Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

71–80 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#71
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

Because when a single machine is infected, at one ISP, it's a good idea to block the whole subnet? I don't think any commercial activity could afford such security strategy, blindly blocking legit users by thousands.

Re: The largest DDoS attack to date, peaking above 398M rps

#72
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

How does the ISP solve it? Send a mass mail/email telling people to reset their devices because someone has a device with botnet malware?

Re: The largest DDoS attack to date, peaking above 398M rps

#73
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

> Sorry citizen, google services are inaccessible because the only ISP in your city sold a service to a bad actor.

> We might fix this, we might not, you DONT have a choice.

> Thank you for your continued business.

Re: The largest DDoS attack to date, peaking above 398M rps

#74
post #23

Earlier quoted context omitted.

That's the particularly bad news, this attack does NOT require a really huge botnet. https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor... "Furthermore, one crucial thing to note about the record-breaking attack is that it involved a modestly-sized botnet, consisting of roughly 20,000 machines"

20000 being modest really says a lot about the state of security on the Internet.

Well, 20000 to hit 201 million requests per second and give Cloudflare problems. You wouldn't need that to make problems for many sites.

Re: The largest DDoS attack to date, peaking above 398M rps

#75
Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.

Re: The largest DDoS attack to date, peaking above 398M rps

#76
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

So it’s the ISPs fault that my grandma never met a spam email that she didn’t want to click?

One of the things that gets lost in this kind of debate is that the vast, vast majority of Internet users are not experts in how the Internet, computers, or their phones work. So expecting them to be able to "just not get exploited" is a naive strategy and bringing the pain to the ISP feels counterproductive because what, realistically, can they do to stop all of their unsophisticated users from getting themselves exploited?

At the end of the day, the vast majority of the users of the Internet do not care how it works - they want their email, they want their cat videos, and they want to check up on their high school ex on Facebook. How can we rearchitect the Internet to be a) open b) privacy protecting, and c) robust against these kinds of attacks so that the targets of DDOS attacks have better protection than paying a third party and hoping that that third party can protect them?

Re: The largest DDoS attack to date, peaking above 398M rps

#77
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

"Moreover, the lifespan of a given IP in a botnet is usually short so any long term mitigation is likely to do more harm than good." "As we can see, many new IPs spotted on a given day disappear very quickly afterwards." https://blog.cloudflare.com/technical-breakdown-http2-rapid-...

Re: The largest DDoS attack to date, peaking above 398M rps

#78
post #73
post #65

Earlier quoted context omitted.

Block the whole subnet and make it the ISP's problem?

> Sorry citizen, google services are inaccessible because the only ISP in your city sold a service to a bad actor. > We might fix this, we might not, you DONT have a choice. > Thank you for your continued business.

Indistinguishable from the kind of service I get from Google - the moment that I need a human involved I just close my account with whatever Google service is misbehaving and move on.

Re: The largest DDoS attack to date, peaking above 398M rps

#79
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

You are quite obviously speaking from the perspective as someone that wouldn’t be in a position to be making these calls.

Re: The largest DDoS attack to date, peaking above 398M rps

#80
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16.

But ISPs do not want to adopt such protocol.

Post reply on HN