Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

81–90 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#82
post #65
post #64

Earlier quoted context omitted.

Great solution for a world without shared and dynamic ips.

Block the whole subnet and make it the ISP's problem?

It's interesting to me that most of the push-back so far has been for the business model of the internet, ie people need link traversal and content publishing in order to make money from advertising (implied, but not stated). Therefore we need to add yet another layer to the mix, the cloud providers, and start paying those guys.

And yes, we can block entire subnets. You own the IP addresses, you're responsible for stuff coming out of them, at least to the degree that it's not maliscious to the web as a whole. (but not the content itself, of course)

I'm calling bullshit on these assumptions. The internet is a communications tool. If it's not communicating, it's broken. If you provide dynamic IPs to clients that attack people, you're breaking it. It's not my problem or something I should ever be expected to pay for.

To be clear, my point is that we're suggesting yet another layer of commercial, paid crap on top of a broken system in order to fix it. It'd be phenomenally better just to publicly identify place and methods where it's broken and let other folks with more vested interests than information consumers worry about it. Hell, I'm not interested in paying for the current busload of bytes I'm currently consuming for every one sentence of value I receive.

Re: The largest DDoS attack to date, peaking above 398M rps

#83
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

It's worth noting that features like the one that enabled Rapid Reset are pushed into standards by the exact same companies, because they are needed for performance at their scale.

So in a way this was partially caused by the existence of insanely big tech companies that need such features.

Re: The largest DDoS attack to date, peaking above 398M rps

#84

At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?

I've heard stories about attacks where the target is a subsystem but in order to avoid drawing attention to it they attack the entire network.

Re: The largest DDoS attack to date, peaking above 398M rps

#85
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Just like the law enforcement forced the criminals to up their games, so the only option we have is to pay tax?

Well, I wrote this comment to ridicule yours... but actually that was what happened.

Re: The largest DDoS attack to date, peaking above 398M rps

#86
post #73
post #65

Earlier quoted context omitted.

Block the whole subnet and make it the ISP's problem?

> Sorry citizen, google services are inaccessible because the only ISP in your city sold a service to a bad actor. > We might fix this, we might not, you DONT have a choice. > Thank you for your continued business.

Hacker News nerds will argue all day long that the Internet is a utility when the argument happens to personally benefit them, then in the same breath say that a random network admin is justified in blocking a whole ISP subnet due to one “bad” actor. And of course by bad actor I mean person that almost certainly accidentally got themselves infected with malware by not understanding the completely Byzantine world of computers and the Internet.

Re: The largest DDoS attack to date, peaking above 398M rps

#88
post #23

Earlier quoted context omitted.

That's the particularly bad news, this attack does NOT require a really huge botnet. https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor... "Furthermore, one crucial thing to note about the record-breaking attack is that it involved a modestly-sized botnet, consisting of roughly 20,000 machines"

20000 being modest really says a lot about the state of security on the Internet.

Distribute just one warez game with your malware embedded and you'll have well over 20,000 hosts under your control.

Re: The largest DDoS attack to date, peaking above 398M rps

#89
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

[flagged]

Re: The largest DDoS attack to date, peaking above 398M rps

#90
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size.

There is no need for any central authority and no need to maintain any lists.

Post reply on HN