Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

201–210 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#201
post #184

Earlier quoted context omitted.

And if someone invests in having >90% of the peers offer a malicious file and serve DHTs matching that file?

Torrent files are hashed, so it's exactly the same risk profile as the comment I was referring to. But generally hashing algorithms are collision-proof enough that what you're describing is basically impossible (requiring many years of compute time).

IIRC BitTorrent still uses SHA-1, which is becoming more problematic.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#202
post #60

> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?

Digital signing wouldn't defend you from a compromised build server.

Reproducible Builds and multiple distributed builders would though.

https://reproducible-builds.org/

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#204
post #182

Earlier quoted context omitted.

Or the law makes the problem smaller, by making the routers secure, and makes outcomes just, by penalizing the responsible companies.

ok, let's redo this: instead of routers it's an IoT device. The router protects the IoT device from direct access so it is secure from majority of attack vectors - now an IoT device provider gets their server compromised and hundreds of thousands of IoT devices are now bots in a botnet due to the ability to forcefully push a security update.

I understand the risk, but the existance of risks doesn't mean they outweigh the benefits. Everything has risks.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#205

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

Who is going to elect and oversee them? I don't want to be governed by China or Russia.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#206
post #143
post #98

This is what I don't get >The Aisuru DDoS botnet operates as a DDoS-for-hire service with restricted clientele; operators have reportedly implemented preventive measures to avoid attacking governmental, law enforcement, military, and other national security properties. Most observed Aisuru attacks to date appear to be related to online gaming. https://www.netscout.com/blog/asert/asert-threat-summary-ais... So why? Li…

What is even more interesting why attack Azure? It's not possible to extort anything from Microsoft, so what's the rationale?

> It's not possible to extort anything from Microsoft

lul wut?

https://www.businessinsider.com/trump-white-house-ballroom-d...

https://www.cnbc.com/2025/01/09/microsoft-contributes-1-mill...

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#207
post #180

Earlier quoted context omitted.

Ballpark math says you could sustain it for half an hour on Hetzner for $5k-$6k (only from 1500 IPs though), at least if your account didn't get banned first and you're halfway decent at network programming. I have no idea what a proper botnet like this costs though or how large the profit margins are.

Isn't the idea behind botnets that no one is paying for the bandwidth, besides the unsuspecting random people who have fallen victim to malware? I'd imagine the pricing is quite disconnected from the price of "legitimate" bandwidth. But I don't know in what direction.

Yeah I assume there's the initial startup cost of successfully managing to infect a large network of devices, and then the cost for any given use is likely "what customers will pay for it". If they are selecting out big money targets and focusing on gaming, I'm guessing the price isn't that high, but they also presumably know interesting a state actor in taking them down either by changing targets or bringing in enough money is bad for business.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#208
post #204

Earlier quoted context omitted.

ok, let's redo this: instead of routers it's an IoT device. The router protects the IoT device from direct access so it is secure from majority of attack vectors - now an IoT device provider gets their server compromised and hundreds of thousands of IoT devices are now bots in a botnet due to the ability to forcefully push a security update.

I understand the risk, but the existance of risks doesn't mean they outweigh the benefits. Everything has risks.

I don't think it does outweigh the benefits, the real benefits would be punishing or/and banning vendors that do not secure their devices since using laws such as "timely updates" just promotes them to include sloppy (insecure) implementations for pushing said updates just to do bare minimum to comply with the law.

relevant law here: EU Cyber Resilience Act (CRA).

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#209
post #190

Earlier quoted context omitted.

"Game servers" also doesn't just mean Timmy's Minecraft server. It's big commercial games. Final Fantasy XIV keeps getting hammered, likely Aisuru, off and on since at least September. https://na.finalfantasyxiv.com/lodestone/news/detail/6b56814...

For some scale, Final Fantasy XIV makes about $65 million in annual revenue (and decreasing).

According to their latest financial earnings on page 11 of https://www.hd.square-enix.com/eng/ir/library/pdf/25q4slides... they made 55.5 billion yen or about $357 million. So quite a bit more revenue than $65 million

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#210

I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.

It's national interest of China and Russia to see the West to fail. Why would they co-operate? They are willing to murder people, West and their own, so "law" enforcement means a bit different in international context.

Typical brainwashed view.

It is China's national interests to see a stable America that can continue to maintain the post WWII world order that benefited China so much for so long. Without the US, who is going to maintain peace in the middle east, Africa and other places? without such peace, how could China export its goods and services?

"West" != America.

Your claim also implies that China and Russia are operating on the same level. That is laughable at best - Russia is a failed rogue state with the economic size comparable only to a Chinese province, it is left behind in ALL modern techs and its military hardware are aging fast. It is the complete opposite of the path took by China.

Post reply on HN