Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

181–190 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#181
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

[flagged]

One is about machines on the internet serving images and forum posts. This comment is low quality and is a form of name calling.

Re: The largest DDoS attack to date, peaking above 398M rps

#182
post #147

Earlier quoted context omitted.

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

> 2FA and password managers didn't make us heavily reliant on massive companies. Retool: https://arstechnica.com/security/2023/09/how-google-authenti... Lastpass: https://news.ycombinator.com/item?id=34516275

2FA, I’m not sure.

But Lastpass doesn’t represent the whole of password managers. Storing your passwords in an online service is a really silly thing to do (for passwords that matter at least). Use something local like keepass.

Re: The largest DDoS attack to date, peaking above 398M rps

#183

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

Do you know what the first D in DDoS attack stands for?

Re: The largest DDoS attack to date, peaking above 398M rps

#184
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

DDoS attacks were growing in size and frequency before these companies started creating products to address them. They took down sites, demanded ransom, and cost a lot of money in lost business and hosting bills.

If you want to complain about an actual working solution, that's your right, but realize that without an alternate solution you're advocating for giving small gangs the ability to disrupt everyone else's lives on a whim.

Re: The largest DDoS attack to date, peaking above 398M rps

#186

Earlier quoted context omitted.

We could also treat it as a public security threat and act accordingly.

Which jurisdiction are you referring to with “we”?

Any that matters, I guess ("we" as in the collective of people).

Re: The largest DDoS attack to date, peaking above 398M rps

#187
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution

That’s not a fair point.

We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of poking around smartly is still enough to this day to find enough open DNS resolvers to launch >500Gbps attacks with one or two computers.

Why are these threats allowed to still exist?

The only ones attempting something are governments shutting down booters (DDoS-as-a-service platforms). But that’s treating symptoms, not causes.

We will eventually need to do something, or it will be impossible to run a website that can’t be kicked down for free by the next bored skid.

Just like paying protection fees to the mafia was a status quo, this also is just that. A status quo, not an inevitability.

The solution is to finally hold accountable attack origins (ISPs, mostly), so that monitoring their egress becomes something they have an incentive to do.

Re: The largest DDoS attack to date, peaking above 398M rps

#188
post #147

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

A similar analogy can be made with the likes of westward expansion in the continental US.

Back then, you got a piece of land, and really could do what you wanted with it. Build a business, farm, etc. some government taxes but nothing crazy. But you had to deal with criminals, lack of access to medical care, and lack of education.

Now to do the same, you have a slew of building codes, regulations, zoning laws, and are basically forced to have municipal services. Higher Taxes to pay the roads, police force, fire fighters, education services etc.

However, home owners can still just have an egg or vegetable stand at the end of their driveway. It won’t be the same as having a storefront in town, but it’s still doable without the overhead.

Similarly, as the internet matures, we’re going to see more and more overhead to sustain a “basic” business.

But you can still have a personal blog ran in your closet, for lower-level traffic.

The analogy isn’t perfect, but unfortunately as threat-actor’s budgets increase, so too do their quality/sophistication of their attacks. If it was cheap to defend against some of the more costly attacks, they would find a different vector.

The answer, to me, is some tangential technology that is some mix of federated or decentralization. Not in a crypto bro sense, but just some tech whose fundamental design solves the inherit problem with how our web is built today.

Then threat actors will find another way, rinse and repeat…

Re: The largest DDoS attack to date, peaking above 398M rps

#189

Earlier quoted context omitted.

Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

I'd say enshittification is inevitable. It isn't a technology issue, it's human issue. Imagination and desire are what brought us this far and also what holds us back. See also: the tragedy of the commons, the prisoner's dilemma, the trolley problem, etc.

Re: The largest DDoS attack to date, peaking above 398M rps

#190

Earlier quoted context omitted.

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

> Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16. So, if my neighbour is infected and one of his devices is part of a botnet, I get blocked as well?

Block the whole country, then I guess you’ll see laws passed that IOT providers need to start updating at a better clip.
Post reply on HN