Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

201–210 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#201
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

[flagged]

I was writing it with a "using antibiotics in absolutely every mundane product causes superbugs" energy actually, which is something that is really a problem.

Re: The largest DDoS attack to date, peaking above 398M rps

#202
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever?

No, but for a day perhaps.

> What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP?

Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator).

If the ISP can’t be arsed to do their job, why am I supposed to care about them at all?

> What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoever gets that IP from now on?

Same as the CGNAT one. It’s the ISP’s job to handle their misbehaving customers.

If they refuse to do it and get complaints from their other customers that they’re getting blocked, maybe they’ll actually get to it.

> Your solution doesn't stop attacks. It just stops regular users.

No. It puts pressure on the ISPs to finally stop whining loudly when they receive an attack while closing their eyes on any attack originating from their network.

This is not sustainable.

Re: The largest DDoS attack to date, peaking above 398M rps

#203
post #147

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

But that's exactly the problem, it shouldn't require a enterprise grade tool just to host a simple website on the internet. We've lost something due to our inability to stop attacks at the source and heavy overreliance on massive cloud providers to do it for us. 2FA and password managers didn't make us heavily reliant on massive companies.

you don't need enterprise grade tools just to host a simple website. however, if your simple site ever gains enough attraction to come under an attack, especially like this, you'll never survive. you can either just accept that your service will not survive the attack and just shut it down until the attackers realize mission accomplished and stops. you can then hope they don't notice when you bring it back. no simple site will be able to afford what's required to stay up from these attacks.

i'm not saying i like having to put the majority behind the services of 2 or 3 companies, but if you ever get shut down from some DDOS, you'll understand why people think they need to.

Re: The largest DDoS attack to date, peaking above 398M rps

#204
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…

The idea clearly needs some work.

But, a slight defense of it—the really big providers can already sink a massive DDoS anyway. So, this is just a scheme to help little websites. It doesn’t really matter if a school, or even a cellphone network, can’t access my little website for an afternoon.

You’d have to decide if you want to send the block request. If you are hosting your personal blog, you’ll probably go for it regardless. If you are providing a small service; hosting git for a couple friends or whatever, you’ll probably block with some discretion.

Re: The largest DDoS attack to date, peaking above 398M rps

#205

Earlier quoted context omitted.

It's worth noting that features like the one that enabled Rapid Reset are pushed into standards by the exact same companies, because they are needed for performance at their scale. So in a way this was partially caused by the existence of insanely big tech companies that need such features.

Either I misunderstood the issue, but it sounds like rapid reset was not the cause.

Rapid Reset is the name given to the technique behind the attack. The cause is a flaw in HTTP/2 stream multiplexing that enables this technique.

Re: The largest DDoS attack to date, peaking above 398M rps

#206

Earlier quoted context omitted.

> 2FA and password managers didn't make us heavily reliant on massive companies. Retool: https://arstechnica.com/security/2023/09/how-google-authenti... Lastpass: https://news.ycombinator.com/item?id=34516275

2FA, I’m not sure. But Lastpass doesn’t represent the whole of password managers. Storing your passwords in an online service is a really silly thing to do (for passwords that matter at least). Use something local like keepass.

Hope you plan ahead for a house fire with a 3-2-1 approach for backups. Maintaining an always on off-site storage is expensive unless you resort to cloud solutions like OneDrive or Dropbox, but then you go back to the problem of having your passwords on the cloud, even if encrypted.

Not using cloud is just very expensive and time consuming for the average user.

Re: The largest DDoS attack to date, peaking above 398M rps

#207
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Proliferation of low cost computing is the cause of this, not big players being able to mitigate this.

This is not coming from "known botnet IPs", this is from random infected devices. Some aren't even permanently doing this, just one request from a device per day - it already large enough to cause issues.

Re: The largest DDoS attack to date, peaking above 398M rps

#208

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution That’s not a fair point. We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of pok…

I don't think it's true that 0 actions are being taken. When new vectors for amplification attacks are found, they get patched - you can't do NTP amplification attacks on modern NTP servers anymore, for example. But it takes a long time for the entire world to upgrade and just a handful of open vulnerable servers to launch attacks. And in the meantime people are always looking for new amplification vectors.

> The solution is to finally hold accountable attack origins (ISPs, mostly), so that monitoring their egress becomes something they have an incentive to do.

Be careful what you wish for. The sort of centralized C&C infrastructure and "list of bad actors everybody has to de-peer" that you would need to this effectively would we a wonderful juicy target for governments to go, "hey, add [this site we don't like] to the list, or go to prison".

Re: The largest DDoS attack to date, peaking above 398M rps

#209

Earlier quoted context omitted.

I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size. There is no need for any central authority and no need to maintain any lists.

That actually sounds like a really good idea. This is already implemented in the physical world (in a much less efficient way) in the form of “no spam” stickers and registrations. Is there a reason other than inertia for why it hasn’t been implemented?

The main problem is how do you authenticate the request as being legitimate? It's already possible to spoof headers and "FROM-IP" (in fact, major DDoS attacks use just this as a replay attack, spoof a DNS request as coming from 1.1.1.1 and get a much larger response sent TO 1.1.1.1 from wherever).

Re: The largest DDoS attack to date, peaking above 398M rps

#210
post #70

Earlier quoted context omitted.

I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.

Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…

Amazon definitely cares if they lose 1% of sales.

Guess who has more votes, you or Amazon.

Post reply on HN