It would really help to understand why attack one endpoint with "the largest DDoS attack ever observed in the cloud". If it was important, it would be redundant in its CDN. Who paid for this attack and what did they gain?
Azure hit by 15 Tbps DDoS attack using 500k IP addresses
41–50 of 318 posts
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#42Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#43IoT is just wave after wave of unsecure devices. There's gotta be a better way.
Until then... There's gonna be a bigger wave.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#44> it suddenly ballooned in size in April 2025 after its operators breached a TotoLink router firmware update server and infected approximately 100,000 devices This is scary. Everyone lauds open source projects like OpenWRT but... who is watching their servers? I imagine you can't run an army of security people on donations and a shoestring budget. Does OpenWRT use digital signing to mitigate this?
This is exactly why OpenWRT has no unattended updates by default )
Didn't they have a vulnerability in their firmware download tool like a minute ago?
The difference between OpenWRT and Linux distros is the amount of testing and visibility. OpenWRT is loaded on to residential devices and forgotten about, it doesn't have professional sysadmins babysitting it 24/7.
Remember the xz backdoor was only discovered because some autist at Microsoft noticed a microsecond difference in performance testing.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#45Earlier quoted context omitted.
How would you even enforce this if the offending country doesn't agree?
Limit their upstream connection to the rest of the internet via allied countries. Literally the same as economic sanctions. The internet is a network of peers “trading” bits and bytes after all.
North Korea doesn't care if you limit their internet they already allow people to go outside their own.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#46Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#47Earlier quoted context omitted.
Because it's not technicaly possible, I mean we're on HN, we all know how internet works.
You should talk to a network engineer before making claims like this. There are mechanisms to curtail DDOS attacks at origin. For a few reasons (political, economical) there’s little will to enact them, these attacks are so few and far between and you can pay your way out of them in most cases, so the incentives aren’t there for ISPs (whom are a commodity judged primarily on price and bandwidth)
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#48I will never understand why there isn’t an international law enforcement agency with teeth, which can get rid of the bad actors.
The international organisation for stopping wars, human trafficking, money laundering, drug distribution etc. however capable they might be, haven't managed to stamp out any of those things. I'd say a putative UN NetWatch would suffer from the same issues of funding and corruption and politics, but still we might have something better than this wild west lawlessness.
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#49> it targeted a single endpoint in Australia. It would really help to understand why attack one endpoint with "the largest DDoS attack ever observed in the cloud". If it was important, it would be redundant in its CDN. Who paid for this attack and what did they gain?
Re: Azure hit by 15 Tbps DDoS attack using 500k IP addresses
#50> it targeted a single endpoint in Australia. It would really help to understand why attack one endpoint with "the largest DDoS attack ever observed in the cloud". If it was important, it would be redundant in its CDN. Who paid for this attack and what did they gain?
we were getting hit with attacks like this daily at some point and were forced to use cloudflare magic transit it's pretty random and you shouldn't read too deep into it as nearly every anti-ddos solution, host and isp has been hit with this botnet by now.