Live data from Hacker News

The largest DDoS attack to date, peaking above 398M rps

cloud.google.com

411–420 of 487 posts

Re: The largest DDoS attack to date, peaking above 398M rps

#411

Earlier quoted context omitted.

Thing is, don’t care. The problem is that ISPs whose customers are originating the attacks from don’t give a shit. If we have to give up 1% of legitimate traffic to thwart 90% of attacks, it is a good deal. If you and other customers complain to your ISP (or switch), eventually they’ll do something about it. We can’t seriously keep on accepting that « thousands of compromised devices » is a fine reality for a « small…

Sounds like a really great way to potentially destroy someone's career if they aren't terribly competent and you are. Infect some component in their home network that they don't even know is smart-enabled, and keep breaching their new devices, adding them to an active and conspicuous botnet. The only recourse for average Joe is to find expert help, which isn't really in abundant supply if you are a semi-sophisticated…

This is an odd argument. The net is currently broken in many ways. One of the many ways is fake negative reviews. They easily destroy small businesses.

As I understand your argument, because the net has solid endpoints we can identify and isolate, we should ignore that fact. Instead we should create more and more complex systems to work around bad actors?

Bad actor takes control of grandma's computer. We should do all sorts of things except stop talking to grandma's computer? The thing, I would suspect, that most people would expect?

Businesses suffer from too much transparency. Got that part. They buy things that don't work and sometimes hurt people, even if they don't intend to do this. So far, so good. Where is the part where new businesses models are supposed to exist because some people made bad choices and the current models don't work? Why don't we just publicize the bad choices and let things work themselves out?

Sorry. Missing it.

Re: The largest DDoS attack to date, peaking above 398M rps

#412

Earlier quoted context omitted.

Sorry, this is not well-thought and certainly has potential for abuse. This is on IP and not domain? What is the signing authority and cryptography mechanism preventing a spoofed request?

When you send a "reject" packet, the imtermediate routers send back a confirmation code. You must send this code back to them to confirm that "reject" packet comes from your IP address. No cryptography or signing required.

I don't think you understand how networking operates at a packet level.

Re: The largest DDoS attack to date, peaking above 398M rps

#413
"In the end, H2 [HTTP/2] is not much robust but each implementation has certain possibilities to cover some of the limitations and these differ due to many architectural constraints."

"The good point in this is that this will probably make more people want to reconsider H3/QUIC [HTTP/3] if they don't trust their products anymore :-)"

https://www.mail-archive.com/haproxy@formilux.org/msg44136.h...

Re: The largest DDoS attack to date, peaking above 398M rps

#414

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

DDOS protection is a billion dollar a year industry.

Re: The largest DDoS attack to date, peaking above 398M rps

#415

Earlier quoted context omitted.

It's mostly not infected computers, but rather poorly configured proxies that are open for anyone to bounce malicious traffic through. Convincing everyone to clean up their open proxies is a long-term, hard problem. But I plan to tackle it soon....

How? I suppose the most effective way is to have those proxies attack each other. But don’t, it’s likely illegal.

Get a few companies to agree that open proxies are a scourge that needs to be stopped. They each apply some action to open proxies (user-facing messaging, loss of functionality, captcha, or complete block), and the users of those proxies will get the problem fixed.

The hard part (and it truly is hard!) is convincing a few companies to do this. It risks user complaints in the short term, to solve a problem that may not be very acute for the largest companies (who can simply absorb these attacks).

Re: The largest DDoS attack to date, peaking above 398M rps

#416

Earlier quoted context omitted.

Yeah, hospitals can't stand that kind of thing...

They should have better IT. Blaming it on the people that knock them off will not make improve the situation.

So your logic is: condemning people for criminal behavior is not useful because it de-incentivizes their victims from being vigilant against that criminal behavior. Am I getting that right?

Re: The largest DDoS attack to date, peaking above 398M rps

#417

> We noticed these attacks at the same time two other major industry players — Google and AWS — were seeing the same. Curious if there's anyone in the HN crowd that works at this level in one of the major vendors. What happens during an attack of this scale? Are there people from Cloudflare + Google + AWS on a live videoconference call co-ordinating with each other in real-time to mitigate it? Or is each vendor mostl…

We typically fight our own fires, but if one of us sees something interesting/new we often ask others (after the fire is out) if anyone else saw a similar attack (which could be a new botnet, a new attack method, or whatever). In this case we realized we were all looking at the same thing (which could have huge impact on smaller targets), so collaborated on understanding the problem and coordinated the security response with all webserver vendors.

Re: The largest DDoS attack to date, peaking above 398M rps

#418

Who has an incentive to carry out these DDos attacks? Why would anyone be willing to spend large amounts of money and develop a sophisticated attack against corporate cloud infrastructure? It seems like the only reasonable answer is foreign governments. But still what is the result - you inconvenience American tech companies and their customers for a few hours? This happens all the time, so clearly someone finds it w…

For a recent and similar attack at scale, the authors of the botnet software were from an American security company who sold DDOS mitigation solutions ( https://en.wikipedia.org/wiki/Mirai_(malware) ).

Google keeps showing me a CAPTCHA and telling me I'm part of the Mirai botnet. I'm using Cloudflare WARP so I have an IP from Cloudflare.

Re: The largest DDoS attack to date, peaking above 398M rps

#419
post #260

Earlier quoted context omitted.

And then that can be abused...

No, it cannot. It is well-thought.

There are 2^128 ipv6 addresses.

If you store 1 bit (banned/unbanned) + a unix timestamp (ban expiration) for each of those IPs, that requires more storage space than exists many billion times over.

To store such a block table you propose would require more memory for routers than any router has ever had and ever will have.

An attacker could easily "flush" all entries in this table by, for example, banning a TB of ipv6 addresses from talking to them, surely resulting in all participating routers dropping other bans to store some of those.

Re: The largest DDoS attack to date, peaking above 398M rps

#420

Earlier quoted context omitted.

> just with everything production-grade, the average enterprise just isn't ready to deal with all the upfront cost to run your entire computing solution That’s not a fair point. We’re not even trying to make the internet safe. There is zero (0) actions being taken to stop this madness. If you run a large website, you still regularly see attacks from routers compromised 3, 4, 5 years ago. Or how a mere few days of pok…

I like the irony of saying there are zero actions being taken in response to a blog post documenting actions taken to specific CVEs.

These blogposts document the attack. Documenting it and acting in it are different.

There’s no practical action being taken besides « use our profucts cause we can tank it for you » here.

The mitigations listed are better than nothing, but the fact that every skid out there can hire a botnet of a few thousands compromised machines (like here) and send you a few millions (say this protocol attack allowed a 100x higer than avg impact) rps is way enough to kill the infra of 99.99% websites. No questions asked.

Post reply on HN