Live data from Hacker News

Fastmail, Runbox, and Posteo under DDoS extortion attack

therecord.media

51–60 of 130 posts

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#51

We still hear about DDoS attacks like this once in a while but it seems it's not anywhere near as common as it used to be. What happened? It looks like the bad guys are really having more and more trouble mounting succesful DDoS: how comes? It also looks like, in despair, they're targetting smaller fishes. Why? Smaller botnets? Cloudflare and OVH and the likes just being too good at absorbing everything and anything…

CloudFlare, AWS, GCP.

Cloudflare I agree, but "give us $10000 or we increase your AWS bill by $20000 per day" sounds like a viable extortion scheme to me.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#52
post #49

Earlier quoted context omitted.

You are correct on the ISP level. I am a network engineer for an ISP, we utilize Corero to monitor and mitigate DDoS attacks into our network. Since 99% of the time the DDoS is not targeted to us but rather the customer, I also kill the active IP addressing to their Modem/ONT, and configure that endpoint so it isn't allowed to pull an IP. Once the attack stops, re-config the endpoint and have it pull a new address.

Doesn't that simply mean that the customer loses connectivity, just as the attacker intended, for the duration of the attack? From the ISP's point of view, you might have prevented an overload that could have affected other customers. From the customer's point of view, their service was denied all the same. Doesn't sound like anything has improved compared to 10-20 years ago.

In both cases the customer has no access. (or a very limited one)

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#55

We still hear about DDoS attacks like this once in a while but it seems it's not anywhere near as common as it used to be. What happened? It looks like the bad guys are really having more and more trouble mounting succesful DDoS: how comes? It also looks like, in despair, they're targetting smaller fishes. Why? Smaller botnets? Cloudflare and OVH and the likes just being too good at absorbing everything and anything…

One factor: the main target was internet gambling sites. They banded together and collectively agreed not to pay any DDoSers.

Source: Security Engineering by Ross Anderson.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#56
post #32

We still hear about DDoS attacks like this once in a while but it seems it's not anywhere near as common as it used to be. What happened? It looks like the bad guys are really having more and more trouble mounting succesful DDoS: how comes? It also looks like, in despair, they're targetting smaller fishes. Why? Smaller botnets? Cloudflare and OVH and the likes just being too good at absorbing everything and anything…

Botnets aren't smaller (IoT has been quite a boon to them) & according to https://www.comparitech.com/blog/information-security/ddos-s... their frequency isn't declining But yes, the larger sites have gotten their shit together so that the cost to DDoS has gone up Also if you have a botnet you now have to ask: do you want rent out DDoS or do you want to mine crypto?

[deleted]

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#58
post #27

Earlier quoted context omitted.

More protection at the OS and ISP level. ISPs can isolate nodes that become part of botnets, and operating systems increasingly remove the avenues malicious actors use to cause trouble. Microsoft's push for hardware security is justly controversial, but the move to TPM by default in Windows 11 is the latest in a long line of changes that's made it harder to take over an ordinary person's computer. Android has had an…

You are correct on the ISP level. I am a network engineer for an ISP, we utilize Corero to monitor and mitigate DDoS attacks into our network. Since 99% of the time the DDoS is not targeted to us but rather the customer, I also kill the active IP addressing to their Modem/ONT, and configure that endpoint so it isn't allowed to pull an IP. Once the attack stops, re-config the endpoint and have it pull a new address.

That will stop overloading paths inside your network, but if your edge can't handle a 100 Gbps DDoS all your other customers still suffer.

Better to have the target blackholed upstream. Can usually be done with a BGP community of 666 if your peers support it.

Re: Fastmail, Runbox, and Posteo under DDoS extortion attack

#60

Earlier quoted context omitted.

CloudFlare, AWS, GCP.

Cloudflare I agree, but "give us $10000 or we increase your AWS bill by $20000 per day" sounds like a viable extortion scheme to me.

https://aws.amazon.com/shield/pricing

Might want to check how much it costs to increase someone's billing 20k a day (granted, a botnet makes it cheaper, but measure opportunity cost of what else that botnet could be doing), see also https://www.reddit.com/r/aws/comments/7z6uc3/comment/dutgw6u...

Full disclosure: I work for Azure

Post reply on HN