Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

271–280 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#271

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

You don't need a lot of money or resources to pull one of these. Code is on Github: https://github.com/649/Memcrashed-DDoS-Exploit

Also the participants are sometimes innocently recruited victims for the attack. I blame app insecure defaults.

The trend since 2015 is to get worst as you will see in the bottom layer of this graph: https://www.digitalattackmap.com/

Re: The largest DDoS attack to date, peaking above 398M rps

#272

Earlier quoted context omitted.

What? Let's go back to username and password. 2FA forces scammers to up their game. What about password managers? Having separate passwords to every account makes hacking into your accounts much harder and might hurt everyone in the long run. And don't get me started on end to end encryption. Privacy, long term, will mean the fall of civilization. Sarcasm aside. I think I understand your point in which we shouldn't j…

> Let's go back to username and password. 2FA forces scammers to up their game. Let's do it. It works for the website you're using right now. 2FA was in large part motivated by limiting bot accounts and getting customers phone number. I can't imagine how much productivity the economy loses every day due to 2FA.

> It works for the website you're using right now

It doesn't, you can regularly see people getting their accounts stolen here. This wouldn't be possible (or at least this trivial) with any competent implementation of 2fa.

Re: The largest DDoS attack to date, peaking above 398M rps

#273

Earlier quoted context omitted.

Passwords are small enough that you can make physical backups easily.

Honest question, because it is interesting and might change how I approach backing up my passwords. How would you go about maintaing that physical copy updated? What I think would make this approach hard is that you would have to ponder if a newly created account is important at creation time in order to know if you should update the off-site, physical copy of your most important passwords (I say this because if you…

With two usb sticks it’s not that much work to take one witha fresh backup to my mom when I visit and take the other one back and update that backup. At worst I lose one or two logins.

Re: The largest DDoS attack to date, peaking above 398M rps

#275
post #255

Earlier quoted context omitted.

Are you positive that "tell nobody" is the mitigation strategy that Google used here? They could have easily asked router vendors to patch their devices, asked ISPs to blackhole those customers until they're patched, etc.

Patch what though? They know that they're getting hit with unprecedented traffic, not how those computers were infected.

It's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....

Re: The largest DDoS attack to date, peaking above 398M rps

#276

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

I've been working on anti-DDOS off and on for 20 years now. The answer is sometimes government actors, but oftentimes scammers in Eastern Europe. They do these big attacks for street cred amongst the botting community. They then use their street cred to get paid by less scrupulous actors to attack their rivals. Sometimes the people paying are governments, sometimes just shady companies. For example last year there wa…

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Re: The largest DDoS attack to date, peaking above 398M rps

#277

Earlier quoted context omitted.

Plenty of even quite-large websites just don't get attacked by DDoS attacks, because nobody has any particular reason to attack them.

You’re completely wrong. All large sites regularly get attacked. The average skiddie’s motivations are that they’re bored. So they DoS a site they use regularly just to see. Heck they generally don’t even mean to cause damage per-se, and just think it’s a funny use of their evening. You have to stop thinking DoS attacks are always particularly personal. They really often just aren’t, and it’s a monumental pain in the…

I run boring sites like government websites which say what kinds of recycling go in which color trash cans.

Well used, but never attacked.

Re: The largest DDoS attack to date, peaking above 398M rps

#278

At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?

protection rackets by companies you'd only find on places like lowendtalk

Re: The largest DDoS attack to date, peaking above 398M rps

#279
post #271

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

You don't need a lot of money or resources to pull one of these. Code is on Github: https://github.com/649/Memcrashed-DDoS-Exploit Also the participants are sometimes innocently recruited victims for the attack. I blame app insecure defaults. The trend since 2015 is to get worst as you will see in the bottom layer of this graph: https://www.digitalattackmap.com/

This is a novel ddos attack. Did you all even read the article?

Re: The largest DDoS attack to date, peaking above 398M rps

#280

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

I've been working on anti-DDOS off and on for 20 years now. The answer is sometimes government actors, but oftentimes scammers in Eastern Europe. They do these big attacks for street cred amongst the botting community. They then use their street cred to get paid by less scrupulous actors to attack their rivals. Sometimes the people paying are governments, sometimes just shady companies. For example last year there wa…

Very useful, thanks. Do you know roughly what sort of resources, in time, money, and compromised machines, it takes to do something like this? (Order of magnitude.)
Post reply on HN