Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

231–240 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#231

Earlier quoted context omitted.

Most of them are dynamic IPs. Some of them are infected mobile devices. What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? What if you're getting hit from a residential connection that gets a new rotated IP every couple of weeks? Block whoe…

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? No, but for a day perhaps. > What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator). If the ISP can’t be arsed to do their job, why…

ISP needs to start taking much more responsibility, currently they do not care or choose not to care to avoid having to deal with upset customers.

The fact that millions, if no more, devices can continue to access the internet regardless of how long they are compromised, is just crazy. I get that it put more responsibility upon end users to secure their devices, if they otherwise run the risk of get thrown of the internet, but I currently fail to see other options. Our device security still isn't good enough that we can just use them with reckless abandonment.

Any "solution" that attempts to fix the problem of increasing DDoS attacks and their damage that doesn't address the issue of compromised devices being allowed to roam free on the internet is a band aid at best.

And I can almost hear people complain that I'm arguing to throw compromised IoT, SCADA and monitoring devices of the internet, and yes I am. None of these things have any business being exposed to the public internet anyway.

Re: The largest DDoS attack to date, peaking above 398M rps

#232

Earlier quoted context omitted.

Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

Before Google, new search engines became crappy after 6-12 months, maybe two years tops.

It's not surprising Google search is now crap, it's what happened to all the old search engines. It's only surprising that it took 15-20 years (depending on perspective), and in the mean time, they've developed a big ecosystem of other stuff.

Re: The largest DDoS attack to date, peaking above 398M rps

#233

Earlier quoted context omitted.

Child-run lemonade stands are technically illegal in most states (some have actually carved out exemptions for them because of overzealous policing). Garage sales often have a specific carve out, also, and limitations on numbers of time per year, etc. Most areas nobody cares at all until it becomes a nuisance somehow.

Selectively enforced laws are the worst kind of law.

I've always thought it would be interesting to allow as a defense against a violation of a law to prove that the law is regularly violated without consequence.

Because selectively enforced laws are just another way of saying you have a king at some level, the person who decides to enforce or not.

Re: The largest DDoS attack to date, peaking above 398M rps

#234

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Doesn't using your botnet expose your botnet IP addresses/devices?

Re: The largest DDoS attack to date, peaking above 398M rps

#235

Earlier quoted context omitted.

Hope you plan ahead for a house fire with a 3-2-1 approach for backups. Maintaining an always on off-site storage is expensive unless you resort to cloud solutions like OneDrive or Dropbox, but then you go back to the problem of having your passwords on the cloud, even if encrypted. Not using cloud is just very expensive and time consuming for the average user.

Passwords are small enough that you can make physical backups easily.

Honest question, because it is interesting and might change how I approach backing up my passwords. How would you go about maintaing that physical copy updated?

What I think would make this approach hard is that you would have to ponder if a newly created account is important at creation time in order to know if you should update the off-site, physical copy of your most important passwords (I say this because if you want to backup everything and avoid the cloud entirely it is just not viable, having to update this physical backup for each new account. I am currently at over 400 logins in my pw manager, 2 years ago it was half as much).

I think having your passwords encrypted with a high enough entropy master password and a quantum-resistant encryption algorithm, and having an off-site, physical backup of your cloud account credentials is enough for anyone not publicly exposed, like a politician or someone extremely wealthy, even though I would be skeptical these people go through such lengths to protect their online accounts.

Re: The largest DDoS attack to date, peaking above 398M rps

#236

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

[deleted]

Re: The largest DDoS attack to date, peaking above 398M rps

#237

Earlier quoted context omitted.

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? No, but for a day perhaps. > What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator). If the ISP can’t be arsed to do their job, why…

It is not an ISPs job to analyze traffic patterns and attempt to stop the bad ones. Thats like saying its the job of the road crews to stop speeders

So who else? My proposal would be to have companies like Google, Microsoft, Amazon and hosting providers be able to report sources of DDoS attack to the ISPs who can then identify the customer and let the customer know that they have a week to fix the issue or lose connectivity.

Re: The largest DDoS attack to date, peaking above 398M rps

#238

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

If they're unsophisticated, it's for clout and "street cred" in hacking communities, no different than tagging a freeway overpass with graffiti.

If they're advanced, they are doing it to test capabilities and responses. The Taliban used to pay kids to light off firecrackers outside base to check defensive TTPs. It also had the effect of desensitizing the sound of gunfire.

Really good adversaries know how to accomplish the latter while appearing as the former.

Re: The largest DDoS attack to date, peaking above 398M rps

#239

Earlier quoted context omitted.

> Let's go back to username and password. 2FA forces scammers to up their game. Let's do it. It works for the website you're using right now. 2FA was in large part motivated by limiting bot accounts and getting customers phone number. I can't imagine how much productivity the economy loses every day due to 2FA.

Is this sarcasm? If not please provide some more details on why you think "2FA was in large part motivated by limiting bot accounts and getting customers phone number". I never used a phone number for 2fa. Mostly TOTP. Bots could do that too. I don't see the connection. >I can't imagine how much productivity the economy loses every day due to 2FA. Is it really that much? Every few days I have to enter a 6 digit numbe…

> ? Every few days I have to enter a 6 digit number I generate on a device I have with me all the time.

I use more than one service a day, and some infrequently, so for me about every day I have a minute or two where I try to login, need to find my phone (it's not predictable when it will ask), and then type it in. This happens to every person several times a day!

I also now must carry a smart phone with me to participate in society.

But the main drag is that when people lose or break their phones the response is: "just don't do that" and the consequences range from losing your account to calling customer service.

> Mostly TOTP. Bots could do that too. I don't see the connection.

Most people using 2FA do not use TOTP, they use a phone number.

Bots could use TOTP, it's more infrastructure, and it's a proof of work function for them to login.

Re: The largest DDoS attack to date, peaking above 398M rps

#240

Earlier quoted context omitted.

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Doesn't using your botnet expose your botnet IP addresses/devices?

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.
Post reply on HN