398M rps means a request every 2.5ns. Most likely the figure is incorrect, or at least misleading.
The largest DDoS attack to date, peaking above 398M rps
341–350 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#342Earlier quoted context omitted.
PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.
Anyone can claim that, there's no link to a specific actor
Step 2: Execute DDoS
Step 3: Prove to others you are responsible by using private key
Re: The largest DDoS attack to date, peaking above 398M rps
#343Earlier quoted context omitted.
Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.
I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.
Re: The largest DDoS attack to date, peaking above 398M rps
#344Earlier quoted context omitted.
I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.
Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…
I don't even want to think about the ramifications for small and medium sized businesses. Realistically, how much would it cost to be able to completely destroy a local competitor by paying someone to orchestrate a few events in succession.
Re: The largest DDoS attack to date, peaking above 398M rps
#345The novel HTTP/2 'Rapid Reset' DDoS attack - https://news.ycombinator.com/item?id=37830987
HTTP/2 Zero-Day Vulnerability Results in Record-Breaking DDoS Attacks - https://news.ycombinator.com/item?id=37830998
Re: The largest DDoS attack to date, peaking above 398M rps
#346Re: The largest DDoS attack to date, peaking above 398M rps
#347Earlier quoted context omitted.
That actually sounds like a really good idea. This is already implemented in the physical world (in a much less efficient way) in the form of “no spam” stickers and registrations. Is there a reason other than inertia for why it hasn’t been implemented?
The main problem is how do you authenticate the request as being legitimate? It's already possible to spoof headers and "FROM-IP" (in fact, major DDoS attacks use just this as a replay attack, spoof a DNS request as coming from 1.1.1.1 and get a much larger response sent TO 1.1.1.1 from wherever).
Re: The largest DDoS attack to date, peaking above 398M rps
#348Earlier quoted context omitted.
PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.
Why not attack a target that can actually be harmed? Are they afraid? It's not obvious what's the value of having the largest ineffective attack.
One gets you more money in the short term. The other one gets you more street cred - which gets you more money in the long term.
Re: The largest DDoS attack to date, peaking above 398M rps
#349Earlier quoted context omitted.
I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size. There is no need for any central authority and no need to maintain any lists.
And then that can be abused...
Re: The largest DDoS attack to date, peaking above 398M rps
#350Earlier quoted context omitted.
You can only block access to your IP address, so you can ban someone from sending packets to you but not to anyone else. My proposal is well-thought and doesn't require any lists like Spamhaus that have vague policies for inclusion and charge money for removing. My proposal doesn't have any potential for misuse.
How can it protect from... botnets, where there are tens of thousands "someones"?