Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

241–250 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#241

Earlier quoted context omitted.

Doesn't using your botnet expose your botnet IP addresses/devices?

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.

Are you positive that "tell nobody" is the mitigation strategy that Google used here? They could have easily asked router vendors to patch their devices, asked ISPs to blackhole those customers until they're patched, etc.

Re: The largest DDoS attack to date, peaking above 398M rps

#242

Earlier quoted context omitted.

Selectively enforced laws are the worst kind of law.

I've always thought it would be interesting to allow as a defense against a violation of a law to prove that the law is regularly violated without consequence. Because selectively enforced laws are just another way of saying you have a king at some level, the person who decides to enforce or not.

You have some control over this as an ordinary citizen. Next time you're on a jury for a lemonade stand violation, nullify.

Re: The largest DDoS attack to date, peaking above 398M rps

#243
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

Yes, what the OP is saying is related to one of the paradoxes of security/defence, i.e. the fact that the more one increases its defences (like Google is doing) then the more said increase of defences also pushes one's adversary to increase its offence capabilities. Which is to say that Google playing it safer and safer actually causes their potential adversaries to become stronger and stronger.

You can see those paradoxes at play throughout the corporate world and especially when it comes to actual combat/war (to which actual combat/war these DOSes might actually be connected). For example the fact that Israel was relatively successful in implementing its Iron Dome shield only incentivised their adversaries to get hold of even more rockets, so that the sheer number of rockets alone would be able to overwhelm said Iron Dome. That's how Hamas got to firing ~4,000 rockets in one single day recently, that number was out of their league several years ago when Iron Dome was not yet functional.

Re: The largest DDoS attack to date, peaking above 398M rps

#245

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution That’s not a fair point. We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of pok…

Traditionally, a botnet can be compromised (at least largely) of actual consumer devices unknowingly making requests on their owners' behalf. This can cover hundreds of unrelated ISPs as the "origin" and is effectively indistinguishable from organic traffic to a popular destination. "Accountability" is not simple here.

Re: The largest DDoS attack to date, peaking above 398M rps

#246

Earlier quoted context omitted.

Doesn't using your botnet expose your botnet IP addresses/devices?

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.

> the owners of those devices isn't going to be informed, nor is their ISPs

not necessarily true

Re: The largest DDoS attack to date, peaking above 398M rps

#247

Earlier quoted context omitted.

> What happens when you log an attack from a device that is attacking you from a school or business WiFi network? Block the whole IP forever? No, but for a day perhaps. > What if the user is on a CGNAT. Are you going to block the edge proxy for that entire ISP? Maybe. If the ISP doesn’t bother doing anything about it (which is THEIR job, not mine as a website operator). If the ISP can’t be arsed to do their job, why…

It is not an ISPs job to analyze traffic patterns and attempt to stop the bad ones. Thats like saying its the job of the road crews to stop speeders

Or that it's the ISP's job to cut off accounts that are downloading copyrighted works, or hashing cryptocurrency without paying taxes, etc.

It would be nice if the cell phone provider could send a text message reporting the problem. But how to distinguish it from spam?

Re: The largest DDoS attack to date, peaking above 398M rps

#248

Earlier quoted context omitted.

Selectively enforced laws are the worst kind of law.

I've always thought it would be interesting to allow as a defense against a violation of a law to prove that the law is regularly violated without consequence. Because selectively enforced laws are just another way of saying you have a king at some level, the person who decides to enforce or not.

Selective prosecution is a defense under the Equal Protection clause of the Constitution.

However, the Supreme Court has left the prescribed remedy intentionally vague since 1996, which in turn makes the claims themselves less likely to be raised, and less likely to succeed.

https://wlr.law.wisc.edu/wp-content/uploads/sites/1263/2022/...

Re: The largest DDoS attack to date, peaking above 398M rps

#249

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

I've been working on anti-DDOS off and on for 20 years now. The answer is sometimes government actors, but oftentimes scammers in Eastern Europe. They do these big attacks for street cred amongst the botting community.

They then use their street cred to get paid by less scrupulous actors to attack their rivals. Sometimes the people paying are governments, sometimes just shady companies. For example last year there was a lot of crypto companies attacking each other's websites.

Most of the people who do this have a lot of technical skill but not a lot of opportunity to get paid for it based on where they live or the circumstances of their upbringing.

Re: The largest DDoS attack to date, peaking above 398M rps

#250

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Anyone can claim that, there's no link to a specific actor
Post reply on HN