Live data from Hacker News

A DDoS in Asia Pacific

telegram.org

21–30 of 46 posts

Re: A DDoS in Asia Pacific

#21

China is doing a mass arrestment*1 of 100+ human right lawyers last weekend, in the same times as DDoS start and end, and there's a news from China's official news agent indicate that Telegram is the main secret contacting tool that human right lawyers used. Some people think it's China who attack Telegram, to avoid the lawyers to warning each other for the arrestment. 1) https://www.facebook.com/chrlcg/photos/a.1571…

Interesting.

We know from this year's GitHub attack that (a) China is willing to DDoS foreign internet services, and (b) China is able to enlist foreign traffic to carry out the actual attack.

So it wouldn't be surprising if China DDoSed Telegram and made it look like the attack came from South Korea.

Re: A DDoS in Asia Pacific

#22
post #16
post #13

Earlier quoted context omitted.

An attack sponsored by the South Korean government sounds unlikely. South Korea isn't exactly a bastion of free speech, but it isn't China, either. If by "nationalists" you mean the notorious online community known as ilbe , that's definitely possible. They're a weird amalgam of political ideology and lulz, basically the neocon counterpart to /b/. But it could just as well have been a shady competitor who got pissed…

The linked post seems to point blame at LINE. Stickers (large animated emoticons) are a major source of revenue for LINE; if Telegram were to offer it for free then it will really hit their bottom line.

The majority of LINE users are in Japan and Taiwan. It's the biggest program in both of those countries. LINE is owned by a Korean company, though.

Re: A DDoS in Asia Pacific

#23
post #13

Earlier quoted context omitted.

Could this be a state-sponsored attack? Or an attack by nationalists who are against people bypassing the anti-everything-speech-related laws?

An attack sponsored by the South Korean government sounds unlikely. South Korea isn't exactly a bastion of free speech, but it isn't China, either. If by "nationalists" you mean the notorious online community known as ilbe , that's definitely possible. They're a weird amalgam of political ideology and lulz, basically the neocon counterpart to /b/. But it could just as well have been a shady competitor who got pissed…

Interesting, I hadn't heard of "iibe". Here's an article I found in case anyone else is interested: http://www.koreabang.com/2012/features/netizen-explains-root...

Re: A DDoS in Asia Pacific

#24
post #15
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

he didn't back anything he said. as much as i like Telegram, at least show some proof when you put such strong statement.

He just replied with more info on his claim: https://twitter.com/durov/status/620538556134653952

Re: A DDoS in Asia Pacific

#25
This is most interesting...

  The garbage traffic came from about a hundred thousand
  infected servers, most noticeably, in LeaseWeb B.V.,
  Hetzner Online AG, PlusServer AG, NFOrce Entertainment
  BV, Amazon and Comcast networks. That said, the attack
  was distributed evenly across thousands of hosts and none
  contributed more than 5% of the total volume.
I used to host a lot with Hetzner, and while quite expensive, they mostly responded to these kinds of things very quickly and with a certain level of technical competence (which definitely cannot be said of every hoster). Also, I'm quite surprised to not see OVH in there, as their network has a kind of "reputation" for these things...

  Fighting back would‘ve been a little easier, if the abuse
  departments in most of the mentioned companies didn’t
  process requests 9-5, Mon-Fri only. (Hours more befitting
  a scuba-diving shop in Vatican.)
Business as usual I would say...although I don't scuba-dive...

Edit: formatting

Re: A DDoS in Asia Pacific

#26
post #25

This is most interesting... The garbage traffic came from about a hundred thousand infected servers, most noticeably, in LeaseWeb B.V., Hetzner Online AG, PlusServer AG, NFOrce Entertainment BV, Amazon and Comcast networks. That said, the attack was distributed evenly across thousands of hosts and none contributed more than 5% of the total volume. I used to host a lot with Hetzner, and while quite expensive, they mos…

Did you mean to say that they are quite UNexpensive? (because they are)

Re: A DDoS in Asia Pacific

#27
post #6
post #3

I knew it would be S.Korea. The company I used to work for, at the time I left, was dealing with some particularly spiteful individuals from S.Korea who have been DDoSing their gaming platform and their separate video host. This was happening off and on for about 12 months. Interestingly enough, each attack was committed by completely different individual and were unrelated. In one attack where the guy was caught (I…

This more or less reflects my stance on SK too. I ran a reasonably large APAC/SEA esports-related site for a while, competing sites in SK often attempted to attack it (and outright told me as such, to get out of korea). It's strange and I really have no idea why.

We had a 9Gbps attack from SK earlier in the year. I have no idea why we were targeted, but my best guess is that a user in SK got upset at some user-generated content and decided to DDoS the site rather than report it to us. Weird.

Anyway, we decided to move to OVH, and haven't had any problem since. We did get an email about an attack being mitigated a few months ago (which didn't cause any outage at all), and since then the trolls have realised that we can't be DDoSed any more :)

Re: A DDoS in Asia Pacific

#28
post #10

According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784

They've been having DDoS attacks since September last year, so it seems unlikely that it's caused by a recent event. I'm surprised they haven't done anything about it before now.

Re: A DDoS in Asia Pacific

#29
Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).

Re: A DDoS in Asia Pacific

#30

Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).

What makes you think OVH could cope with a 200 Gbps DoS attack of this nature? A quick look at their services indicates they don't mention what kind of attacks they defend against, and SYN floods are some of the hardest to defend against.
Post reply on HN