Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

251–260 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#251

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution That’s not a fair point. We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of pok…

>There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago

Yes, you're 100% correct. Back in the day when the main bot net activity was spam if you were infected and you started sending TB of spam the ISP would first block your outgoing smtp. If they kept getting complaints in a week or two they'd cut you off.

I remember 30 years ago when most people were on dialup, I was fortunate enough to have 128kB SDSL. As a relatively clueless kid I decided to portscan an IP range belonging to a mobile service company. Few days later my dad got a phone call saying their IDS flagged it and "don't do it or we'll cancel your service". For a port scan of few public IPs no less!

ISPs could definitely put a stop to 99% of these botnets, but until they see some ROI, why would they bother?

Re: The largest DDoS attack to date, peaking above 398M rps

#253

Earlier quoted context omitted.

> Let's go back to username and password. 2FA forces scammers to up their game. Let's do it. It works for the website you're using right now. 2FA was in large part motivated by limiting bot accounts and getting customers phone number. I can't imagine how much productivity the economy loses every day due to 2FA.

Is this sarcasm? If not please provide some more details on why you think "2FA was in large part motivated by limiting bot accounts and getting customers phone number". I never used a phone number for 2fa. Mostly TOTP. Bots could do that too. I don't see the connection. >I can't imagine how much productivity the economy loses every day due to 2FA. Is it really that much? Every few days I have to enter a 6 digit numbe…

While I don't take starcraft2wol's theory seriously, there are a bunch of services that have made phone numbers essentially mandatory. They claim this is to "protect your account".

You sign up for a Skype account or Twitter account and decline to give your phone number, instead choosing a different form of 2FA? In my experience your account will be blocked for 'suspicious activity' even if you have literally no activity.

Re: The largest DDoS attack to date, peaking above 398M rps

#254
post #38

Earlier quoted context omitted.

The only answer is publicly-resourced protection and it's not that weird when you think about it. My apartment has a basic lock that any locksmith can undo and I'm safe because of my community and government protection (police, mental healthcare, justice system, etc...). Seems like the same logic should apply to my website or other digital property.

ISPs will gladly quarantine/rate limit folks for pirating stuff, why don't they use those tools to combat botnets? Though I could see this leading to a slippery slope of remote attestation for internet access.

> why don't they use those tools to combat botnets?

Because they probably don't care.

Re: The largest DDoS attack to date, peaking above 398M rps

#255

Earlier quoted context omitted.

Yes, but currently that has zero consequences. Say you infect 500.000 Windows XP machines or consumer routers, the owners of those devices isn't going to be informed, nor is their ISPs. In many cases the manufacturer of those devices also aren't going to provide security update, but those probably wasn't going to be applied anyway.

Are you positive that "tell nobody" is the mitigation strategy that Google used here? They could have easily asked router vendors to patch their devices, asked ISPs to blackhole those customers until they're patched, etc.

Patch what though? They know that they're getting hit with unprecedented traffic, not how those computers were infected.

Re: The largest DDoS attack to date, peaking above 398M rps

#256
post #14

The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet. It forces botnets to up their game and for websites the only solutions available are to pay Google, Amazon or Cloudflare a protection tax. I honestly don't see any other options, but I'd really wish for them to come through some community coordinated list of botnet infected IPs or something.

> The fact that large cloud providers can handle huge DDoS attacks I think in the long run leads to a worse internet

Don't agree.

> the only solutions available are to pay Google, Amazon or Cloudflare a protection tax.

It's not.

> come through some community coordinated list of botnet infected IPs

How would that help?

Re: The largest DDoS attack to date, peaking above 398M rps

#257

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

For example a certain group decides to short on a share. The DDOS the company and "leak" it to the press. The bad press negatively impacts the share price. At least this was the way some time ago when I had to deal with such attacks.

Re: The largest DDoS attack to date, peaking above 398M rps

#258

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

For a recent and similar attack at scale, the authors of the botnet software were from an American security company who sold DDOS mitigation solutions (https://en.wikipedia.org/wiki/Mirai_(malware)).

Re: The largest DDoS attack to date, peaking above 398M rps

#259
post #250

Earlier quoted context omitted.

PR. Attack Google or cloudflare. Wait for them to publish a blog post about the biggest attack ever seen, then tell potential customers of your botnet that you can launch a bigger attack than anyone else and point to the above blog post.

Anyone can claim that, there's no link to a specific actor

I'm guessing you would do this in advance - "pay attention to tech news next week - our botnet will unleash hell"

Re: The largest DDoS attack to date, peaking above 398M rps

#260

Earlier quoted context omitted.

Why don't we just require major providers to provide a realtime list of IPs that are attacking so that we can drop them in a block list with an expiration date of a month or so. If your computer is infected, I don't want to talk to you for a month. If it continues to be infected, I might up that to a year, or permanently ban you. It's your problem. Go fix it.

I propose to make a special "reject" packet. When a host, let's say 1.1.1.1, sends such packet to 2.2.2.2, all providers that see this packet, MUST reject any traffic from 2.2.2.2 to 1.1.1.1. This is very easy but very efficient and allows a single host to withstand the attack of any size. There is no need for any central authority and no need to maintain any lists.

And then that can be abused...
Post reply on HN