Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

221–230 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#221

Earlier quoted context omitted.

Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? No, but for a day perhaps. > What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator). If the ISP can’t be arsed to do their job, why…

Trust me when I say that you don't want the ISP's to inspect web traffic. That is not how to solve this. That is costly for the ISP and will drive up costs. It also makes supporting a website impossible. The ISP is assumed by all parties to be impartial. That assumption is required for the internet to be operational. Sure it might function your way, but it would be impossible to support.

And maybe Facebook and Google are big enough to push around the ISP's, but they are the only ones. Nobody will bat an eyelash if 15,000 Comcast users in Phoenix AZ can access your hokey-pokey website. Comcast doesn't care. The users won't blame their ISP. They will blame you, or whoever owns the hokey-pokey website. If you want traffic, you need to be equipped to handle traffic. You are the one with the internet facing infrastructure.

You are the one blocking traffic. Not the ISP. That is how it should be. The ISP should be impartial. You pay for connectivity. Consider yourself connected. For better or for worse. You are responsible for what you put onto that connection.

Re: The largest DDoS attack to date, peaking above 398M rps

#222

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

If the source field in a packet reliably indicated the source of the packet and a given IP was sending you a lot of unwanted traffic, you'd ask their ISP to turn them off and the problem would be solved. Maybe one day BCP38 will be fully deployed and that will work. I also dream of a day where chargen servers are only a memory. Some newer protocols are designed to limit the potential of reflected responses.

Null routing is available in some situations, but of course it's not very specific: hey upstreams (and maybe their upstreams), drop all packets to my specific IP. My understanding is null routing is often done via BGP, so all the things (nice and not) that come with that.

Asking for deeper packet inspection than looking at the destination is asking for router ASICs to change their programing; it's unlikely to happen. Anyway, the distributed nature of DDoS means you'd need hundreds of thousands of rules, and nobody will be willing to add that.

Null routing is effective, but of course it takes you IP offline. Often real traffic can be encouraged to move faster than attack traffic. Otherwise, the only solution is to have more input bandwidth than the attack and suck it up. Content networks are in a great position here, because they deliver a lot of traffic over symetric connections, they have a lot of spare inbound capacity.

Re: The largest DDoS attack to date, peaking above 398M rps

#223
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

It’s a prisoner dilemma! The only way to win is for both service providers and “bad people” to not escalate. That’s not going to happen.

Re: The largest DDoS attack to date, peaking above 398M rps

#224

Earlier quoted context omitted.

You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.

It's not very hard to send packets with a fake source IP, especially if you don't care about the reply.

Seems easy enough to require (i.e. regulate) end-customer ISPs to drop any traffic with a source IP that isn't assigned to the modem it's coming from. This would at least prevent spoofing from e.g. compromised residential IoT devices. Are they not already doing that filtering? Is there any legitimate use-case to allow that kind of traffic?

Re: The largest DDoS attack to date, peaking above 398M rps

#225

Earlier quoted context omitted.

Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? No, but for a day perhaps. > What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator). If the ISP can’t be arsed to do their job, why…

It is not an ISPs job to analyze traffic patterns and attempt to stop the bad ones. Thats like saying its the job of the road crews to stop speeders

Re: The largest DDoS attack to date, peaking above 398M rps

#226

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Re: The largest DDoS attack to date, peaking above 398M rps

#227

Earlier quoted context omitted.

Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

As someone old enough to remember: one of the main reasons Google won was that the other engines (shedding here a tear for Lycos) simply couldnt handle the increasing amount of web spam. They were built in a trusted web environment, but suddenly things became cheap enough for less scrupulous people to start creating effectively spam sites, and the engines somehow didn't manage to react in time.

Re: The largest DDoS attack to date, peaking above 398M rps

#228
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

>but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

Using any kind of community coordinated IP ban is useless and would hurt a lot of people, millions(or even billions) of devices have dynamic IP addresses.

You would not stop botnets from DDoSing you and on top of that you'd block millions of legitimate users.

Re: The largest DDoS attack to date, peaking above 398M rps

#229

Earlier quoted context omitted.

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

> Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.2.3.4/16. So, if my neighbour is infected and one of his devices is part of a botnet, I get blocked as well?

That already effectively happens in a lot of cases.

Re: The largest DDoS attack to date, peaking above 398M rps

#230

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

The botnet is probably the critical thing. Even if the PR (or "avenge the global south", or whatever) value might not be enormous, the cost to a bad actor of having other peoples' computers do something is almost negligible.
Post reply on HN