The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
We could also treat it as a public security threat and act accordingly.
The largest DDoS attack to date, peaking above 398M rps
151–160 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#152Earlier quoted context omitted.
So I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!
You can deny access only from your IP, not for anyone else.
Re: The largest DDoS attack to date, peaking above 398M rps
#153No word on the origin of these attacks? This must require massive amounts of hardware, you’d imagine it to be easily traceable unless some kind of botnet.
One could imagine that, given the size, it could be politically or legally sensitive to announce the origin.
Re: The largest DDoS attack to date, peaking above 398M rps
#154Earlier quoted context omitted.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.
Re: The largest DDoS attack to date, peaking above 398M rps
#155Wonder how you could even handle this if you weren’t using a big cloud provider and didn’t have a lot of money to spend.
Most web services don't need clever protocol attacks to be downed by 20k machines.
Re: The largest DDoS attack to date, peaking above 398M rps
#156Earlier quoted context omitted.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…
So, if my neighbour is infected and one of his devices is part of a botnet, I get blocked as well?
Re: The largest DDoS attack to date, peaking above 398M rps
#157Earlier quoted context omitted.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.
Retool: https://arstechnica.com/security/2023/09/how-google-authenti...
Re: The largest DDoS attack to date, peaking above 398M rps
#158The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
Re: The largest DDoS attack to date, peaking above 398M rps
#159Earlier quoted context omitted.
So I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!
You can deny access only from your IP, not for anyone else.
I do think your idea has merit though. But it’s still a long way from being a well thought-out solution.
Re: The largest DDoS attack to date, peaking above 398M rps
#160The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
A protection tax? You realize that DDoS protection costs them providers real money?
DDoS is really the only thing that you can't host yourself on your own machines in today's internet.