Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

151–160 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#152
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

A game I work with got hit by ~10Tbps earlier this year. It's likely because someone got mad they were banned.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#153
post #96
post #72

Earlier quoted context omitted.

Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…

Bit-Reproducible infrastructure could also result in some of the wildest build distribution architectures if you think about it. You could publish sources and have people register like in APT mirrors to provide builds, and at the end of the day, the build from the largest bit-equal group is published. I do see the Tor-Issue - a botnet or a well-supplied malicious actor could just flood it. And if you flip it - if you…

Sounds overly complex and completely unnecessary, like some kind of blockchain/defi scheme shoehorned onto distributed builds.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#154
post #120

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

If we were all running IPv6, we could just block this crap. But here we are in 2025 still running IPv4 with CGNAT, so we can't.

What difference would it make?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#155

Earlier quoted context omitted.

It's national interest of China and Russia to see the West to fail. Why would they co-operate? They are willing to murder people, West and their own, so "law" enforcement means a bit different in international context.

It is absolutely not in China's interest to see the West fail. This is propaganda

China (or at least the CCP, I find the equivocation of the CCP with the country disagreeable) has had the desire or even need to get revenge for their "century of humiliation" for a long time.

They have a fundamentally different government and social model, basically a one person dictatorship that feels the need to micromanage and control their populace.

They absolutely love seeing democracy and businesses associated with it fail because it reinforces their perspective of the CCP model being superior and thus strengthens their perceived legitimacy (or even inevitability) of CCP control over China.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#156
post #72

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…

This exchange is somewhat hilarious. Oh how on earth do we keep things safe and secure if everyone can see the code and verify what it does! Who would keep us safe if we turn our backs to unverifiable, unvetted, unprofitable security fixes, by for-profit companies!

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#157
post #57

Earlier quoted context omitted.

As always, hundreds watch the open repositories, maybe one watches a company's build servers, if they're lucky. :-)

Hundreds watch, but how closely? Plenty of stories of fairly major projects having evil commits snuck in that remain for months.

Name a few.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#158

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

I don't follow. > run an army of security people Do you think these private companies do this? They don't. They pay as little as humanly possible to cover their ass. Botnets comprised of compromised routers is common and commercial/consumer routers are a far juicer target than openwrt.

> They pay as little as humanly possible to cover their ass.

It’s probably helpful that open source teams aren’t hampered by standards and 20 year outdated audit processes either.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#159

Earlier quoted context omitted.

It is absolutely not in China's interest to see the West fail. This is propaganda

China (or at least the CCP, I find the equivocation of the CCP with the country disagreeable) has had the desire or even need to get revenge for their "century of humiliation" for a long time. They have a fundamentally different government and social model, basically a one person dictatorship that feels the need to micromanage and control their populace. They absolutely love seeing democracy and businesses associated…

A rivalry, wanting to score points, wanting to gain standing at the expense of another, are all things that do not have much to do with wanting your opponent to collapse

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#160

IoT is just wave after wave of unsecure devices. There's gotta be a better way.

fun fact, part of the reason this botnet exists is because europe required the ability to install security updates unattended that you cannot disable and they compromised one of the servers that had the capability to push these updates compromising hundreds of thousands of routers.

That's just not true. I'm in Europe and all of my routers allow me to disable unattended updates and most don't enable it by default.
Post reply on HN