The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
[flagged]
The largest DDoS attack to date, peaking above 398M rps
201–210 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#202The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…
No, but for a day perhaps.
> What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP?
Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator).
If the ISP can’t be arsed to do their job, why am I supposed to care about them at all?
> What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoever gets that IP from now on?
Same as the CGNAT one. It’s the ISP’s job to handle their misbehaving customers.
If they refuse to do it and get complaints from their other customers that they’re getting blocked, maybe they’ll actually get to it.
> Your solution doesn't stop attacks. It just stops regular users.
No. It puts pressure on the ISPs to finally stop whining loudly when they receive an attack while closing their eyes on any attack originating from their network.
This is not sustainable.
Re: The largest DDoS attack to date, peaking above 398M rps
#203Earlier quoted context omitted.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.
i'm not saying i like having to put the majority behind the services of 2 or 3 companies, but if you ever get shut down from some DDOS, you'll understand why people think they need to.
Re: The largest DDoS attack to date, peaking above 398M rps
#204The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…
But, a slight defense of it—the really big providers can already sink a massive DDoS anyway. So, this is just a scheme to help little websites. It doesn’t really matter if a school, or even a cellphone network, can’t access my little website for an afternoon.
You’d have to decide if you want to send the block request. If you are hosting your personal blog, you’ll probably go for it regardless. If you are providing a small service; hosting git for a couple friends or whatever, you’ll probably block with some discretion.
Re: The largest DDoS attack to date, peaking above 398M rps
#205Earlier quoted context omitted.
It's worth noting that features like the one that enabled Rapid Reset are pushed into standards by the exact same companies, because they are needed for performance at their scale. So in a way this was partially caused by the existence of insanely big tech companies that need such features.
Either I misunderstood the issue, but it sounds like rapid reset was not the cause.
Re: The largest DDoS attack to date, peaking above 398M rps
#206Earlier quoted context omitted.
> 2FA and password managers didn't make us heavily reliant on massive companies. Retool: https://arstechnica.com/security/2023/09/how-google-authenti... Lastpass: https://news.ycombinator.com/item?id=34516275
2FA, I’m not sure. But Lastpass doesn’t represent the whole of password managers. Storing your passwords in an online service is a really silly thing to do (for passwords that matter at least). Use something local like keepass.
Not using cloud is just very expensive and time consuming for the average user.
Re: The largest DDoS attack to date, peaking above 398M rps
#207The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.
This is not coming from "known botnet IPs", this is from random infected devices. Some aren't even permanently doing this, just one request from a device per day - it already large enough to cause issues.
Re: The largest DDoS attack to date, peaking above 398M rps
#208Earlier quoted context omitted.
What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…
> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution That’s not a fair point. We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of pok…
> The solution is to finally hold accountable attack origins (ISPs, mostly), so that monitoring their egress becomes something they have an incentive to do.
Be careful what you wish for. The sort of centralized C&C infrastructure and "list of bad actors everybody has to de-peer" that you would need to this effectively would we a wonderful juicy target for governments to go, "hey, add [this site we don't like] to the list, or go to prison".
Re: The largest DDoS attack to date, peaking above 398M rps
#209Earlier quoted context omitted.
I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size. There is no need for any central authority and no need to maintain any lists.
That actually sounds like a really good idea. This is already implemented in the physical world (in a much less efficient way) in the form of “no spam” stickers and registrations. Is there a reason other than inertia for why it hasn’t been implemented?
Re: The largest DDoS attack to date, peaking above 398M rps
#210Earlier quoted context omitted.
I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.
Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…
Guess who has more votes, you or Amazon.