Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

101–110 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#101

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

Why do they block Serbia? I work with a Serbian offshore team (Intens) and my understanding of Serbia is they have one foot in Russia and one in the rest of the world, kind of like Belarus (but the leader isn't in the pocket of Putin), but I haven't heard about DDoS or other attacks coming from Serbia.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#102
post #96

Me and millions of users of "obsolete" software and hardware wish CloudFlare slow and painful death. I mean, require solving 65535 useless captchas to die. And "sorry, you are not allowed to die now. Try some other time. Meanwhile why don't you learn how we protect the heavens and hell from freeloaders like you!" after that. And repeat. 71M times.

What "obsolete" software and hardware are you using that's somehow blocked by Cloudflare?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#103
post #53
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

Lots of garbage traffic comes from countries such as Russia, China, India, Brazil, etc and if you don't intend to sell anything to them it makes sense to just block them. If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

It’s all a cost/benefit ratio. Even if the most efficient language is used, given a sufficient number of requests, it might make sense to block them no?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#104

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

> Letting russia and china on the internet was a massive security mistake we should rectify. Internet is decentralized in nature. Even if you tried to undo that, what's stopping anyone from bridging a non-CN/RU Intranet to CN/RU-Intranet. More importantly: who is to decide that? Should now a US-based organization dictate who EU/JP/Africa can communicate with? Applying such decisions at such a low level will only resu…

> Applying such decisions at such a low level will only result in the balkanization of the Internet

Are we not already there with states being able to dictate what is and isn't allowed?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#105
post #90

Earlier quoted context omitted.

One has history, the other was created a couple of hours ago, but nice try!

what are you talking about? do you know where you are right now?

The account dubbed "throwaway" is twice as old as the other account.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#108

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

[deleted]

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#109
post #97
post #69

Earlier quoted context omitted.

I used to work on bizdev with a German group and it took me a long time to catch on: "The character used as the thousands separator In the United States, this character is a comma (,). In Germany, it is a period (.). Thus one thousand and twenty-five is displayed as 1,025 in the United States and 1.025 in Germany. In Sweden, the thousands separator is a space. The character used as the decimal separator In the United…

Switzerland, where I'm from uses 1'023.7, often 1'023,7 in handwriting and at least in my region when spoken you also say comma. So it took my a while to parse as I become more and more exposed to number formats from surrounding countries and the US.

Everything in this message thread sounds like an annoying data processing problem if you ever have to do numbers between countries. Regex rules aren't universal for the comma issues apparently.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#110
post #96

Me and millions of users of "obsolete" software and hardware wish CloudFlare slow and painful death. I mean, require solving 65535 useless captchas to die. And "sorry, you are not allowed to die now. Try some other time. Meanwhile why don't you learn how we protect the heavens and hell from freeloaders like you!" after that. And repeat. 71M times.

What "obsolete" software and hardware are you using that's somehow blocked by Cloudflare?

NetFront on the phone, IceCat mobile (never gets updates) or internal WebView browser on a smartpone, some unknown browser on samsung tv, Firefox 50 on a Linux laptop, but using others often doesn't help. For a while on these I get "screw yourself" message right away, while on others it's 5-30 captcha solving (AI feeding) sessions. And not only me. People with stock android 7 and older browsers have this too. And users of "suspicious" (e.g. non-chrome) browsers too. Oh, and these proxy pages forcing me to use JS (which I clearly don't want), and provide training to some AI (same here).
Post reply on HN