Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

161–170 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#161
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> Let's go back to username and password. 2FA forces scammers to up their game.

Let's do it. It works for the website you're using right now. 2FA was in large part motivated by limiting bot accounts and getting customers phone number.

I can't imagine how much productivity the economy loses every day due to 2FA.

Re: The largest DDoS attack to date, peaking above 398M rps

#162

Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.

If it becomes this easy to block traffic couldn't malicious applications really mess up a user by spamming out reject packets for common IP?

Re: The largest DDoS attack to date, peaking above 398M rps

#163
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

This is akin to the argument that bike helmets makes people less safe (and invariably has a comment about the Dutch and their safety record)

It is like saying effective spam filters are bad for email as a distributed system.

It's the spam that killed email, not the filters.

Re: The largest DDoS attack to date, peaking above 398M rps

#165

Wonder how you could even handle this if you weren’t using a big cloud provider and didn’t have a lot of money to spend.

You can’t. If your webserver receives 400m rps it dies, end if story.

Mitigations are just that, mitigations. They are as effective as buying a better door lock to protect your apartment from a nuke.

Re: The largest DDoS attack to date, peaking above 398M rps

#166
post #65

Earlier quoted context omitted.

Block the whole subnet and make it the ISP's problem?

How does the ISP solve it? Send a mass mail/email telling people to reset their devices because someone has a device with botnet malware?

That is their problem. Maybe the price needs to go up if you don't secure all your devices as the ISP is going to send a tech to your house. Or maybe the ISP has deep enough pockets to find a sue those cheap IOT device makers for not being secure thus funding their tech support team.

Re: The largest DDoS attack to date, peaking above 398M rps

#167
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

In less words, it’s DDoS attackers that make the internet a worst place

Re: The largest DDoS attack to date, peaking above 398M rps

#168
post #38
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

The only answer is publicly-resourced protection and it's not that weird when you think about it. My apartment has a basic lock that any locksmith can undo and I'm safe because of my community and government protection (police, mental healthcare, justice system, etc...). Seems like the same logic should apply to my website or other digital property.

Community yes. Government protection no. When was the last time you heard of police stopping a break-in or making a successful investigation ?

Independent of police, in bad communities your neighbors are willing to break in. In good communities they don't.

Re: The largest DDoS attack to date, peaking above 398M rps

#169
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Most of them are dynamic IPs. Some of them are infected mobile devices.

What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever?

What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP?

What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoever gets that IP from now on?

Your solution doesn't stop attacks. It just stops regular users.

Re: The largest DDoS attack to date, peaking above 398M rps

#170
post #23

Earlier quoted context omitted.

That's the particularly bad news, this attack does NOT require a really huge botnet. https://blog.cloudflare.com/zero-day-rapid-reset-http2-recor... "Furthermore, one crucial thing to note about the record-breaking attack is that it involved a modestly-sized botnet, consisting of roughly 20,000 machines"

20000 being modest really says a lot about the state of security on the Internet.

There are 5 billion people on the internet. This is 0.0004%. Even 2 million is only 0.04%.

(this assumes that 1 person = 1 device; some people share devices, most people have more than one, e.g. I have a laptop and a router, many people also have a phone, a work laptop, and whatnot – the average is probably >1, maybe even >2)

Post reply on HN