Earlier quoted context omitted.
If this attack takes only 20,000 machines to orchestrate, how is it the "largest DDoS attack to date"? It was to my understanding that some botnets and organizations have placed far more than 20,000 machines under their control before or currently. Could you explain a bit better?
I think they're measuring "largest" by the number of requests per second.
The largest DDoS attack to date, peaking above 398M rps
471–480 of 487 posts
Re: The largest DDoS attack to date, peaking above 398M rps
#472Earlier quoted context omitted.
I think they're measuring "largest" by the number of requests per second.
But that's part of my question. If other botnets have previously been created with many more than 20,000 controlled machines, why has nobody else before orchestrated an attack with so many requests if it only requires 20,000 machines or so to pull off?
Re: The largest DDoS attack to date, peaking above 398M rps
#473Earlier quoted context omitted.
But that's part of my question. If other botnets have previously been created with many more than 20,000 controlled machines, why has nobody else before orchestrated an attack with so many requests if it only requires 20,000 machines or so to pull off?
This is exploiting a new technique. This technique wasn't known previously, or wasn't viable when HTTP/2 wasn't widespread. This technique is a ~100x multiplier on the impact any size botnet can have. A previous botnet might have needed 20,000,000 machines to achieve the same impact.
Re: The largest DDoS attack to date, peaking above 398M rps
#474Earlier quoted context omitted.
I don’t think either of those countries would attack US companies. Obviously I would suspect adversaries instead of allies
The USA sees all countries, even allies, as adversaries, and always has ... hence the deep paranoia the USA has, lack of trust, lies, coercion, and spying (the list is longer but time is limited).
Re: The largest DDoS attack to date, peaking above 398M rps
#475Earlier quoted context omitted.
20000 being modest really says a lot about the state of security on the Internet.
There are 5 billion people on the internet. This is 0.0004%. Even 2 million is only 0.04%. (this assumes that 1 person = 1 device; some people share devices, most people have more than one, e.g. I have a laptop and a router, many people also have a phone, a work laptop, and whatnot – the average is probably >1, maybe even >2)
And lots of devices are not even that, Internet of Shit garbage is well known for being botnet-central, servers running insecure services are good fodder (it's very common for vulnerabilities to be used not to exploit the machine itself, but to install C&C and leverage the machine into other attacks), ...
Re: The largest DDoS attack to date, peaking above 398M rps
#476Earlier quoted context omitted.
>> Most of the people who do this have a lot of technical skill but not a lot of opportunity to get paid for it based on where they live or the circumstances of their upbringing. LOL. No there are plenty of legitimate enterprises as well as opportunity to immigrate. Especially in tech. These guys are just criminals.
Not to condone the DDoS activities in the least, but that's just ignorance. Which prosperous country accepts evrn remotely as many legal immigrants as apply / would want to move there? And a lot of people / political parties are constantly lobbying for less immigration :-/
Re: The largest DDoS attack to date, peaking above 398M rps
#477Earlier quoted context omitted.
I've been on the receiving end of "Your" (dynamic) "IP has been blocked." I would greatly prefer not having my semi-randomized IP blocked because someone used it maliciously a year ago.
Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…
My personal want / solution would simply be "everything gets an IPV6, and IPV4 gets deprecated. Everything using IPV4 gets an algorithm slapped on top to covert it into IPV6.
Dynamic ips become a thing of the past.
But I realize that is significantly easier said than done. (Makes Minecraft servers easier to setup though)
Re: The largest DDoS attack to date, peaking above 398M rps
#478Earlier quoted context omitted.
No, it cannot. It is well-thought.
There are 2^128 ipv6 addresses. If you store 1 bit (banned/unbanned) + a unix timestamp (ban expiration) for each of those IPs, that requires more storage space than exists many billion times over. To store such a block table you propose would require more memory for routers than any router has ever had and ever will have. An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv…
Re: The largest DDoS attack to date, peaking above 398M rps
#479Earlier quoted context omitted.
sure, It's no doubt an arms race. The prevalance of websites going down due to scaling issues feels like order of magnitude less than it was 20 years ago though. Purely anecdotal with no real data to back that up.
Because the majority of sites run on/behind: - AWS - Cloudflare - Azure - GCP - Great Firewall of China Maybe there was some truth about "the world market for maybe five computers", after all...