Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

321–330 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#321

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

You can (or could, my information is old) pay botnet owners a few hundred bucks to disrupt the servers of people you don't like. An example would be ruining a match for a competing game clan. There's a suprising amount of this kind of petty bullshit going on in the world. With the Mirai botnet, some of the creators had a DDOS mitigation company as well: they'd sell one party the weapon, and sell another party the def…

Disruption is part of it for sure, but often big, aggressive DDoS come hand-in-hand with other attacks.

Seen it happen with big DDoS on clients. Furaffinity, one of the larger furry webistes, and a constant drama magnet, was a client at a former job. They got DDoS'd hard, and in between scripted DDoS hits they slammed the hell out of their web applications to get vulns and do credential stuffing.

As in blast em, lighten it up just enough to get a ssh or nmap through a few times, blast em again, and repeat until they got in.

Is also why you want out-of-band solution that doesn't touch your infra much.

Re: The largest DDoS attack to date, peaking above 398M rps

#322

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Why not attack a target that can actually be harmed? Are they afraid?

It's not obvious what's the value of having the largest ineffective attack.

Re: The largest DDoS attack to date, peaking above 398M rps

#323
post #281

398M rps means a request every 2.5ns. Most likely the figure is incorrect, or at least misleading.

Well .. it's a novel minimalistic attack. A trivial attack. Cloud Flare also got one of these, 201 RPS.

Minimum frame size is about 100 bytes. At 100Gbps, that's a top bandwidth of one frame every 8 nanoseconds.

Re: The largest DDoS attack to date, peaking above 398M rps

#324

Earlier quoted context omitted.

It's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....

How? I suppose the most effective way is to have those proxies attack each other. But don’t, it’s likely illegal.

the most efficient way would be to write a script that gains root on those open proxies and then fixes the issue.

Re: The largest DDoS attack to date, peaking above 398M rps

#325
This is just Google bs. There is no way in hell they can't mitigate anything at the edge of this nature. If this was a real problem it most likely originated from within GCP. The article does not even state where the traffic comes from.

EDIT: Ok, so this was a 0-day issue. Then it all makes more sense. Sorry.

Re: The largest DDoS attack to date, peaking above 398M rps

#326

Earlier quoted context omitted.

Surely bringing down Google is a bigger technical achievement than some random government website maintained by someone who stumbled into their job after 20 years doing mid level government organizational work.

Yes, but they are clearly going to fail to bring down Google.

Well - they clearly were successful enough to get a thread on hacker news……

Re: The largest DDoS attack to date, peaking above 398M rps

#327
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

It’s a prisoner dilemma! The only way to win is for both service providers and “bad people” to not escalate. That’s not going to happen.

The typical way of dealing with "bad people" is to subject them to the criminal justice system (or vigilantism if the problem is bad enough and the criminal justice system is inadequate). This tends to reduce, but not eliminate, the misbehaving.

Improving the ability to track down and prosecute perpetrators tends to result in less anonymity/privacy, so that makes the problem challenging.

Thinking in the long/very-long term, we need to get more innovative with the underlying technology to mitigate abuse. I mentioned this effort https://named-data.net in another part of the thread.

Re: The largest DDoS attack to date, peaking above 398M rps

#328
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

None of your examples are valid, IMO.

Procuring and operating the infrastructure to mitigate this kind of attack costs many many thousands of dollars or requires becoming part of the Cloudflare/AWS/Google hive.

Joe Schmo can set up a TOTP server, run keepass/bitwarden and use letsencrypt for free (or another SSL provider for cheap).

The lament from parent is that running a simple blog reliably shouldn't require being inside Cloudflare's castle walls or building your own castle.

---

My personal observation is that simple websites should continue operating HTTP1!

Re: The largest DDoS attack to date, peaking above 398M rps

#329

Earlier quoted context omitted.

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.

Google should start using their ad network to silently update people’s security!

Uh, no thanks from this user.

Also, sounds illegal.

Re: The largest DDoS attack to date, peaking above 398M rps

#330

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Well in this case it seems like they blew their "0-day" and Google worked with other providers to patch this type of attack.
Post reply on HN