Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

171–180 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#171
post #70

Earlier quoted context omitted.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.

Thing is, don’t care.

The problem is that ISPs whose customers are originating the attacks from don’t give a shit.

If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal.

If you and other customers complain to your ISP (or switch), eventually they’ll do something about it.

We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small botnet ».

These devices should be quarantined.

Re: The largest DDoS attack to date, peaking above 398M rps

#172
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

That would be giving away some of the secret sauce on the part of the cloud providers. They are selling security as (part of their) service. There are some community shared lists of botnets ofcourse, but they may not be vry real time or very up to date.

Re: The largest DDoS attack to date, peaking above 398M rps

#173

Earlier quoted context omitted.

Simple! To prevent it being abused easily you could make it so you would need to send a high number of those packets for a sustained period in order to activate the block.

You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.

It's not very hard to send packets with a fake source IP, especially if you don't care about the reply.

Re: The largest DDoS attack to date, peaking above 398M rps

#174
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Plenty of even quite-large websites just don't get attacked by DDoS attacks, because nobody has any particular reason to attack them.

You’re completely wrong.

All large sites regularly get attacked.

The average skiddie’s motivations are that they’re bored. So they DoS a site they use regularly just to see.

Heck they generally don’t even mean to cause damage per-se, and just think it’s a funny use of their evening.

You have to stop thinking DoS attacks are always particularly personal. They really often just aren’t, and it’s a monumental pain in the ass to be on the receiving end.

Re: The largest DDoS attack to date, peaking above 398M rps

#175

Earlier quoted context omitted.

Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

>... or was the enshittification of search inevitable?

My bet is on the latter. Enshitification is a direct product of greed. No crafts person or creator I know of goes into something they enjoy creating with the intent to make it this monstrosity of money extraction. Most creators have a drive for their creation to be shared and experienced by many.

Yes, you may want to get a reward in the process and for some creators, their motives may change over time if they see an opportunity to turn their creation into a wealth machine for themselves so they can do whatever after.

Enshitification I believe is a secondary effect of something that becomes successful for the owners of something and either they or others change motives towards value. Optimization is no longer about the creation, sharing, experience, humanitarian, whatever motive and shifts to money. The second that becomes the goal, enshitication is just part of the optimization journey. In my line of thinking, it's the same reason monopolies or near monopolies tend to form, these are merely further states along optimization strategies in the monetary/wealth extraction goal.

Part of that process is that when something starts to succeed, it attracts people with these goals so the goal of something shifts pretty rapidly.

Re: The largest DDoS attack to date, peaking above 398M rps

#176
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

[flagged]

[deleted]

Re: The largest DDoS attack to date, peaking above 398M rps

#177
post #147

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

20 years ago if a blog or website ended up on slashdot/digg/whatever there was a good chance it was going down. Scalable websites are a commodity today

Re: The largest DDoS attack to date, peaking above 398M rps

#178
post #147

Earlier quoted context omitted.

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

> 2FA and password managers didn't make us heavily reliant on massive companies. Retool: https://arstechnica.com/security/2023/09/how-google-authenti... Lastpass: https://news.ycombinator.com/item?id=34516275

If Google Authenticator goes away, people will still be able to use 2FA (I for one use Aegis, it's available on F-droid and does everything I need, including encrypted backups)

If Lastpass goes away, people will still be able to use keepass or any of the large number of open source password managers, some of them even with browser integrations.

If I have a website that is frequently attacked by botnets and Cloudflare goes away, what can I use to replace it?

Re: The largest DDoS attack to date, peaking above 398M rps

#179
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

> Cloudflare a protection tax

$NET gives away DDOS protection for free for non-businesses

Re: The largest DDoS attack to date, peaking above 398M rps

#180
post #73

Earlier quoted context omitted.

> Sorry citizen, google services are inaccessible because the only ISP in your city sold a service to a bad actor. > We might fix this, we might not, you DONT have a choice. > Thank you for your continued business.

Indistinguishable from the kind of service I get from Google - the moment that I need a human involved I just close my account with whatever Google service is misbehaving and move on.

But you have other options which is my point.

(swap in any corpo-service provider you personally like the most)

Blanket banning subnet ranges from services because of the actions of someone else is 3rd world shit.

Post reply on HN