Live data from Hacker News

A DDoS in Asia Pacific

telegram.org

11–20 of 46 posts

Re: A DDoS in Asia Pacific

#11
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

LINE is a Japanese company IIRC.

Re: A DDoS in Asia Pacific

#12
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

LINE is a Japanese company IIRC.

It is a subsidiary of Naver, the largest (and politically well-connected) portal in Korea.

Re: A DDoS in Asia Pacific

#13
post #3

I knew it would be S.Korea. The company I used to work for, at the time I left, was dealing with some particularly spiteful individuals from S.Korea who have been DDoSing their gaming platform and their separate video host. This was happening off and on for about 12 months. Interestingly enough, each attack was committed by completely different individual and were unrelated. In one attack where the guy was caught (I…

Could this be a state-sponsored attack? Or an attack by nationalists who are against people bypassing the anti-everything-speech-related laws?

An attack sponsored by the South Korean government sounds unlikely. South Korea isn't exactly a bastion of free speech, but it isn't China, either.

If by "nationalists" you mean the notorious online community known as ilbe, that's definitely possible. They're a weird amalgam of political ideology and lulz, basically the neocon counterpart to /b/.

But it could just as well have been a shady competitor who got pissed off with Telegram for whatever reason. The social networking market in Korea is cutthroat. Almost everyone treats it as a zero-sum game where you have to destroy all the others in order to succeed. Maybe this competitor was planning to launch what it considered a killer feature and Telegram launched it first. Stickers?

Re: A DDoS in Asia Pacific

#14
post #2

200Gbps (if true) seems very high for a non reflection attack.

This tsunami TCP SYN attack uses 1000 byte SYN packets apparently. A good countermeasure for these would be rejection of all large SYN packets. Verisign DDoS protection services claim that they can withstand 2Tbps attacks of most types.

Re: A DDoS in Asia Pacific

#15
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

he didn't back anything he said. as much as i like Telegram, at least show some proof when you put such strong statement.

Re: A DDoS in Asia Pacific

#16
post #13

Earlier quoted context omitted.

Could this be a state-sponsored attack? Or an attack by nationalists who are against people bypassing the anti-everything-speech-related laws?

An attack sponsored by the South Korean government sounds unlikely. South Korea isn't exactly a bastion of free speech, but it isn't China, either. If by "nationalists" you mean the notorious online community known as ilbe , that's definitely possible. They're a weird amalgam of political ideology and lulz, basically the neocon counterpart to /b/. But it could just as well have been a shady competitor who got pissed…

The linked post seems to point blame at LINE. Stickers (large animated emoticons) are a major source of revenue for LINE; if Telegram were to offer it for free then it will really hit their bottom line.

Re: A DDoS in Asia Pacific

#17
China is doing a mass arrestment*1 of 100+ human right lawyers last weekend, in the same times as DDoS start and end, and there's a news from China's official news agent indicate that Telegram is the main secret contacting tool that human right lawyers used.

Some people think it's China who attack Telegram, to avoid the lawyers to warning each other for the arrestment.

1) https://www.facebook.com/chrlcg/photos/a.1571958406350448.10...

2) http://news.xinhuanet.com/politics/2015-07/11/c_128010249.ht...

Re: A DDoS in Asia Pacific

#18
I got hit by two of these (1/27 to Feb 4th and 6/4 to 6/22), and they were relentless. It was difficult to know where the attack originated because many proxies were involved - most inside the USA). We only managed a 62% uptime during the whole affair, many customers were upset, and it really hurt business. We ended up refunding everyone for the month and sending out a huge apology, for which many customers were understanding. Still, it hurt our business dramatically.

Re: A DDoS in Asia Pacific

#19
post #14
post #2

200Gbps (if true) seems very high for a non reflection attack.

This tsunami TCP SYN attack uses 1000 byte SYN packets apparently. A good countermeasure for these would be rejection of all large SYN packets. Verisign DDoS protection services claim that they can withstand 2Tbps attacks of most types.

Unfortunately this would break TCP Fast Open, which transmits data with the initial SYN.

Re: A DDoS in Asia Pacific

#20
post #19
post #14

Earlier quoted context omitted.

This tsunami TCP SYN attack uses 1000 byte SYN packets apparently. A good countermeasure for these would be rejection of all large SYN packets. Verisign DDoS protection services claim that they can withstand 2Tbps attacks of most types.

Unfortunately this would break TCP Fast Open, which transmits data with the initial SYN.

Would a client that supports TCP Fast Open then fallback to the standard 3-way handshake once it's SYNs timed out?
Post reply on HN