Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

141–150 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#141

Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.

That costs a lot of money to implement. They are in business of selling pipes, not pipe filters

Re: The largest DDoS attack to date, peaking above 398M rps

#142

Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.

ISPs could enshitty-sell it though.

Altruism is not profitable.

Re: The largest DDoS attack to date, peaking above 398M rps

#144

Earlier quoted context omitted.

Simple! To prevent it being abused easily you could make it so you would need to send a high number of those packets for a sustained period in order to activate the block.

You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.

Sorry, this is not well-thought and certainly has potential for abuse. This is on IP and not domain? What is the signing authority and cryptography mechanism preventing a spoofed request?

Re: The largest DDoS attack to date, peaking above 398M rps

#145

Earlier quoted context omitted.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

Was at Tokyo Disneyland today and taught my girlfriend the word “enshittification”. (i.e. making your customers pay via your stupid app to do literally anything in your park, and not even providing wi-fi.)

That's double-dipping?

Re: The largest DDoS attack to date, peaking above 398M rps

#146
post #96

Earlier quoted context omitted.

What you say already exists, hell, you can use BGP to distribute ACLs But it costs space in the routing tables and that means replacing routers earlier. It's no wonder, especially if you multiply it by thousand customers. "block all traffic from outside from this IP" is significantly easier than "block all traffic from outside from this IP to this client". And you need to do it per ISP client, else it is ripe for abu…

> What you say already exists, hell, you can use BGP to distribute ACLs But you should own an AS for that? > But it costs space in the routing tables Not implementing my proposal leaves critical infrastructure unprotected from foreign attacks. Make larger routing tables. Also, instead of blocking single IPs one can block /8 or /16 subnets.

Make larger routing tables.

Brilliant! Why didn’t we think of that?!? MOARE TCAMS!!!

Re: The largest DDoS attack to date, peaking above 398M rps

#147
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us.

2FA and password managers didn't make us heavily reliant on massive companies.

Re: The largest DDoS attack to date, peaking above 398M rps

#148

Earlier quoted context omitted.

So I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!

Simple! To prevent it being abused easily you could make it so you would need to send a high number of those packets for a sustained period in order to activate the block.

There is already an RFC we could apply, just implement forced RFC3514 compliance and filter any packets with the evil bit set.

https://datatracker.ietf.org/doc/html/rfc3514

Re: The largest DDoS attack to date, peaking above 398M rps

#149

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> Privacy, long term, will mean the fall of civilization. I'm curious about your rationalization for this. Lack of privacy will also mean the fall of civilization. Civilization is just doomed to fail at one point or another. All things come to an end.

This discussion is somewhat reminiscent of "Don't hex the water"..

https://www.youtube.com/watch?v=Fzhkwyoe5vI

Re: The largest DDoS attack to date, peaking above 398M rps

#150
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

A protection tax? You realize that DDoS protection costs them providers real money?
Post reply on HN