Earlier quoted context omitted.
Great solution for a world without shared and dynamic ips.
Block the whole subnet and make it the ISP's problem?
The largest DDoS attack to date, peaking above 398M rps
71–80 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#72Earlier quoted context omitted.
Great solution for a world without shared and dynamic ips.
Block the whole subnet and make it the ISP's problem?
Re: The largest DDoS attack to date, peaking above 398M rps
#73Earlier quoted context omitted.
Great solution for a world without shared and dynamic ips.
Block the whole subnet and make it the ISP's problem?
> We might fix this, we might not, you DONT have a choice.
> Thank you for your continued business.
Re: The largest DDoS attack to date, peaking above 398M rps
#74Earlier quoted context omitted.
That's the particularly bad news, this attack does NOT require a really huge botnet. https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor... "Furthermore, one crucial thing to note about the record-breaking attack is that it involved a modestly-sized botnet, consisting of roughly 20,000 machines"
20000 being modest really says a lot about the state of security on the Internet.
Re: The largest DDoS attack to date, peaking above 398M rps
#75Re: The largest DDoS attack to date, peaking above 398M rps
#76Earlier quoted context omitted.
Great solution for a world without shared and dynamic ips.
Block the whole subnet and make it the ISP's problem?
One of the things that gets lost in this kind of debate is that the vast, vast majority of Internet users are not experts in how the Internet, computers, or their phones work. So expecting them to be able to "just not get exploited" is a naive strategy and bringing the pain to the ISP feels counterproductive because what, realistically, can they do to stop all of their unsophisticated users from getting themselves exploited?
At the end of the day, the vast majority of the users of the Internet do not care how it works - they want their email, they want their cat videos, and they want to check up on their high school ex on Facebook. How can we rearchitect the Internet to be a) open b) privacy protecting, and c) robust against these kinds of attacks so that the targets of DDOS attacks have better protection than paying a third party and hoping that that third party can protect them?
Re: The largest DDoS attack to date, peaking above 398M rps
#77The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.
Re: The largest DDoS attack to date, peaking above 398M rps
#78Earlier quoted context omitted.
Block the whole subnet and make it the ISP's problem?
> Sorry citizen, google services are inaccessible because the only ISP in your city sold a service to a bad actor. > We might fix this, we might not, you DONT have a choice. > Thank you for your continued business.
Re: The largest DDoS attack to date, peaking above 398M rps
#79Re: The largest DDoS attack to date, peaking above 398M rps
#80The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
But ISPs do not want to adopt such protocol.