Earlier quoted context omitted.
isn't JA4 also useless because it is so easy to spoof tls. For eg. cycletls for nodejs etc..
It will probably be useless one day. In practice, it is still useful today though not for this attack.
Understanding the recent DDoS attack against Read the Docs
41–50 of 74 posts
Re: Understanding the recent DDoS attack against Read the Docs
#42I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…
Re: Understanding the recent DDoS attack against Read the Docs
#43There’s an assumption that turning on Cloudflare’s “under attack” mode would mitigate the attack. Given how adaptive the rest of the attack was, I would be very curious to find out how it would approach that obstacle.
My assumption would be that it would drastically reduce the attack to be borderline irrelevant. I've never turned on Under Attack so somebody else may have more insight and the docs[1] don't describe precisely what happens besides a JS interstitial. I know that JS challenges, both interactive and non-interactive, can be solved by bots. I've seen it. However, I suspect that the challenges just get harder and harder un…
Re: Understanding the recent DDoS attack against Read the Docs
#44My naive take on a Cloudflare perspective wants to combine "three times is enemy action" with toddler-speed block dropping and manual clearance. What's the money reason this problem isn't handled at the ISP level?
I saw this quite a few years ago. It is possibly relevant. I don't know what, if anything, came of it since then.
Re: Understanding the recent DDoS attack against Read the Docs
#45I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…
Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I think it was in the GamerNexus investigation on the whole LG Tv spying on people IIRC.
Re: Understanding the recent DDoS attack against Read the Docs
#46I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…
I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort. Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I t…
Re: Understanding the recent DDoS attack against Read the Docs
#47Re: Understanding the recent DDoS attack against Read the Docs
#48Earlier quoted context omitted.
I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort. Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I t…
AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.
Re: Understanding the recent DDoS attack against Read the Docs
#49Earlier quoted context omitted.
I agree they they should, but that would be hard before, now in the IoT-hell where even your lightbulbs and internet-facing and capable of being proxies seems like a herculean effort. Pretty sure I saw an article on HN a few days ago about, in part, how a bunch on seemingly innocuous apps for smart tvs, stuff like screen savers and the like, all ran proxy servers (in the users residential address) under the hood. I t…
AFAIK most people's contract with their ISP includes fine print that forbids a lot of the nasty things these IoT and "smart" devices do.
Re: Understanding the recent DDoS attack against Read the Docs
#50I'd like to see more of a legal response. First, find out who's on the other end of a few hundred IP addresses. Start with ones in the US. Sue for damages. Use discovery to find out what's on the other end. Sue the maker of that device. If it turns out to be an appliance or smart TV, it may be possible to consolidate cases into one case against the manufacturer. Criminal negligence, tort interference with contract, h…