Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

341–350 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#342
post #250

Earlier quoted context omitted.

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Anyone can claim that, there's no link to a specific actor

Step 1: Put message on blockchain beforehand with exact date/time and characteristics of DDoS

Step 2: Execute DDoS

Step 3: Prove to others you are responsible by using private key

Re: The largest DDoS attack to date, peaking above 398M rps

#343
post #70

Earlier quoted context omitted.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.

[deleted]

Re: The largest DDoS attack to date, peaking above 398M rps

#344
post #70

Earlier quoted context omitted.

I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.

Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…

Sounds like a really great way to potentially destroy someone's career if they aren't terribly competent and you are. Infect some component in their home network that they don't even know is smart-enabled, and keep breaching their new devices, adding them to an active and conspicuous botnet. The only recourse for average Joe is to find expert help, which isn't really in abundant supply if you are a semi-sophisticated malicious actor.

I don't even want to think about the ramifications for small and medium sized businesses. Realistically, how much would it cost to be able to completely destroy a local competitor by paying someone to orchestrate a few events in succession.

Re: The largest DDoS attack to date, peaking above 398M rps

#347

Earlier quoted context omitted.

That actually sounds like a really good idea. This is already implemented in the physical world (in a much less efficient way) in the form of “no spam” stickers and registrations. Is there a reason other than inertia for why it hasn’t been implemented?

The main problem is how do you authenticate the request as being legitimate? It's already possible to spoof headers and "FROM-IP" (in fact, major DDoS attacks use just this as a replay attack, spoof a DNS request as coming from 1.1.1.1 and get a much larger response sent TO 1.1.1.1 from wherever).

You can send back a reply with a token to confirm ban.

Re: The largest DDoS attack to date, peaking above 398M rps

#348
post #322

Earlier quoted context omitted.

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Why not attack a target that can actually be harmed? Are they afraid? It's not obvious what's the value of having the largest ineffective attack.

Why not roll a couple defenseless grannies in the streets for pocket change, rather than throw rocks at the cops and then get away unscathed?

One gets you more money in the short term. The other one gets you more street cred - which gets you more money in the long term.

Re: The largest DDoS attack to date, peaking above 398M rps

#349
post #260

Earlier quoted context omitted.

I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size. There is no need for any central authority and no need to maintain any lists.

And then that can be abused...

No, it cannot. It is well-thought.

Re: The largest DDoS attack to date, peaking above 398M rps

#350

Earlier quoted context omitted.

You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.

How can it protect from... botnets, where there are tens of thousands "someones"?

You can only ban packets coming to your IP. Botnet can only ban packets coming to its IP addresses.
Post reply on HN