Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

291–300 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#291

Earlier quoted context omitted.

I've been working on anti-DDOS off and on for 20 years now. The answer is sometimes government actors, but oftentimes scammers in Eastern Europe. They do these big attacks for street cred amongst the botting community. They then use their street cred to get paid by less scrupulous actors to attack their rivals. Sometimes the people paying are governments, sometimes just shady companies. For example last year there wa…

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Nah it's even better because they're considered capable defenders so it's harder.

What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities.

Unless this is marketing for Google Cloud?

Re: The largest DDoS attack to date, peaking above 398M rps

#292

Earlier quoted context omitted.

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Nah it's even better because they're considered capable defenders so it's harder. What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities. Unless this is marketing for Google Cloud?

This is certainly marketing. If they sell DDOS protection, then announcing that they stopped the largest attack ever is an ad.

Re: The largest DDoS attack to date, peaking above 398M rps

#293

At a previous company, we were subject to semi-frequent attacks (of a much smaller scale). The operating assumption internally was that it’s a competitor trying to undermine us but it remains a mystery. Anyone involved in these type of attacks (at internet-infrastructure scale or targeting specific companies) brave/crazy enough to create a throwaway account and tell hn about the motivations?

The universities in Sweden were attacked by "Turkey" after the big quran-burning scandal. They had some twitter account bragging about it. Was pretty evident it was Russia.

Re: The largest DDoS attack to date, peaking above 398M rps

#294
post #271

Earlier quoted context omitted.

You don't need a lot of money or resources to pull one of these. Code is on Github: https://github.com/649/Memcrashed-DDoS-Exploit Also the participants are sometimes innocently recruited victims for the attack. I blame app insecure defaults. The trend since 2015 is to get worst as you will see in the bottom layer of this graph: https://www.digitalattackmap.com/

This is a novel ddos attack. Did you all even read the article?

I did. I replied to OP question.And that was about DDos attacks in general not "HTTP/2 Rapid Reset attacks"

> Who has an incentive to carry out these DDos attacks?

Did you read the comment I was replying to?

Re: The largest DDoS attack to date, peaking above 398M rps

#295

Earlier quoted context omitted.

Seems like attacking Google would be a bad target for street cred as compared to govt websites.

Nah it's even better because they're considered capable defenders so it's harder. What I'm not sure of is why Google published this. I can't figure out what their strategy is here. We never published about the attacks we absorbed because we didn't want them to know our capabilities. Unless this is marketing for Google Cloud?

> Unless this is marketing for Google Cloud?

If you read the article, there are plenty of marketing remarks in there to get you to use Google Cloud

Re: The largest DDoS attack to date, peaking above 398M rps

#296
post #284

Earlier quoted context omitted.

Very useful, thanks. Do you know roughly what sort of resources, in time, money, and compromised machines, it takes to do something like this? (Order of magnitude.)

approx. 20,000 machines https://news.ycombinator.com/item?id=37831355

So a single machine can do ~ 20,000 rps?

Re: The largest DDoS attack to date, peaking above 398M rps

#297
post #255

Earlier quoted context omitted.

Patch what though? They know that they're getting hit with unprecedented traffic, not how those computers were infected.

It's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....

How? I suppose the most effective way is to have those proxies attack each other. But don’t, it’s likely illegal.

Re: The largest DDoS attack to date, peaking above 398M rps

#298

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

You can (or could, my information is old) pay botnet owners a few hundred bucks to disrupt the servers of people you don't like. An example would be ruining a match for a competing game clan. There's a suprising amount of this kind of petty bullshit going on in the world.

With the Mirai botnet, some of the creators had a DDOS mitigation company as well: they'd sell one party the weapon, and sell another party the defense against that weapon.

Sometimes it's for the street cred, or the lulz, or just the challenge of building a botnet.

Re: The largest DDoS attack to date, peaking above 398M rps

#299
post #294

Earlier quoted context omitted.

This is a novel ddos attack. Did you all even read the article?

I did. I replied to OP question.And that was about DDos attacks in general not "HTTP/2 Rapid Reset attacks" > Who has an incentive to carry out these DDos attacks? Did you read the comment I was replying to?

Yes, “these attacks” referring to the sophisticated novel attacks under discussion in the article. No need to be defensive, just read it next time.
Post reply on HN