Earlier quoted context omitted.
Sure, I’ll spill the beans. Some people think it’s related to Gaza or Ukraine but it’s not. We just really don’t like Google, we are trying to shut it down so we can bring back Altavista.
I think the plan went horribly wrong, everybody started using Bing again!
The largest DDoS attack to date, peaking above 398M rps
431–440 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#432Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…
Why do you think Finland or Spain might attack USA companies?
Re: The largest DDoS attack to date, peaking above 398M rps
#433Earlier quoted context omitted.
Step 1: Put message on blockchain beforehand with exact date/time and characteristics of DDoS Step 2: Execute DDoS Step 3: Prove to others you are responsible by using private key
There’s (as ever) no need for a blockchain, people do this with twitter and sha256 all the time. Hash the message, post the hash, wait for prediction to happen, post the full message.
Re: The largest DDoS attack to date, peaking above 398M rps
#434Earlier quoted context omitted.
Made me wonder - if Google wasn't there and Altavista was the incumbent, would it be any different, or was the enshittification of search inevitable?
>... or was the enshittification of search inevitable? My bet is on the latter. Enshitification is a direct product of greed. No crafts person or creator I know of goes into something they enjoy creating with the intent to make it this monstrosity of money extraction. Most creators have a drive for their creation to be shared and experienced by many. Yes, you may want to get a reward in the process and for some creat…
The drive to create the thing comes from sincere enthusiasm + excitement that simply don’t leave me alone.
Shifting the thing’s purpose from the original one that filled me with enthusiasm to the purpose of simply extracting money, corrupts its original purpose.
I call this corruption.
it is my observation that one kind of people create, and another kind of people corrupt.
Unfortunately the economic system we have accepted as normal, leans toward corruption and extraction.
Re: The largest DDoS attack to date, peaking above 398M rps
#435At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?
This kind of attack is nothing like the actual DDoS attacks, but it's a lot more common in my experience, but also relatively easy to mitigate with something like Cloudflare or Akamai (which is what I'd recommend to my customers).
Re: The largest DDoS attack to date, peaking above 398M rps
#436Earlier quoted context omitted.
There should be a protocol to block traffic on the upstream provider. So if someone from 1.2.3.4 sends lots of traffic at you, you send a special packet to 1.2.3.4 and all upstream providers (including the provider that serves 1.2.0.0/16), that see this packet block traffic from that IP address directed at you. Of course, the packet should allow blocking not only a single address, but a whole network, for example, 1.…
I just imagined this: isp's could make a isp.com?target=yourwebsite.org/fromisp [slow] redirecting url. If you receive unusual amounts of requests from the isp you redirect it though their website. They can then ignore it until their server melts (which takes care of the problem) or take honorable action if one of their customers is compromised. The S stands for service after all.
Re: The largest DDoS attack to date, peaking above 398M rps
#437Earlier quoted context omitted.
Nah it's even better because they're considered capable defenders so it's harder. What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities. Unless this is marketing for Google Cloud?
> Unless this is marketing for Google Cloud? If you read the article, there are plenty of marketing remarks in there to get you to use Google Cloud
Re: The largest DDoS attack to date, peaking above 398M rps
#438Earlier quoted context omitted.
You missed the no WiFi part. At least enable customers to send their money!
That’s shitty, but if that’s all enshittification means then it’s ten extra letters for nothing. Disneyland is not a “platform”, it doesn’t go through the enshittification process.
Re: The largest DDoS attack to date, peaking above 398M rps
#439Earlier quoted context omitted.
Depends, but there seems to be a multiplier effect at play with this attack. A single client request may result in 100x the work for the server. More details here: https://cloud.google.com/blog/products/identity-security/how...
This is sort of an aside based on something I read in the article but does anyone know why the RFC guidelines say that you should first send an informational GOAWAY that does not prevent opening new streams when gracefully closing a connection? They point out in the article that it's a better practice to immediately limit stream creation when you detect abuse - not wait for a round trip to complete first. I'm sure th…
After all you could say any client ignoring a GOAWAY is either bugged or malicious but certainly not until you get confirmation they go it.
Re: The largest DDoS attack to date, peaking above 398M rps
#440Earlier quoted context omitted.
Have you tried that yourself? Especially as someone who has the skills but doesn't speak the language. I know people who can't relocate because of communication issues and/or cultural differences. No they aren't criminals, but they are definitely underpaid compared to those who managed to relocate.
If they operate botnets, I think it's fair to call them criminals