Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

151–160 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#151
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

We could also treat it as a public security threat and act accordingly.

Which jurisdiction are you referring to with “we”?

Re: The largest DDoS attack to date, peaking above 398M rps

#152

Earlier quoted context omitted.

So I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!

You can deny access only from your IP, not for anyone else.

How do you verify the source address of the packet is legit?

Re: The largest DDoS attack to date, peaking above 398M rps

#153

No word on the origin of these attacks? This must require massive amounts of hardware, you’d imagine it to be easily traceable unless some kind of botnet.

One could imagine that, given the size, it could be politically or legally sensitive to announce the origin.

Cloudflare explicitly says it's an unknown threat actor: https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor...

Re: The largest DDoS attack to date, peaking above 398M rps

#154
post #147

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

Yes, but if these cloud providers didn't exist eventually there'd be botnets that no site could protect against, rather than the status quo of at least some sites being able to resist them. The idea that the existence of cloud providers that can soak up a lot of traffic is making things worse by causing botnets to get more powerful just seems silly.

Re: The largest DDoS attack to date, peaking above 398M rps

#155

Wonder how you could even handle this if you weren’t using a big cloud provider and didn’t have a lot of money to spend.

How small a server setup do you mean? This was apparently 20k machines: https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor...

Most web services don't need clever protocol attacks to be downed by 20k machines.

Re: The largest DDoS attack to date, peaking above 398M rps

#156

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

> Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16.

So, if my neighbour is infected and one of his devices is part of a botnet, I get blocked as well?

Re: The largest DDoS attack to date, peaking above 398M rps

#157
post #147

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

> 2FA and password managers didn't make us heavily reliant on massive companies.

Retool: https://arstechnica.com/security/2023/09/how-google-authenti...

Lastpass: https://news.ycombinator.com/item?id=34516275

Re: The largest DDoS attack to date, peaking above 398M rps

#158
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

This is akin to the argument that bike helmets makes people less safe (and invariably has a comment about the Dutch and their safety record)

Re: The largest DDoS attack to date, peaking above 398M rps

#159

Earlier quoted context omitted.

So I can deny service to your site with a single packet, instead of having to bother with establishing a whole botnet? The current botnet customers would be the first to advocate for this new protocol!

You can deny access only from your IP, not for anyone else.

IP addresses can be spoofed. So you’d need some kind of handshake to verify you are the owner of that IP. Which is going to be tough to complete if your network is completely saturated from the DDoS in progress.

I do think your idea has merit though. But it’s still a long way from being a well thought-out solution.

Re: The largest DDoS attack to date, peaking above 398M rps

#160
post #150
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

A protection tax? You realize that DDoS protection costs them providers real money?

Yes, but cloud providers share that protection over all customers. Someone hosting their own websites needs the same level of protection just for themselves.

DDoS is really the only thing that you can't host yourself on your own machines in today's internet.

Post reply on HN