Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

211–220 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#211

Earlier quoted context omitted.

ISPs do not want to spend money for fighting against criminals.

That doesn’t sound convincing to me. I mean I understand they don’t want to spend money but if cost is the only barrier it seems like that could be overcome somehow by interested parties.

It's not the costs, it's that some ISPs like getting money from spammers and criminals, and carefully look the other way.

And the other ISPs like getting paid for DDoS mitigation, so they also look the other way. There's no money to be made fixing the underlying problem.

Re: The largest DDoS attack to date, peaking above 398M rps

#212
post #199

Earlier quoted context omitted.

A similar analogy can be made with the likes of westward expansion in the continental US. Back then, you got a piece of land, and really could do what you wanted with it. Build a business, farm, etc. some government taxes but nothing crazy. But you had to deal with criminals, lack of access to medical care, and lack of education. Now to do the same, you have a slew of building codes, regulations, zoning laws, and are…

> home owners can still just have an egg or vegetable stand at the end of their driveway No you can't. That is illegal without a "cottage food" license, training, and labeling in most of the US. https://www.pickyourown.org/CottageFoodLawsByState.htm

Okay but does that mean anything regarding the parent commentor's analogy or the article?

Re: The largest DDoS attack to date, peaking above 398M rps

#213
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

That's not a valid comparison, since there are various effective decentralized 2FA methods available – unlike for DDoS protection.

Re: The largest DDoS attack to date, peaking above 398M rps

#214
post #110

Earlier quoted context omitted.

> pay Google, Amazon or Cloudflare a protection tax. Just FYI: hetzner has free DDoS https://www.hetzner.com/unternehmen/ddos-schutz I'm sure other hosting companies also offers it.

Doesn't really work for those types of attacks > In this final layer, we filter out attacks in the form of SYN floods, DNS floods, and invalid packets. We are also able to flexibly adapt to other unique attacks and to reliably mitigate them. Which means any legit http2 connection will go just fine. Even if such connection now triggers hundreds of substreams. Push for end to end encrypted internet also means you can't…

For the higher layer attacks you have to have something like the "modified cryptominer in the browser" things that cloud flare and friends do now - those interstitial pages that pop up for a few seconds are doing mathematical hashing to burn processor time on your end - which greatly complicates the ability to DDoS.

Re: The largest DDoS attack to date, peaking above 398M rps

#215
post #199

Earlier quoted context omitted.

> home owners can still just have an egg or vegetable stand at the end of their driveway No you can't. That is illegal without a "cottage food" license, training, and labeling in most of the US. https://www.pickyourown.org/CottageFoodLawsByState.htm

Child-run lemonade stands are technically illegal in most states (some have actually carved out exemptions for them because of overzealous policing). Garage sales often have a specific carve out, also, and limitations on numbers of time per year, etc. Most areas nobody cares at all until it becomes a nuisance somehow.

Selectively enforced laws are the worst kind of law.

Re: The largest DDoS attack to date, peaking above 398M rps

#216

Should Google actually provide the DDoS initiators with debug information like this graph? Just thinking...

The graph shows the initiators nothing they don't already know.

What would be truly terrifying is if Google kept this a secret and let it sneak up on the world. I have zero faith in Google to do the right thing, and I have zero confidence in their impartiality, and zero confidence in them being the gatekeeper for internet standards. And that's WITH all these silly open self-congratulating blog posts.

Google needs people to trust them in order for them to try to be gatekeeper of best practices and web standards. They want nothing more than to absorb the W3C. That will never happen if they can't convince the "professionals" to parrot everything they say. And they can't get anyone to parrot unless they write these self-congratulatory blog posts. Likewise, they need all the open-source developers who basically wrote Google's codebase to fix their code for them, for free of course. They won't do that unless Google tells them what's broken.

Re: The largest DDoS attack to date, peaking above 398M rps

#217

Earlier quoted context omitted.

2FA, I’m not sure. But Lastpass doesn’t represent the whole of password managers. Storing your passwords in an online service is a really silly thing to do (for passwords that matter at least). Use something local like keepass.

Hope you plan ahead for a house fire with a 3-2-1 approach for backups. Maintaining an always on off-site storage is expensive unless you resort to cloud solutions like OneDrive or Dropbox, but then you go back to the problem of having your passwords on the cloud, even if encrypted. Not using cloud is just very expensive and time consuming for the average user.

Passwords are small enough that you can make physical backups easily.

Re: The largest DDoS attack to date, peaking above 398M rps

#218
Couldn't cloudflare show a page to the next handful of http requests from an IP informing the user that "something on your network is participating in DDoS attacks".

All the big providers could do this, just inject a little turnstile like page in front of the next cloudflare site you visit.

I would love to know if there's a compromised device on my network, and I don't have any real monitoring set up to detect it.

It's not a full solution, but at least informing users there is a problem is a good start.

Re: The largest DDoS attack to date, peaking above 398M rps

#219
Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it worthwhile. Can anyone help me understand?

Re: The largest DDoS attack to date, peaking above 398M rps

#220
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Do you remember the pre-DDoS mitigation days? Botnets could easily bring down major, important sites and make them unavailable to users. This caused monetary loss and could even cause life loss depending on the site. How is the previous state better than, well, not suffering from these problems?
Post reply on HN