I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.
Azure hit by 15 Tbps DDoS attack using 500k IP addresses
151–160 of 318 posts
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#152This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#153Earlier quoted context omitted.
Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…
Bit-Reproducible infrastructure could also result in some of the wildest build distribution architectures if you think about it. You could publish sources and have people register like in APT mirrors to provide builds, and at the end of the day, the build from the largest bit-equal group is published. I do see the Tor-Issue - a botnet or a well-supplied malicious actor could just flood it. And if you flip it - if you…
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#154I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.
If we were all running IPv6, we could just block this crap. But here we are in 2025 still running IPv4 with CGNAT, so we can't.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#155Earlier quoted context omitted.
It's national interest of China and Russia to see the West to fail. Why would they co-operate? They are willing to murder people, West and their own, so "law" enforcement means a bit different in international context.
It is absolutely not in China's interest to see the West fail. This is propaganda
They have a fundamentally different government and social model, basically a one person dictatorship that feels the need to micromanage and control their populace.
They absolutely love seeing democracy and businesses associated with it fail because it reinforces their perspective of the CCP model being superior and thus strengthens their perceived legitimacy (or even inevitability) of CCP control over China.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#156> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?
Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#157Earlier quoted context omitted.
As always, hundreds watch the open repositories, maybe one watches a company's build servers, if they're lucky. :-)
Hundreds watch, but how closely? Plenty of stories of fairly major projects having evil commits snuck in that remain for months.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#158> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?
I don't follow. > run an army of security people Do you think these private companies do this? They don't. They pay as little as humanly possible to cover their ass. Botnets comprised of compromised routers is common and commercial/consumer routers are a far juicer target than openwrt.
It’s probably helpful that open source teams aren’t hampered by standards and 20 year outdated audit processes either.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#159Earlier quoted context omitted.
It is absolutely not in China's interest to see the West fail. This is propaganda
China (or at least the CCP, I find the equivocation of the CCP with the country disagreeable) has had the desire or even need to get revenge for their "century of humiliation" for a long time. They have a fundamentally different government and social model, basically a one person dictatorship that feels the need to micromanage and control their populace. They absolutely love seeing democracy and businesses associated…
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#160IoT is just wave after wave of unsecure devices. There's gotta be a better way.
fun fact, part of the reason this botnet exists is because europe required the ability to install security updates unattended that you cannot disable and they compromised one of the servers that had the capability to push these updates compromising hundreds of thousands of routers.