Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

431–440 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#431

Earlier quoted context omitted.

Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.

I think the plan went horribly wrong, everybody started using Bing again!

Bing aka DDG as if...

Re: The largest DDoS attack to date, peaking above 398M rps

#432

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

Why do you think Finland or Spain might attack USA companies?

I don’t think either of those countries would attack US companies. Obviously I would suspect adversaries instead of allies

Re: The largest DDoS attack to date, peaking above 398M rps

#433
post #424
post #342

Earlier quoted context omitted.

Step 1: Put message on blockchain beforehand with exact date/time and characteristics of DDoS Step 2: Execute DDoS Step 3: Prove to others you are responsible by using private key

There’s (as ever) no need for a blockchain, people do this with twitter and sha256 all the time. Hash the message, post the hash, wait for prediction to happen, post the full message.

Any examples of major predictions verified in this way?

Re: The largest DDoS attack to date, peaking above 398M rps

#434

Earlier quoted context omitted.

Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?

>... or was the enshittification of search inevitable? My bet is on the latter. Enshitification is a direct product of greed. No crafts person or creator I know of goes into something they enjoy creating with the intent to make it this monstrosity of money extraction. Most creators have a drive for their creation to be shared and experienced by many. Yes, you may want to get a reward in the process and for some creat…

This is beautifully written, thank you. As a creator, my money ambitions fit between “does this thing provide enough value to pay for itself” and “could this provide enough value to pay for my needs”.

The drive to create the thing comes from sincere enthusiasm + excitement that simply don’t leave me alone.

Shifting the thing’s purpose from the original one that filled me with enthusiasm to the purpose of simply extracting money, corrupts its original purpose.

I call this corruption.

it is my observation that one kind of people create, and another kind of people corrupt.

Unfortunately the economic system we have accepted as normal, leans toward corruption and extraction.

Re: The largest DDoS attack to date, peaking above 398M rps

#435

At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?

I had a customer that was getting DDoSed by competitors, the competitors likely didn't know they were doing a DDoS, as they were aggressively scraping product listings but just doing so without any delay/rate limiting and it effectively DDoSed them. They weren't trying to make the target site slower, but were trying to get data at a rate that made the target's servers uneconomical to their actual paying customers.

This kind of attack is nothing like the actual DDoS attacks, but it's a lot more common in my experience, but also relatively easy to mitigate with something like Cloudflare or Akamai (which is what I'd recommend to my customers).

Re: The largest DDoS attack to date, peaking above 398M rps

#436
post #133

Earlier quoted context omitted.

There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…

I just imagined this: isp's could make a isp.com?target=yourwebsite.org/fromisp [slow] redirecting url. If you receive unusual amounts of requests from the isp you redirect it though their website. They can then ignore it until their server melts (which takes care of the problem) or take honorable action if one of their customers is compromised. The S stands for service after all.

It appears you don’t understand DDoS at all. There aren’t humans sitting behind browsers or scripts using browser automation software. No one cares about less respects your “redirect” because no one’s reading your response. Most of the time the attacks aren’t even HTTP, they are just packet floods.

Re: The largest DDoS attack to date, peaking above 398M rps

#437

Earlier quoted context omitted.

Nah it's even better because they're considered capable defenders so it's harder. What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities. Unless this is marketing for Google Cloud?

> Unless this is marketing for Google Cloud? If you read the article, there are plenty of marketing remarks in there to get you to use Google Cloud

CDN is the ultimate solution for DDoS, so any report about DDoS finally become an ad for CDN

Re: The largest DDoS attack to date, peaking above 398M rps

#438
post #314

Earlier quoted context omitted.

You missed the no WiFi part. At least enable customers to send their money!

That’s shitty, but if that’s all enshittification means then it’s ten extra letters for nothing. Disneyland is not a “platform”, it doesn’t go through the enshittification process.

Arguably everything driven by capitalism is geared towards enshitification. Maximum extraction for minimal effort is a hard paradigm to beat

Re: The largest DDoS attack to date, peaking above 398M rps

#439
post #307

Earlier quoted context omitted.

Depends, but there seems to be a multiplier effect at play with this attack. A single client request may result in 100x the work for the server. More details here: https://cloud.google.com/blog/products/identity-security/how...

This is sort of an aside based on something I read in the article but does anyone know why the RFC guidelines say that you should first send an informational GOAWAY that does not prevent opening new streams when gracefully closing a connection? They point out in the article that it's a better practice to immediately limit stream creation when you detect abuse - not wait for a round trip to complete first. I'm sure th…

How do you act on a GOAWAY you haven't received and allowing the server to unilaterally stop supporting things can lead to weird edge cases.

After all you could say any client ignoring a GOAWAY is either bugged or malicious but certainly not until you get confirmation they go it.

Re: The largest DDoS attack to date, peaking above 398M rps

#440
post #335

Earlier quoted context omitted.

Have you tried that yourself? Especially as someone who has the skills but doesn't speak the language. I know people who can't relocate because of communication issues and/or cultural differences. No they aren't criminals, but they are definitely underpaid compared to those who managed to relocate.

If they operate botnets, I think it's fair to call them criminals

probably, or if they aren’t directly criminals they’re probably facilitating criminals. but if you were very particular about it you could in theory set up in a country which doesn’t have treaties with any of the countries in which the victims operate.
Post reply on HN