longer does business with russia, belarusia and few other countries as…
> After blocking certain countries IP ranges Alright, can we just put this one to bed ? When RIPE/APNIC/ARIN allocate a range of IPs, there is NOTHING in the terms and conditions that says "you can only use this in this geography". The legal range holder must be in the geography, but where they announce it is nobody's business. The range is held by a range holder who are listed on the relevant database. But there is…