Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

111–120 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#111
post #47

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

The US' foreign policy is to disrupt and steal as well, even to allies (the NSA engaged in industrial espionage on the Germany company Siemens). Moreover, DDoS attacks orginating from the US are sometimes greater than Chinese originated attacks -- as recently as a year ago [1] Also don't forget that some of the sketchiest providers on the internet are American, who routinely ignore abuse reports. NameCheap's abuse re…

I don't think we are talking about national security spying, I am sure every country does this as much as they can.

This sounds more like stopping people who want to extort or even just mess with American companies or individuals. It doesn't really logic to me that US citizens are attempting to ransom Chinese businesses at a higher rate than the inverse.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#112
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

> The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? Well, not directly,but this is the first time I was morally willing to work in parallel to the defense industry. My previous startups were fintech. The customer I had who was attacked by China was Slideshare. Ultimately they bent over for China, and blocked…

I've seen similar stuff in Publishing (news) and another big (popular) company at that time. Yes, Ru/Cn are not the only one, but if you work in security this is just one problem less to solve if you have those banned.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#113
post #105
post #90

Earlier quoted context omitted.

what are you talking about? do you know where you are right now?

The account dubbed "throwaway" is twice as old as the other account.

the exchange rate on throwaway years to IRL years is 10:1, your calculations fail to account for this.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#114
post #21

Earlier quoted context omitted.

Just for a different perspective, here in the EU I get most of the attacks from US servers. Often times Google cloud or AWS. But we can't block the IP space of the US for obvious reasons

Did you report it to Google/AWS? I feel like they would be proactive about removing malicious users, but whether expectations match reality is another question.

I did to Azure and Cloudflare. 0 responses. No one cares.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#116

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

> The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space

Sorry for the language, but fuck that attitude. I don't live in any of these countries, but I used to live in a large European one that still regularly gets blocked by US sites for no fathomable reason.

Maybe you should try using the internet from a VPN location outside the US to see how fun that is as a paying customer of the sites that are blocking you for your crime by association (if temporary physical presence can even be called that).

One time I couldn't even unsubscribe from a VOD streaming service that I had been subscribed to while on an assignment in the US once I was back in Europe because their entire website was just a big geoblocked mess, including account/subscription management. Of course they were still happy to take my money! Less egregious but still infuriating: OMNY, New York's open-loop transit payment system, just outright blocks me when trying to access my account from Europe. Have the people ever considered the scenario that a visitor might use their service and later need the receipts for e.g. an expense report? Sure enough, London's TfL does the same thing for the US.

I can't wait for the day that the decision makers responsible for this insanity get stuck on a business or holiday trip like that and realize how annoying this is – or even better, realize that things like VPNs and botnets exist and can obscure the source of any Internet traffic...

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#117
post #53
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

Lots of garbage traffic comes from countries such as Russia, China, India, Brazil, etc and if you don't intend to sell anything to them it makes sense to just block them. If you wrote your website in some shitty language and you need lots of server power just to serve the home page you will end up saving a lot of money from blocking those countries.

If you don't care about your paying customers ever traveling there and still wanting to use your service (or at least be able to unsubscribe from it without doing a chargeback), sure.

As a customer, I try to avoid any company that considers "blocking the bad countries" a reasonable security posture. If nothing else, it's usually indicative of other irrational and frustrating decisions that might hurt me later.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#118
post #27

Earlier quoted context omitted.

In my experience running large sites most attack traffic has come from EU and US hosts such as Choopa/Vultr, OVH, Hetzner, AWS etc followed closely by major domestic ISPs like Comcast. Any traffic at all from BRICs has been pretty low. The post doesn't even mention any of the countries you whine about.

why do you disregard South Africa like that?

SA wasn’t in the original BRIC acronym. Ie the s stood for plural not South Africa

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#119

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

I develop and maintain 2 Internet faced products at the moment. One serves my own company the other serves my enterprise client. Neither has ever experienced DDOS (my own is about 10 years old). We do have our share of various bots pocking for vulnerabilities and sending us various spam. I'd say that US constitutes very healthy if not predominant portion of those.

>"Letting russia and china on the internet was a massive security mistake we should rectify. The world spends literally BILLIONS because chinarussia are frankly assholes online."

chinarussia are not run by best people for sure. Cutting them or any other country for that matter off the Internet I think is really stupid decision. As for the costs - I think the West in general and the US in particular were able for many decades reap an enormous rewards by having China people do the work for peanuts.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#120
post #110

Earlier quoted context omitted.

What "obsolete" software and hardware are you using that's somehow blocked by Cloudflare?

NetFront on the phone, IceCat mobile (never gets updates) or internal WebView browser on a smartpone, some unknown browser on samsung tv, Firefox 50 on a Linux laptop, but using others often doesn't help. For a while on these I get "screw yourself" message right away, while on others it's 5-30 captcha solving (AI feeding) sessions. And not only me. People with stock android 7 and older browsers have this too. And use…

Unfortunately the internet moves fast, and if you're using a smart TV (prime for DDOS) or (in internet years) old tech it's the same as trying to drive a model t on the highway - sure it's a perfectly serviceable vehicle but you're probably going to get pulled over more often because you're a danger to yourself and others.
Post reply on HN