Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

401–410 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#401

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

I mean you can ask them https://t.me/s/noname05716eng chat of NoName group skids doing some DDOSing, they pool their bots by community of like-minded people (Russians supporting current government, murder rape etc. you know)

Re: The largest DDoS attack to date, peaking above 398M rps

#402

Earlier quoted context omitted.

20 years ago if a blog or website ended up on slashdot/digg/whatever there was a good chance it was going down. Scalable websites are a commodity today

That goes both ways. What was the price then to get a botnet with 10k nodes making 1k requests / second? What is the price today?

For the website or for the use of the botnet?

Re: The largest DDoS attack to date, peaking above 398M rps

#403

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

I'm just guessing here but it could easily be stock market manipulation

Re: The largest DDoS attack to date, peaking above 398M rps

#404

Earlier quoted context omitted.

It is only criminal if the botnets are used to steal something. DDoS-in just for fun is at most an annoyance.

Yeah, hospitals can't stand that kind of thing...

They should have better IT.

Blaming it on the people that knock them off will not make improve the situation.

Re: The largest DDoS attack to date, peaking above 398M rps

#405

Earlier quoted context omitted.

You can (or could, my information is old) pay botnet owners a few hundred bucks to disrupt the servers of people you don't like. An example would be ruining a match for a competing game clan. There's a suprising amount of this kind of petty bullshit going on in the world. With the Mirai botnet, some of the creators had a DDOS mitigation company as well: they'd sell one party the weapon, and sell another party the def…

Disruption is part of it for sure, but often big, aggressive DDoS come hand-in-hand with other attacks. Seen it happen with big DDoS on clients. Furaffinity, one of the larger furry webistes, and a constant drama magnet, was a client at a former job. They got DDoS'd hard, and in between scripted DDoS hits they slammed the hell out of their web applications to get vulns and do credential stuffing. As in blast em, ligh…

> in between scripted DDoS hits they slammed the hell out of their web applications

I've heard this before, but I still don't understand what purpose the DDoS serves here. Distraction, so the actual attack drowns in the noise?

Re: The largest DDoS attack to date, peaking above 398M rps

#406

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

Yes, what the OP is saying is related to one of the paradoxes of security/defence, i.e. the fact that the more one increases its defences (like Google is doing) then the more said increase of defences also pushes one's adversary to increase its offence capabilities. Which is to say that Google playing it safer and safer actually causes their potential adversaries to become stronger and stronger. You can see those par…

It's the opposite, the number of rocket was growing and hence the Iron Dome was developed. The Israelis saw the writing on the wall and acted accordingly. The laser system will be operational soon and then it will cost 1$ per shot.

Re: The largest DDoS attack to date, peaking above 398M rps

#407

Earlier quoted context omitted.

Yes, what the OP is saying is related to one of the paradoxes of security/defence, i.e. the fact that the more one increases its defences (like Google is doing) then the more said increase of defences also pushes one's adversary to increase its offence capabilities. Which is to say that Google playing it safer and safer actually causes their potential adversaries to become stronger and stronger. You can see those par…

It's the opposite, the number of rocket was growing and hence the Iron Dome was developed. The Israelis saw the writing on the wall and acted accordingly. The laser system will be operational soon and then it will cost 1$ per shot.

Unless it's cloudy outside.

Re: The largest DDoS attack to date, peaking above 398M rps

#409

Earlier quoted context omitted.

I've been working on anti-DDOS off and on for 20 years now. The answer is sometimes government actors, but oftentimes scammers in Eastern Europe. They do these big attacks for street cred amongst the botting community. They then use their street cred to get paid by less scrupulous actors to attack their rivals. Sometimes the people paying are governments, sometimes just shady companies. For example last year there wa…

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

They're not attacking Google, per se. Just the Google Cloud platform that hosts govt sites, Discord channels, gaming servers, etc.

Re: The largest DDoS attack to date, peaking above 398M rps

#410

At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?

We had a similar issue and assumed it was script kiddies having fun. Turns out someone (raises hand) wrote a really bad microservice who's inefficient queries sometimes triggered all our alerts.

Hehehe, entirely unsurprising :)
Post reply on HN