Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

301–310 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#301
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

> I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

The problem is that IP addresses are not a reliable identifier, especially for the kinds of folks whose routers have been infected by malware. Few ISPs hand out static IP addresses anymore. It's why online games no longer bother with IP bans anymore, because as soon as the target reboots their router they evade your ban and some other poor sap on the same ISP gets stuck with the flagged IP.

Re: The largest DDoS attack to date, peaking above 398M rps

#302

Earlier quoted context omitted.

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Surely bringing down Google is a bigger technical achievement than some random government website maintained by someone who stumbled into their job after 20 years doing mid level government organizational work.

Yes, but they are clearly going to fail to bring down Google.

Re: The largest DDoS attack to date, peaking above 398M rps

#303
post #162

Such attacks are possible because ISPs do not want to adopt a protocol that would allow any host to send a special packet to block malicious traffic on the upstream provider or even at the source network. In this case networks like Cloudflare would become unnecessary.

If it becomes this easy to block traffic couldn't malicious applications really mess up a user by spamming out reject packets for common IP?

I think it would have to be something like "Block traffic from intended for . . ."

Re: The largest DDoS attack to date, peaking above 398M rps

#304

Earlier quoted context omitted.

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Nah it's even better because they're considered capable defenders so it's harder. What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities. Unless this is marketing for Google Cloud?

> Unless this is marketing for Google Cloud?

That seems likely here if they're claiming this is the largest DDOS ever.

Re: The largest DDoS attack to date, peaking above 398M rps

#305
post #294

Earlier quoted context omitted.

I did. I replied to OP question.And that was about DDos attacks in general not "HTTP/2 Rapid Reset attacks" > Who has an incentive to carry out these DDos attacks? Did you read the comment I was replying to?

Yes, “these attacks” referring to the sophisticated novel attacks under discussion in the article. No need to be defensive, just read it next time.

Are there DDoS attacks that are not sophisticated in form or execution? :-)

Re: The largest DDoS attack to date, peaking above 398M rps

#306
post #50

Earlier quoted context omitted.

In that scenario, it's on the ISP to clean their network of abuse, the same thing they would need to do if Gmail had blacklisted their IPs for spamming. After all, an ISP that can't connect to YouTube isn't going to stay in business for long. People have been begging ISPs for ages to do a bit of egress filtering, for example, to prevent source address falsification. They've demonstrated time and again that they don't…

OK, but how should an ISP distinguish a good HTTP/2 connection from a bad one (I'm talking about this particular attack)? As far as I can tell, the DoS starts after the connection from bot to server is established, at which point the connection is fully encrypted. Should all ISPs MITM their clients to ensure that all traffic is good and proper?

Ever had your droplet suspended for using a vulnerable WordPress plugin?

Your droplet suddenly tries to log into somebody else's server 10 times a second. The target of the attack complains to DigitalOcean, "hey, one of your customers is trying to hack me!" and attaches a log of the login attempts. DigitalOcean assumes that the report was made in good faith, forwards it to you and immediately suspends your droplet. It won't be reactivated until you reply with evidence that you have at least tried to clean up the problem. If it happens again, you won't get off so easily.

I suppose that a similar system, in a more real-time fashion, could be set up between the maintainers of the blacklist (Google, Cloudflare, Amazon, etc.) and the ISPs. No need for the ISPs to sniff on everyone's traffic if they can rely on good-faith reports from the lion's mouth that somebody from port 52384 on 11.22.33.44 is DDoSing a Google property. Even with CGNAT, the port will identify the customer responsible.

Re: The largest DDoS attack to date, peaking above 398M rps

#307
post #284

Earlier quoted context omitted.

approx. 20,000 machines https://news.ycombinator.com/item?id=37831355

So a single machine can do ~ 20,000 rps?

Depends, but there seems to be a multiplier effect at play with this attack. A single client request may result in 100x the work for the server. More details here: https://cloud.google.com/blog/products/identity-security/how...

Re: The largest DDoS attack to date, peaking above 398M rps

#308

Earlier quoted context omitted.

Surely bringing down Google is a bigger technical achievement than some random government website maintained by someone who stumbled into their job after 20 years doing mid level government organizational work.

Yes, but they are clearly going to fail to bring down Google.

Right, so clearly the ability to bring down Google is not the point.

Re: The largest DDoS attack to date, peaking above 398M rps

#309

Earlier quoted context omitted.

Surely bringing down Google is a bigger technical achievement than some random government website maintained by someone who stumbled into their job after 20 years doing mid level government organizational work.

Yes, but they are clearly going to fail to bring down Google.

It doesn't matter if you fail. The cred comes from how much bandwidth and resources you can soak up.

Re: The largest DDoS attack to date, peaking above 398M rps

#310
post #246

Earlier quoted context omitted.

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.

> the owners of those devices isn't going to be informed, nor is their ISPs not necessarily true

But these ISPs that give something and inform and even isolate their infected customers are few and far between.

Shout out to Dutch ISP XS4ALL who was (is?) very very strict and active in this space.

Post reply on HN