Live data from Hacker News

Azure hit by 15 Tbps DDoS attack using 500k IP addresses

bleepingcomputer.com

261–270 of 318 posts

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#261

Earlier quoted context omitted.

EVE Online had to put their foot down when people were talking about what could easily be considered terrorism.

Please tell us more, I need to hear the story!

The story goes that they were talking about figuring our where someone lived and cutting the power to their house so their ship would be defenceless.

You might be taking a game a bit too seriously if the FBI show up to have a chat.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#263
post #73
post #46

Earlier quoted context omitted.

Through personal responsibility? That is not scalable; look at how many compromised devices there are. We need a better solution as an industry.

Yep. Manufacturers / distributors should be held responsible. Aligning the incentives is half the battle.

A "do not connect to the cloud" physical flip switch on the IoT device is what I want. Where can I sign the petition for that?

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#264

> by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries, Presumably it’s possible to log the residential IP of the source of these packets. Why isn’t there any industry group pushing for the ISPs to a) send the owners an email telling them or b) blocking off all traffic for a period to get them to do something - or is the economic cost higher than caus…

Some of these devices are controlled by the ISP. The TMobile 5G routers for example are pretty much black box devices controlled by TMobile. The home owner can't fix the device and has very limited access (via a mobile app) to 'manage' the device.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#265
post #72

Earlier quoted context omitted.

Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…

This exchange is somewhat hilarious. Oh how on earth do we keep things safe and secure if everyone can see the code and verify what it does! Who would keep us safe if we turn our backs to unverifiable, unvetted, unprofitable security fixes, by for-profit companies!

The biggest joke is most of the proprietary routers both consumer and enterprise grade often are running some old outdated version of custom tuned openwrt lol, this goes for tp-link, and everyone else almost.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#266
post #260
post #72

Earlier quoted context omitted.

Why, OpenWRT firmware and packages are both signed, of course. You can manually and independently check the image signature before flashing an update. The build infrastructure is, of course, a juicy target: infect the artifact after building but before signing, and pwn millions of boxes before this is detected. This is why bit-perfect reproducible builds are so important. OpenWRT in particular have that: https://open…

> You can manually and independently check the image signature before flashing an update. Of course you can. You can also read the ToS before clicking accept, but who does that?

I'm sure there are dozens of us.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#267

> by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries, Presumably it’s possible to log the residential IP of the source of these packets. Why isn’t there any industry group pushing for the ISPs to a) send the owners an email telling them or b) blocking off all traffic for a period to get them to do something - or is the economic cost higher than caus…

Because then the ISPs have to provide support on how to secure those devices.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#268

> by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries, Presumably it’s possible to log the residential IP of the source of these packets. Why isn’t there any industry group pushing for the ISPs to a) send the owners an email telling them or b) blocking off all traffic for a period to get them to do something - or is the economic cost higher than caus…

Because then the ISPs have to provide support on how to secure those devices.

I will say most of the time the ISPs themselves provide the routers at residential homes

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#269
post #234

Earlier quoted context omitted.

Isn't the idea behind botnets that no one is paying for the bandwidth, besides the unsuspecting random people who have fallen victim to malware? I'd imagine the pricing is quite disconnected from the price of "legitimate" bandwidth. But I don't know in what direction.

The idea is, the botnets are in control of someone else. Who "owns" them. And some of those will rent "their property" for money, like they would legitimately own them.

Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.

Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses

#270
post #234

Earlier quoted context omitted.

The idea is, the botnets are in control of someone else. Who "owns" them. And some of those will rent "their property" for money, like they would legitimately own them.

Ok, but that doesn’t change the fact that the price of renting them is completely disconnected from the price of bandwidth.

Depends. The more the owners use their bots, or let others use their botnets, the more attention there is to them and the less useful the botnet is (either blacklisted IPs or owners noticing).

And a little bit of malicious bandwidth is easy to hide, a lot not. So there is a price to bandwith to the criminal owner.

Post reply on HN